Sekit CSF · Application Security · Process
RCF-0134IaC scanning
Infrastructure templates are consistently scanned for misconfigurations before being applied
Mapping at a glance
RCF-0134IaC scanningApplication Security · Process
RCF-0134 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.9Configuration managementsupportsScanning every infrastructure template for misconfigurations before changes are applied catches configuration errors at the design stage rather than after deployment.A.8.25Secure development life cyclesupportsThe process facet scans every infrastructure template for misconfigurations as a routine step before changes are applied.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0134?”
Also via MCP, free with account