Sekit CSF · Application Security · Technical
RCF-0135IaC scanning
Automated tools scan infrastructure code for security issues and block deployment of non-compliant templates
Mapping at a glance
RCF-0135IaC scanningApplication Security · Technical
RCF-0135 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.9Configuration managementsupportsEnforcing automated template scanning in the pipeline so non-compliant infrastructure cannot deploy is a technical gate for exactly the drift A.8.9 tries to prevent.A.8.29Security testing in development and acceptancesupportsThis Sekit technical control blocks infrastructure templates that fail automated scanning from ever deploying, closing off a path to production that bypasses the application-level tests entirely.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0135?”
Also via MCP, free with account