Sekit CSF · Privacy · Policy
RCF-0364Privacy by design
Privacy is built into new systems and processes from the start
Mapping at a glance
RCF-0364Privacy by designPrivacy · Policy
A.5.34Privacy and protection of personal identifiable information (PII)ISO/IEC 27001:2022A.8.27Secure system architecture and engineering principlesISO/IEC 27001:2022GV.PO-02Cybersecurity policy maintainedNIST CSF 2.0PR.DS-01Data-at-rest protectedNIST CSF 2.0PR.PS-01Configuration management appliedNIST CSF 2.0
RCF-0364 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.34Privacy and protection of personal identifiable information (PII)supportsRequiring privacy questions to be answered before any new system or vendor goes live builds this control's protections into projects from the start rather than after launch.A.8.27Secure system architecture and engineering principlessupportsThis policy facet requires privacy questions, data minimization, retention, lawful basis, to be answered before any new system touches personal data, one design principle A.8.27 covers.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.PO-02Cybersecurity policy maintainedPR.DS-01Data-at-rest protectedPR.PS-01Configuration management applied
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.6.1.2Objectives for responsible development of AI systemenablesRequiring privacy questions to be answered before launch creates one of the measurable gates a responsible AI objective set would reuse for data minimisation and retention.A.6.2.2AI system requirements and specificationsupportsRequiring privacy questions answered before launch feeds directly into an AI system's data requirements, though the policy itself does not name AI systems.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
DPIA and cross-border transfer records
The privacy impact assessments done before new data processing and the records of personal-data transfers to other countries.
From the Sekit evidence catalog
This topic through the other lenses
All Privacy controls
Ask Sekura: “What evidence proves RCF-0364?”
Also via MCP, free with account