Sekit CSF · Governance & Risk · Technical
RCF-0018Regulatory compliance
Technical controls support compliance with regulatory requirements
Mapping at a glance
RCF-0018Regulatory complianceGovernance & Risk · Technical
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022A.5.33Protection of recordsISO/IEC 27001:2022A.5.34Privacy and protection of personal identifiable information (PII)ISO/IEC 27001:2022A.8.24Use of cryptographyISO/IEC 27001:2022GV.OC-01Organizational mission understoodNIST CSF 2.0
RCF-0018 maps to 9 controls across the published frameworks. +4 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.31Legal, statutory, regulatory and contractual requirementsenablesSystem configuration that satisfies regulatory requirements automatically wherever the platform allows it reduces how much of this control depends on manual process alone.A.5.33Protection of recordsrelatedUsing system configuration to satisfy regulatory requirements automatically applies broadly across compliance, and specifically supports the retention and disposal rules this control requires be enforced technically.A.5.34Privacy and protection of personal identifiable information (PII)relatedSystem configuration that satisfies regulatory requirements automatically applies broadly, and privacy settings are one concrete case this control depends on being enforced technically.A.8.24Use of cryptographyrelatedConfiguring system settings to meet regulatory requirements automatically touches the cryptography rules A.8.24 expects but does not itself define key management.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.OC-01Organizational mission understoodGV.OC-02Stakeholder needs understoodGV.OC-03Legal and regulatory requirements understoodGV.OC-04Critical objectives and services understoodGV.OC-05Dependencies understood
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Regulatory obligations register
The list of laws, regulations and frameworks that apply to the company (e.g. GDPR, sector rules) and how they map to your internal controls.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0018?”
Also via MCP, free with account