SekitCrosswalk
Sekit CSF · Governance & Risk · Technical

RCF-0009Risk assessment

Risk assessment processes are supported by technical tools and data

Maps to ISO/IEC 27001:2022

Curated mapping with the reasoning, not just the codes.

Maps to NIST CSF 2.0

Curated mapping with the reasoning, not just the codes.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog

This topic through the other lenses

All Governance & Risk controls

Ask Sekura: “What evidence proves RCF-0009?”
Also via MCP, free with account