Sekit CSF · Governance & Risk · Technical
RCF-0009Risk assessment
Risk assessment processes are supported by technical tools and data
Mapping at a glance
RCF-0009Risk assessmentGovernance & Risk · Technical
RCF-0009 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.7Threat intelligencesupportsThis technical control feeds risk assessments with real technical data instead of opinion, which is what a working threat intelligence practice supplies.A.8.8Management of technical vulnerabilitiessupportsFeeding risk assessments with real scanner and vulnerability data grounds A.8.8's technical exposure assessment in evidence instead of opinion.A.8.16Monitoring activitiesrelatedFeeding risk assessments with real technical data draws on the same monitoring activity A.8.16 requires, but serves risk analysis rather than the detection function itself.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-01Risk management objectives establishedGV.RM-02Risk appetite and tolerance establishedGV.RM-03Cyber risk in enterprise risk managementID.RA-01Vulnerabilities identified and recordedID.RA-02Threat intelligence received
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0009?”
Also via MCP, free with account