Sekit CSF · Governance & Risk · Policy
RCF-0010Risk treatment
The company has a formal plan to address identified security risks
Mapping at a glance
RCF-0010Risk treatmentGovernance & Risk · Policy
A.5.8Information security in project managementISO/IEC 27001:2022 · Annex A controlsGV.RM-04Risk response strategy establishedNIST CSF 2.0GV.RM-05Lines of communication for risk establishedNIST CSF 2.0GV.RM-06Standardized risk method establishedNIST CSF 2.0GV.RM-07Strategic opportunities characterizedNIST CSF 2.0
RCF-0010 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-04Risk response strategy establishedGV.RM-05Lines of communication for risk establishedGV.RM-06Standardized risk method establishedGV.RM-07Strategic opportunities characterized
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0010?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.