Sekit CSF · Application Security · Process
RCF-0125SAST/DAST
Static and dynamic security tests are consistently run as part of the build and release process
Mapping at a glance
RCF-0125SAST/DASTApplication Security · Process
RCF-0125 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cyclesupportsThe process facet executes static and dynamic security tests as a routine part of every build and release, with findings triaged to closure.A.8.29Security testing in development and acceptancesupportsThe Sekit process control executes static and dynamic tests as a routine part of every build, applying the testing this ISO control requires to each release rather than occasionally.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
DE.CM-01Networks monitoredPR.PS-01Configuration management appliedPR.PS-04Logs generated for monitoring
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Application security testing evidence
The proof that code and applications are automatically scanned for flaws (SAST/DAST), including dependencies and APIs.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0125?”
Also via MCP, free with account