Sekit CSF · Asset Management · Technical
RCF-0060Shadow IT discovery
Technical tools continuously scan for unauthorised devices, applications and cloud services
Mapping at a glance
RCF-0060Shadow IT discoveryAsset Management · Technical
RCF-0060 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.9Inventory of information and other associated assetssupportsThis technical control continuously scans for unauthorised devices, applications and cloud services, catching what a manual A.5.9 inventory alone would not.A.5.10Acceptable use of information and other associated assetsenablesAutomated detection of unsanctioned devices and services gives the acceptable-use policy something to check against, enabling enforcement that a policy statement alone cannot provide.A.8.16Monitoring activitiessupportsContinuously detecting unauthorized devices and unsanctioned cloud services is monitoring activity aimed squarely at the unusual behavior A.8.16 wants surfaced.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.AM-01Hardware inventory maintainedID.AM-02Software inventory maintainedID.AM-08Assets managed through lifecycle
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
From the Sekit evidence catalog
This topic through the other lenses
All Asset Management controls
Ask Sekura: “What evidence proves RCF-0060?”
Also via MCP, free with account