Sekit CSF · Cloud Security · Process
RCF-0332Shared responsibility model
Teams consistently apply the correct security controls for their side of the cloud shared responsibility model
Mapping at a glance
RCF-0332Shared responsibility modelCloud Security · Process
A.5.22Monitoring, review and change management of supplier servicesISO/IEC 27001:2022A.5.23Information security for use of cloud servicesISO/IEC 27001:2022GV.OC-04Critical objectives and services understoodNIST CSF 2.0GV.SC-01Supply chain risk program establishedNIST CSF 2.0GV.SC-05Supply chain requirements in contractsNIST CSF 2.0
RCF-0332 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.22Monitoring, review and change management of supplier servicessupportsMaking the customer-side cloud duties part of routine operations is how A.5.22's review requirement applies to the specific split of responsibility in cloud services.A.5.23Information security for use of cloud servicessupportsThe process facet turns the documented split into routine work, so someone performs each customer-side duty on a schedule instead of assuming the provider covers it.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.OC-04Critical objectives and services understoodGV.SC-01Supply chain risk program establishedGV.SC-05Supply chain requirements in contracts
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Cloud Security controls
Ask Sekura: “What evidence proves RCF-0332?”
Also via MCP, free with account