Sekit CSF · Governance & Risk · Technical
RCF-0027Third-party risk management
Technical controls monitor third party access and activity
Mapping at a glance
RCF-0027Third-party risk managementGovernance & Risk · Technical
RCF-0027 maps to 13 controls across the published frameworks. +8 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.18Access rightssupportsGiving third parties named, individually attributable accounts with logged, reviewed access is A.5.18's provisioning and review discipline applied to non-employee access rights.A.5.22Monitoring, review and change management of supplier servicessupportsLogging and reviewing what third-party accounts do gives A.5.22's monitoring requirement something concrete to review, beyond trusting that access is used as intended.A.8.15LoggingsupportsLogging and reviewing what third parties do with their attributable accounts is a direct application of the activity logging A.8.15 requires, focused on external access.A.8.16Monitoring activitiessupportsLogging and reviewing third-party account activity is a specific application of the network and system monitoring A.8.16 requires, focused on external access.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-01Supply chain risk program establishedGV.SC-02Supplier roles and responsibilities establishedGV.SC-03Supply chain risk integratedGV.SC-04Suppliers known and prioritizedGV.SC-05Supply chain requirements in contractsGV.SC-06Due diligence before engagementGV.SC-07Supplier risk managed over relationshipGV.SC-08Suppliers in incident planningGV.SC-09Supply chain practices integrated in lifecycle
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0027?”
Also via MCP, free with account