Sekit CSF · Application Security · Technical
RCF-0120Threat modeling
Technical tools support structured threat modeling and track identified risks to resolution
Mapping at a glance
RCF-0120Threat modelingApplication Security · Technical
A.8.25Secure development life cycleISO/IEC 27001:2022 · Annex A controlsA.8.26Application security requirementsISO/IEC 27001:2022 · Annex A controlsID.RA-01Vulnerabilities identified and recordedNIST CSF 2.0ID.RA-03Threats identified and recordedNIST CSF 2.0PR.PS-01Configuration management appliedNIST CSF 2.0
RCF-0120 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cycleenablesTooling that captures identified threats in structured form and tracks each to closure gives A.8.25's threat-modeling step a durable record instead of a one-off workshop.A.8.26Application security requirementsenablesTooling that captures identified threats in structured form and tracks them to closure gives the requirements A.8.26 expects a durable record.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.RA-01Vulnerabilities identified and recordedID.RA-03Threats identified and recordedPR.PS-01Configuration management applied
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Secure development policy
The rules the development team follows to build software securely: security requirements, code review and threat modeling.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0120?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.