Sekit CSF · Vulnerability & Configuration · Process
RCF-0221Vulnerability remediation SLAs
Vulnerability remediation deadlines are consistently tracked and escalated when at risk of being missed
Mapping at a glance
RCF-0221Vulnerability remediation SLAsVulnerability & Configuration · Process
RCF-0221 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.37Documented operating proceduressupportsThis process control tracks every open vulnerability against its deadline and escalates before it slips, the kind of documented operating discipline A.5.37 requires.A.8.8Management of technical vulnerabilitiessupportsThe process facet tracks every open vulnerability against its deadline and escalates before the deadline slips, not after.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.IM-02Improvements from tests and exercisesID.RA-05Inherent risk understoodID.RA-07Changes and exceptions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Patch management report
The proof that security updates are applied on time across devices and systems, with tracking of what is still outstanding.
From the Sekit evidence catalog
This topic through the other lenses
All Vulnerability & Configuration controls
Ask Sekura: “What evidence proves RCF-0221?”
Also via MCP, free with account