Framework crosswalk Sekit CSFISO/IEC 27001:2022 Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Sekit CSF · Identity & Access Management Crosswalk / Identity & Access Management RCF-0061 Policy 2 mapped Identity lifecycle ISO 27001 A.5.15 ISO 27001 A.5.16 RCF-0062 Process 2 mapped Identity lifecycle ISO 27001 A.5.16 ISO 27001 A.5.18 RCF-0063 Technical 2 mapped Identity lifecycle ISO 27001 A.5.16 ISO 27001 A.5.18 RCF-0064 Policy 3 mapped Strong authentication (MFA) ISO 27001 A.5.15 ISO 27001 A.5.17 ISO 27001 A.8.5 RCF-0065 Process 2 mapped Strong authentication (MFA) ISO 27001 A.5.17 ISO 27001 A.8.5 RCF-0066 Technical 1 mapped Strong authentication (MFA) ISO 27001 A.8.5 RCF-0067 Policy 3 mapped Least privilege / RBAC ISO 27001 A.5.15 ISO 27001 A.5.18 ISO 27001 A.8.3 RCF-0068 Process 1 mapped Least privilege / RBAC ISO 27001 A.5.18 RCF-0069 Technical 2 mapped Least privilege / RBAC ISO 27001 A.5.15 ISO 27001 A.8.3 RCF-0070 Policy 2 mapped Privileged access management ISO 27001 A.5.15 ISO 27001 A.8.2 RCF-0071 Process 3 mapped Privileged access management ISO 27001 A.8.15 ISO 27001 A.8.18 ISO 27001 A.8.2 RCF-0072 Technical 4 mapped Privileged access management ISO 27001 A.8.15 ISO 27001 A.8.16 ISO 27001 A.8.18 ISO 27001 A.8.2 RCF-0073 Policy 3 mapped SSO & federation ISO 27001 A.5.1 ISO 27001 A.5.15 ISO 27001 A.5.16 RCF-0074 Process 3 mapped SSO & federation ISO 27001 A.5.15 ISO 27001 A.5.16 ISO 27001 A.5.8 RCF-0075 Technical 3 mapped SSO & federation ISO 27001 A.5.15 ISO 27001 A.5.16 ISO 27001 A.8.5 RCF-0076 Policy 2 mapped Password policy ISO 27001 A.5.1 ISO 27001 A.5.17 RCF-0077 Process 2 mapped Password policy ISO 27001 A.5.17 ISO 27001 A.6.3 RCF-0078 Technical 2 mapped Password policy ISO 27001 A.5.17 ISO 27001 A.8.5 RCF-0079 Policy 2 mapped Session management ISO 27001 A.5.15 ISO 27001 A.5.17 RCF-0080 Process 2 mapped Session management ISO 27001 A.5.10 ISO 27001 A.7.7 RCF-0081 Technical 2 mapped Session management ISO 27001 A.8.1 ISO 27001 A.8.5 RCF-0082 Policy 2 mapped Remote access ISO 27001 A.5.15 ISO 27001 A.6.7 RCF-0083 Process 2 mapped Remote access ISO 27001 A.6.3 ISO 27001 A.6.7 RCF-0084 Technical 4 mapped Remote access ISO 27001 A.6.7 ISO 27001 A.8.20 ISO 27001 A.8.24 ISO 27001 A.8.5 RCF-0085 Policy 2 mapped Access reviews (recertification) ISO 27001 A.5.15 ISO 27001 A.5.18 RCF-0086 Process 1 mapped Access reviews (recertification) ISO 27001 A.5.18 RCF-0087 Technical 3 mapped Access reviews (recertification) ISO 27001 A.5.18 ISO 27001 A.8.15 ISO 27001 A.8.16 RCF-0088 Policy 3 mapped JML (joiner-mover-leaver) ISO 27001 A.5.16 ISO 27001 A.5.18 ISO 27001 A.6.5 RCF-0089 Process 2 mapped JML (joiner-mover-leaver) ISO 27001 A.5.18 ISO 27001 A.6.5 RCF-0090 Technical 2 mapped JML (joiner-mover-leaver) ISO 27001 A.5.16 ISO 27001 A.5.18
ISO/IEC 27001:2022 A.5.1 Policies for information security A.5.8 Information security in project management A.5.10 Acceptable use of information and other associated assets A.5.15 Access control A.5.16 Identity management A.5.17 Authentication information A.5.18 Access rights A.6.3 Information security awareness, education and training A.6.5 Responsibilities after termination or change of employment A.6.7 Remote working A.7.7 Clear desk and clear screen A.8.1 User endpoint devices A.8.2 Privileged access rights A.8.3 Information access restriction A.8.5 Secure authentication A.8.15 Logging A.8.16 Monitoring activities A.8.18 Use of privileged utility programs A.8.20 Networks security A.8.24 Use of cryptography