Framework crosswalk Sekit CSFISO/IEC 27001:2022 Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Sekit CSF · Application Security Crosswalk / Application Security RCF-0115 Policy 3 mapped Secure SDLC policy ISO 27001 A.5.1 ISO 27001 A.5.8 ISO 27001 A.8.25 RCF-0116 Process 2 mapped Secure SDLC policy ISO 27001 A.8.25 ISO 27001 A.8.32 RCF-0117 Technical 3 mapped Secure SDLC policy ISO 27001 A.8.25 ISO 27001 A.8.29 ISO 27001 A.8.31 RCF-0118 Policy 3 mapped Threat modeling ISO 27001 A.8.25 ISO 27001 A.8.26 ISO 27001 A.8.27 RCF-0119 Process 2 mapped Threat modeling ISO 27001 A.8.25 ISO 27001 A.8.26 RCF-0120 Technical 2 mapped Threat modeling ISO 27001 A.8.25 ISO 27001 A.8.26 RCF-0121 Policy 3 mapped Secure code review ISO 27001 A.5.1 ISO 27001 A.8.25 ISO 27001 A.8.29 RCF-0122 Process 2 mapped Secure code review ISO 27001 A.8.25 ISO 27001 A.8.29 RCF-0123 Technical 2 mapped Secure code review ISO 27001 A.8.28 ISO 27001 A.8.29 RCF-0124 Policy 2 mapped SAST/DAST ISO 27001 A.5.1 ISO 27001 A.8.29 RCF-0125 Process 2 mapped SAST/DAST ISO 27001 A.8.25 ISO 27001 A.8.29 RCF-0126 Technical 2 mapped SAST/DAST ISO 27001 A.8.25 ISO 27001 A.8.29 RCF-0127 Policy 3 mapped Dependency/SBOM management ISO 27001 A.5.1 ISO 27001 A.5.9 ISO 27001 A.8.8 RCF-0128 Process 2 mapped Dependency/SBOM management ISO 27001 A.5.9 ISO 27001 A.8.8 RCF-0129 Technical 2 mapped Dependency/SBOM management ISO 27001 A.8.29 ISO 27001 A.8.8 RCF-0130 Policy 3 mapped CI/CD hardening ISO 27001 A.5.1 ISO 27001 A.8.25 ISO 27001 A.8.9 RCF-0131 Process 2 mapped CI/CD hardening ISO 27001 A.8.25 ISO 27001 A.8.32 RCF-0132 Technical 3 mapped CI/CD hardening ISO 27001 A.8.25 ISO 27001 A.8.4 ISO 27001 A.8.9 RCF-0133 Policy 3 mapped IaC scanning ISO 27001 A.5.1 ISO 27001 A.8.25 ISO 27001 A.8.9 RCF-0134 Process 2 mapped IaC scanning ISO 27001 A.8.25 ISO 27001 A.8.9 RCF-0135 Technical 2 mapped IaC scanning ISO 27001 A.8.29 ISO 27001 A.8.9 RCF-0136 Policy 2 mapped API security ISO 27001 A.5.1 ISO 27001 A.8.26 RCF-0137 Process 3 mapped API security ISO 27001 A.8.16 ISO 27001 A.8.26 ISO 27001 A.8.29 RCF-0138 Technical 3 mapped API security ISO 27001 A.5.15 ISO 27001 A.8.26 ISO 27001 A.8.5 RCF-0139 Policy 3 mapped Container security ISO 27001 A.5.1 ISO 27001 A.8.25 ISO 27001 A.8.9 RCF-0140 Process 2 mapped Container security ISO 27001 A.8.25 ISO 27001 A.8.9 RCF-0141 Technical 3 mapped Container security ISO 27001 A.8.29 ISO 27001 A.8.7 ISO 27001 A.8.9 RCF-0142 Policy 2 mapped DevSecOps governance ISO 27001 A.5.1 ISO 27001 A.5.2 RCF-0143 Process 2 mapped DevSecOps governance ISO 27001 A.5.4 ISO 27001 A.8.25 RCF-0144 Technical 2 mapped DevSecOps governance ISO 27001 A.8.15 ISO 27001 A.8.16
ISO/IEC 27001:2022 A.5.1 Policies for information security A.5.2 Information security roles and responsibilities A.5.4 Management responsibilities A.5.8 Information security in project management A.5.9 Inventory of information and other associated assets A.5.15 Access control A.8.4 Access to source code A.8.5 Secure authentication A.8.7 Protection against malware A.8.8 Management of technical vulnerabilities A.8.9 Configuration management A.8.15 Logging A.8.16 Monitoring activities A.8.25 Secure development life cycle A.8.26 Application security requirements A.8.27 Secure system architecture and engineering principles A.8.28 Secure coding A.8.29 Security testing in development and acceptance A.8.31 Separation of development, test and production environments A.8.32 Change management