Framework crosswalk Sekit CSFISO/IEC 27001:2022 Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Sekit CSF · Vulnerability & Configuration Crosswalk / Vulnerability & Configuration RCF-0217 Policy 2 mapped Vulnerability scanning ISO 27001 A.5.1 ISO 27001 A.8.8 RCF-0218 Process 2 mapped Vulnerability scanning ISO 27001 A.5.37 ISO 27001 A.8.8 RCF-0219 Technical 1 mapped Vulnerability scanning ISO 27001 A.8.8 RCF-0220 Policy 2 mapped Vulnerability remediation SLAs ISO 27001 A.5.1 ISO 27001 A.8.8 RCF-0221 Process 2 mapped Vulnerability remediation SLAs ISO 27001 A.5.37 ISO 27001 A.8.8 RCF-0222 Technical 1 mapped Vulnerability remediation SLAs ISO 27001 A.8.8 RCF-0223 Policy 2 mapped Configuration management ISO 27001 A.5.1 ISO 27001 A.8.9 RCF-0224 Process 2 mapped Configuration management ISO 27001 A.5.36 ISO 27001 A.8.9 RCF-0225 Technical 1 mapped Configuration management ISO 27001 A.8.9 RCF-0226 Policy 2 mapped Baseline compliance ISO 27001 A.5.1 ISO 27001 A.8.9 RCF-0227 Process 2 mapped Baseline compliance ISO 27001 A.5.36 ISO 27001 A.8.9 RCF-0228 Technical 1 mapped Baseline compliance ISO 27001 A.8.9 RCF-0229 Policy 2 mapped Patch prioritization ISO 27001 A.5.1 ISO 27001 A.8.8 RCF-0230 Process 2 mapped Patch prioritization ISO 27001 A.5.37 ISO 27001 A.8.8 RCF-0231 Technical 2 mapped Patch prioritization ISO 27001 A.5.7 ISO 27001 A.8.8 RCF-0232 Policy 2 mapped Exposure management ISO 27001 A.5.1 ISO 27001 A.8.8 RCF-0233 Process 2 mapped Exposure management ISO 27001 A.5.9 ISO 27001 A.8.8 RCF-0234 Technical 2 mapped Exposure management ISO 27001 A.8.16 ISO 27001 A.8.8 RCF-0235 Policy 2 mapped Penetration testing ISO 27001 A.5.1 ISO 27001 A.8.8 RCF-0236 Process 2 mapped Penetration testing ISO 27001 A.8.34 ISO 27001 A.8.8 RCF-0237 Technical 2 mapped Penetration testing ISO 27001 A.8.31 ISO 27001 A.8.34
ISO/IEC 27001:2022 A.5.1 Policies for information security A.5.7 Threat intelligence A.5.9 Inventory of information and other associated assets A.5.36 Compliance with policies, rules and standards for information security A.5.37 Documented operating procedures A.8.8 Management of technical vulnerabilities A.8.9 Configuration management A.8.16 Monitoring activities A.8.31 Separation of development, test and production environments A.8.34 Protection of information systems during audit testing