Framework crosswalk Sekit CSFISO/IEC 27001:2022 Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Sekit CSF · Governance & Risk Crosswalk / Governance & Risk RCF-0001 Policy 1 mapped Policy management ISO 27001 A.5.1 RCF-0002 Process 3 mapped Policy management ISO 27001 A.5.1 ISO 27001 A.5.36 ISO 27001 A.5.4 RCF-0003 Technical 3 mapped Policy management ISO 27001 A.5.36 ISO 27001 A.5.37 ISO 27001 A.8.9 RCF-0004 Policy 1 mapped Roles & responsibilities ISO 27001 A.5.2 RCF-0005 Process 3 mapped Roles & responsibilities ISO 27001 A.5.2 ISO 27001 A.5.4 ISO 27001 A.6.2 RCF-0006 Technical 3 mapped Roles & responsibilities ISO 27001 A.5.15 ISO 27001 A.5.3 ISO 27001 A.8.2 RCF-0007 Policy 1 mapped Risk assessment ISO 27001 A.5.7 RCF-0008 Process 2 mapped Risk assessment ISO 27001 A.5.35 ISO 27001 A.5.7 RCF-0009 Technical 3 mapped Risk assessment ISO 27001 A.5.7 ISO 27001 A.8.16 ISO 27001 A.8.8 RCF-0010 Policy 1 mapped Risk treatment ISO 27001 A.5.8 RCF-0011 Process 2 mapped Risk treatment ISO 27001 A.5.26 ISO 27001 A.5.36 RCF-0012 Technical 3 mapped Risk treatment ISO 27001 A.5.36 ISO 27001 A.8.8 ISO 27001 A.8.9 RCF-0013 Policy 2 mapped Exception management ISO 27001 A.5.1 ISO 27001 A.5.36 RCF-0014 Process 2 mapped Exception management ISO 27001 A.5.36 ISO 27001 A.5.4 RCF-0015 Technical 2 mapped Exception management ISO 27001 A.8.16 ISO 27001 A.8.9 RCF-0016 Policy 1 mapped Regulatory compliance ISO 27001 A.5.31 RCF-0017 Process 3 mapped Regulatory compliance ISO 27001 A.5.31 ISO 27001 A.5.36 ISO 27001 A.5.4 RCF-0018 Technical 4 mapped Regulatory compliance ISO 27001 A.5.31 ISO 27001 A.5.33 ISO 27001 A.5.34 ISO 27001 A.8.24 RCF-0019 Policy 2 mapped Metrics & reporting ISO 27001 A.5.35 ISO 27001 A.5.36 RCF-0020 Process 2 mapped Metrics & reporting ISO 27001 A.5.35 ISO 27001 A.5.4 RCF-0021 Technical 3 mapped Metrics & reporting ISO 27001 A.5.7 ISO 27001 A.8.15 ISO 27001 A.8.16 RCF-0022 Policy 1 mapped Internal audit ISO 27001 A.5.35 RCF-0023 Process 3 mapped Internal audit ISO 27001 A.5.27 ISO 27001 A.5.35 ISO 27001 A.5.36 RCF-0024 Technical 3 mapped Internal audit ISO 27001 A.5.28 ISO 27001 A.8.15 ISO 27001 A.8.34 RCF-0025 Policy 1 mapped Third-party risk management ISO 27001 A.5.19 RCF-0026 Process 3 mapped Third-party risk management ISO 27001 A.5.20 ISO 27001 A.5.21 ISO 27001 A.5.22 RCF-0027 Technical 4 mapped Third-party risk management ISO 27001 A.5.18 ISO 27001 A.5.22 ISO 27001 A.8.15 ISO 27001 A.8.16 RCF-0028 Policy 3 mapped Security charter ISO 27001 A.5.1 ISO 27001 A.5.2 ISO 27001 A.5.4 RCF-0029 Process 1 mapped Security charter ISO 27001 A.5.4 RCF-0030 Technical 0 mapped Security charter RCF-0031 Policy 3 mapped Control testing program ISO 27001 A.5.35 ISO 27001 A.5.36 ISO 27001 A.8.29 RCF-0032 Process 3 mapped Control testing program ISO 27001 A.5.27 ISO 27001 A.5.35 ISO 27001 A.5.36 RCF-0033 Technical 3 mapped Control testing program ISO 27001 A.8.16 ISO 27001 A.8.29 ISO 27001 A.8.8 RCF-0034 Policy 3 mapped Issues management ISO 27001 A.5.24 ISO 27001 A.5.25 ISO 27001 A.5.36 RCF-0035 Process 3 mapped Issues management ISO 27001 A.5.25 ISO 27001 A.5.26 ISO 27001 A.5.27 RCF-0036 Technical 3 mapped Issues management ISO 27001 A.5.25 ISO 27001 A.8.15 ISO 27001 A.8.16
ISO/IEC 27001:2022 A.5.1 Policies for information security A.5.2 Information security roles and responsibilities A.5.3 Segregation of duties A.5.4 Management responsibilities A.5.7 Threat intelligence A.5.8 Information security in project management A.5.15 Access control A.5.18 Access rights A.5.19 Information security in supplier relationships A.5.20 Addressing information security within supplier agreements A.5.21 Managing information security in the ICT supply chain A.5.22 Monitoring, review and change management of supplier services A.5.24 Information security incident management planning and preparation A.5.25 Assessment and decision on information security events A.5.26 Response to information security incidents A.5.27 Learning from information security incidents A.5.28 Collection of evidence A.5.31 Legal, statutory, regulatory and contractual requirements A.5.33 Protection of records A.5.34 Privacy and protection of personal identifiable information (PII) A.5.35 Independent review of information security A.5.36 Compliance with policies, rules and standards for information security A.5.37 Documented operating procedures A.6.2 Terms and conditions of employment A.8.2 Privileged access rights A.8.8 Management of technical vulnerabilities A.8.9 Configuration management A.8.15 Logging A.8.16 Monitoring activities A.8.24 Use of cryptography A.8.29 Security testing in development and acceptance A.8.34 Protection of information systems during audit testing