SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.1Policies for information security

Define a top-level information security policy plus supporting topic-specific policies, get them approved by management, and communicate them to staff and relevant outsiders. Review them on a schedule and after major changes.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0001Policy management · PolicysupportsSekit's Policy management control produces the leadership-approved written security policy naming an owner, scope and review cycle, one piece of A.5.1's full requirement alongside the topic-specific policies and communication step mapped separately here.RCF-0002Policy management · ProcesssupportsRunning a recurring routine that puts security policies in front of every employee and checks they are followed makes A.5.1's communication requirement work day to day rather than sit unread in a folder.RCF-0013Exception management · PolicysupportsSekit's Exception management policy, one of A.5.1's topic-specific policies, spells out how staff request, get approval for, and time-limit any deviation from the rules.RCF-0028Security charter · PolicysupportsSekit's Security charter is part of A.5.1's topic-specific policy layer: it is a management-signed statement naming an accountable owner and granting that person a mandate to act.RCF-0073SSO & federation · PolicysupportsSekit's SSO and federation standard, one of the topic-specific policies A.5.1 expects, requires business applications to authenticate through the central identity provider under documented exception criteria.RCF-0076Password policy · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Password policy sets minimum length, bans reuse across services, and requires a password manager for staff credentials.RCF-0094Encryption at rest · PolicysupportsSekit's Encryption at rest policy is a topic-specific policy under A.5.1 that requires sensitive data to stay encrypted on laptops, servers, cloud storage, backups and removable media.RCF-0109Data retention & disposal · PolicysupportsSekit's Data retention and disposal policy, one of A.5.1's topic-specific policies, sets legal minimums for how long each data category is kept and how it is destroyed afterward.RCF-0112Secrets management · PolicysupportsSekit's Secrets management policy is part of A.5.1's topic-specific policy layer: it requires passwords, API keys and other credentials to live only in an approved vault, never in documents or chat.RCF-0115Secure SDLC policy · PolicysupportsSekit's Secure SDLC policy, one of the topic-specific policies A.5.1 expects, builds security requirements into every stage of development, from design through release, for in-house and outsourced work alike.RCF-0121Secure code review · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Secure code review policy requires a security-focused review of every code change before it reaches production.RCF-0124SAST/DAST · PolicysupportsSekit's SAST/DAST policy is a topic-specific policy under A.5.1 that requires automated static and dynamic security testing of applications before each release.RCF-0127Dependency/SBOM management · PolicysupportsSekit's Dependency and SBOM management policy, one of A.5.1's topic-specific policies, mandates that every third-party component used in company applications is inventoried and accounted for.RCF-0130CI/CD hardening · PolicysupportsSekit's CI/CD hardening policy is part of A.5.1's topic-specific policy layer: it sets written security requirements for the build and deployment pipeline, treating it as a production system in its own right.RCF-0133IaC scanning · PolicysupportsSekit's IaC scanning policy, one of the topic-specific policies A.5.1 expects, requires infrastructure-as-code templates to pass a security scan before they are deployed.RCF-0136API security · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's API security policy documents the authentication, authorisation and data-handling requirements every company API must meet.RCF-0139Container security · PolicysupportsSekit's Container security policy is a topic-specific policy under A.5.1 that sets written standards for how container images are built, stored and run.RCF-0142DevSecOps governance · PolicysupportsSekit's DevSecOps governance policy, one of A.5.1's topic-specific policies, assigns and documents who is accountable for security inside the development and operations teams.RCF-0145Configuration baselines · PolicysupportsSekit's Configuration baselines policy is part of A.5.1's topic-specific policy layer: it sets a management-approved configuration standard for every device type, reviewed at least once a year.RCF-0148EDR/anti-malware · PolicysupportsSekit's EDR/anti-malware policy, one of the topic-specific policies A.5.1 expects, requires approved endpoint protection on every company device that nobody may disable.RCF-0151MDM/MAM · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's MDM/MAM policy requires any phone or tablet used for work email or chat to enrol in mobile device management first.RCF-0154Patch management · PolicysupportsSekit's Patch management policy is a topic-specific policy under A.5.1 that sets deadlines by severity for applying security updates across every system the company runs.RCF-0157Removable media control · PolicysupportsSekit's Removable media control policy, one of A.5.1's topic-specific policies, restricts USB drives and similar storage to approved, justified business needs only.RCF-0160Device hardening · PolicysupportsSekit's Device hardening policy is part of A.5.1's topic-specific policy layer: it names the services, features and defaults that must be disabled to shrink the attack surface.RCF-0163Disk encryption · PolicysupportsSekit's Disk encryption policy, one of the topic-specific policies A.5.1 expects, requires full disk encryption on every laptop, portable device and machine holding sensitive data.RCF-0166Local admin control · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Local admin control policy keeps day-to-day accounts free of administrator rights unless granted on approval, per person and per need.RCF-0169Network segmentation · PolicysupportsSekit's Network segmentation policy is a topic-specific policy under A.5.1 that names the network zones the company operates and the traffic rules allowed between them.RCF-0172Firewall management · PolicysupportsSekit's Firewall management policy, one of A.5.1's topic-specific policies, states the default-deny stance and who may request and approve rule changes.RCF-0175Secure DNS · PolicysupportsSekit's Secure DNS policy is part of A.5.1's topic-specific policy layer: it states which resolvers company devices must use and protects the company's own domain records from tampering.RCF-0178Email security · PolicysupportsSekit's Email security policy, one of the topic-specific policies A.5.1 expects, requires protection against spoofing and malicious content plus a clear path for staff to report suspicious messages.RCF-0181TLS termination/hardening · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's TLS termination policy requires current TLS versions and ciphers with a named owner for keeping certificates valid.RCF-0184Zero Trust network access · PolicysupportsSekit's Zero Trust network access policy is a topic-specific policy under A.5.1 that grants access per request based on verified identity and device state, never on network location.RCF-0187VPN management · PolicysupportsSekit's VPN management policy, one of A.5.1's topic-specific policies, governs who may use the VPN, from which devices, and with what authentication.RCF-0190Wireless security · PolicysupportsSekit's Wireless security policy is part of A.5.1's topic-specific policy layer: it sets the encryption standard, passphrase handling and guest separation for every wireless network the company operates.RCF-0193Time sync · PolicysupportsSekit's Time sync policy, one of the topic-specific policies A.5.1 expects, requires every server, workstation and network device to synchronise its clock to a trusted time source.RCF-0196Centralized logging · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Centralized logging policy states which systems must send security events to a central log platform and names who keeps that pipeline complete.RCF-0199SIEM use cases · PolicysupportsSekit's SIEM use cases policy is a topic-specific policy under A.5.1 that documents which threat scenarios the monitoring platform is expected to detect, rather than leaving coverage to vendor defaults.RCF-0202Alerting & triage · PolicysupportsSekit's Alerting and triage policy, one of A.5.1's topic-specific policies, defines how security alerts are prioritised, assigned, and how quickly each priority level must be looked at.RCF-0205UEBA/behavior analytics · PolicysupportsSekit's UEBA/behavior analytics policy is part of A.5.1's topic-specific policy layer: it records the deliberate decision on whether anomaly detection is in scope, what it watches and who acts on it.RCF-0208Log protection & retention · PolicysupportsSekit's Log protection and retention policy, one of the topic-specific policies A.5.1 expects, defines how long each log category is kept and what protects it from tampering, even by an attacker with admin rights.RCF-0211Detection engineering · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Detection engineering policy commits to building detection logic tailored to the company's own systems rather than relying on vendor defaults alone.RCF-0214Telemetry coverage · PolicysupportsSekit's Telemetry coverage policy is a topic-specific policy under A.5.1 that names which systems must produce security telemetry so any visibility gap is a documented decision, not an accident.RCF-0217Vulnerability scanning · PolicysupportsSekit's Vulnerability scanning policy, one of A.5.1's topic-specific policies, requires every server, workstation and externally reachable service to be scanned for known vulnerabilities on a defined schedule.RCF-0220Vulnerability remediation SLAs · PolicysupportsSekit's Vulnerability remediation SLA policy is part of A.5.1's topic-specific policy layer: it sets deadlines for fixing vulnerabilities by severity, from days for critical issues to weeks for minor ones.RCF-0223Configuration management · PolicysupportsSekit's Configuration management policy, one of the topic-specific policies A.5.1 expects, sets security configuration standards for each system type, covering at minimum operating systems, cloud services and network devices.RCF-0226Baseline compliance · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Baseline compliance policy commits to measuring what share of systems meet approved baselines and reporting that figure to management.RCF-0229Patch prioritization · PolicysupportsSekit's Patch prioritization policy is a topic-specific policy under A.5.1 that ranks patches by combining flaw severity, asset criticality and whether the flaw is being actively exploited.RCF-0232Exposure management · PolicysupportsSekit's Exposure management policy, one of A.5.1's topic-specific policies, states that the company maintains a view of everything it exposes to the internet and trims what has no business need.RCF-0235Penetration testing · PolicysupportsSekit's Penetration testing policy is part of A.5.1's topic-specific policy layer: it commits to commissioning an independent test at a defined interval and after any major change.RCF-0238Backup policy · PolicysupportsSekit's Backup policy, one of the topic-specific policies A.5.1 expects, defines what data is backed up, how often, how long copies are kept, and how one copy resists tampering or ransomware.RCF-0241Immutable/offsite backups · PolicysupportsAmong A.5.1's topic-specific policies, Sekit's Immutable and offsite backups policy requires at least one backup copy that attackers cannot alter or delete.RCF-0244Backup coverage · PolicysupportsSekit's Backup coverage policy is a topic-specific policy under A.5.1 that names which systems and data are critical enough that all of them must be backed up.RCF-0247Restore testing · PolicysupportsSekit's Restore testing policy, one of A.5.1's topic-specific policies, requires backup restores to be tested on a defined schedule with documented, reviewable results.RCF-0250RTO/RPO definitions · PolicysupportsSekit's RTO/RPO definitions policy is part of A.5.1's topic-specific policy layer: it sets the maximum tolerable downtime and data loss allowed for each critical system.RCF-0430Safety alignment · PolicysupportsSekit's Safety alignment policy, one of the topic-specific policies A.5.1 expects, states that operational safety takes precedence and defines cybersecurity measures for production systems jointly with those responsible for safety.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Information security policy
The written, leadership-approved document that sets the company's security rules: what is protected, how, and who is responsible.
From the Sekit evidence catalog

In practice

In practice a small or mid-size company gets by with one short information security policy document that names an owner, states scope, and links out to topic-specific rules for passwords, encryption and acceptable use rather than repeating them inline. Auditors open the information security policy and check three things: a real approval date and signature from leadership, a review date that has passed and was acted on, not only printed on the cover, and evidence staff were told when it changed. The common failure is a downloaded template nobody customized, still referencing a different company or a review cycle that lapsed two years ago.

Common gaps

The policy was approved once at company formation and never reviewed again, even though headcount and the technology stack have changed substantially since.
Topic-specific policies referenced in the main document, such as password or encryption rules, do not exist or were never linked from the policy itself.
Staff sign an acknowledgment during onboarding but nobody can produce a record the policy was communicated again after a material update.

Questions your auditor will ask

Who approved the current version of the information security policy and when?
Point to the signed approval on the information security policy, naming the accountable executive and the approval date, not a document creation timestamp.
How often is the policy reviewed, and can you show the last review took place?
Show the review cadence stated in the policy plus a dated record, such as a change log entry or meeting minute, confirming the last scheduled review happened.
How do employees and contractors learn the policy changed?
Point to the onboarding acknowledgment process and any all-staff notice or training session sent after the most recent substantive policy update.
Does the policy cover topics like passwords, encryption and remote access, or only general principles?
Walk through the linked topic-specific policies referenced from the main document, such as the password and encryption standards, and confirm each has its own owner and review date.

Where regulation demands it

NIS2 art. 1.1 (Policy on the security of network and information systems) requires the same top-level, management-approved policy this control asks for.
ENS org.1 (Política de seguridad) sets the same expectation for a formal, approved security policy as a baseline control.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.1?”
Also via MCP, free with account