NIST CSF 2.0 · derived mapping target
PR.PS-01Configuration management applied
Establish and apply secure configuration baselines so systems start hardened and stay that way, rather than running with risky default settings.
Mapping at a glance
PR.PS-01Configuration management appliedNIST CSF 2.0
PR.PS-01 is covered by 57 Sekit CSF controls. +52 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0115Secure SDLC policy · PolicyRCF-0116Secure SDLC policy · ProcessRCF-0117Secure SDLC policy · TechnicalRCF-0118Threat modeling · PolicyRCF-0119Threat modeling · ProcessRCF-0120Threat modeling · TechnicalRCF-0121Secure code review · PolicyRCF-0122Secure code review · ProcessRCF-0123Secure code review · TechnicalRCF-0124SAST/DAST · PolicyRCF-0125SAST/DAST · ProcessRCF-0126SAST/DAST · TechnicalRCF-0127Dependency/SBOM management · PolicyRCF-0128Dependency/SBOM management · ProcessRCF-0129Dependency/SBOM management · TechnicalRCF-0130CI/CD hardening · PolicyRCF-0131CI/CD hardening · ProcessRCF-0132CI/CD hardening · TechnicalRCF-0133IaC scanning · PolicyRCF-0134IaC scanning · ProcessRCF-0135IaC scanning · TechnicalRCF-0136API security · PolicyRCF-0137API security · ProcessRCF-0138API security · TechnicalRCF-0139Container security · PolicyRCF-0140Container security · ProcessRCF-0141Container security · TechnicalRCF-0142DevSecOps governance · PolicyRCF-0143DevSecOps governance · ProcessRCF-0144DevSecOps governance · TechnicalRCF-0145Configuration baselines · PolicyRCF-0146Configuration baselines · ProcessRCF-0147Configuration baselines · TechnicalRCF-0151MDM/MAM · PolicyRCF-0152MDM/MAM · ProcessRCF-0153MDM/MAM · TechnicalRCF-0160Device hardening · PolicyRCF-0161Device hardening · ProcessRCF-0162Device hardening · TechnicalRCF-0223Configuration management · PolicyRCF-0224Configuration management · ProcessRCF-0225Configuration management · TechnicalRCF-0226Baseline compliance · PolicyRCF-0227Baseline compliance · ProcessRCF-0228Baseline compliance · TechnicalRCF-0328Software supply chain (SBOM) · PolicyRCF-0329Software supply chain (SBOM) · ProcessRCF-0330Software supply chain (SBOM) · TechnicalRCF-0337CSPM posture · PolicyRCF-0338CSPM posture · ProcessRCF-0339CSPM posture · TechnicalRCF-0352SaaS security configuration · PolicyRCF-0353SaaS security configuration · ProcessRCF-0354SaaS security configuration · TechnicalRCF-0364Privacy by design · PolicyRCF-0365Privacy by design · ProcessRCF-0366Privacy by design · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Device hardening baseline
The secure-configuration standard applied to devices when handed out (default settings, disabled services) and how compliance is checked.
Mobile device management configuration
The tool that manages work phones and tablets, able to enforce security rules and remotely wipe a lost device.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.PS-01?”
Also via MCP, free with account