SekitCrosswalk
NIST CSF 2.0 · derived mapping target

PR.PS-02Software maintained

Keep software patched, updated, and retired in line with risk, so known vulnerabilities are closed promptly and unsupported software is removed.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0139Container security · PolicyRCF-0140Container security · ProcessRCF-0141Container security · TechnicalRCF-0145Configuration baselines · PolicyRCF-0146Configuration baselines · ProcessRCF-0147Configuration baselines · TechnicalRCF-0148EDR/anti-malware · PolicyRCF-0149EDR/anti-malware · ProcessRCF-0150EDR/anti-malware · TechnicalRCF-0151MDM/MAM · PolicyRCF-0152MDM/MAM · ProcessRCF-0153MDM/MAM · TechnicalRCF-0154Patch management · PolicyRCF-0155Patch management · ProcessRCF-0156Patch management · TechnicalRCF-0157Removable media control · PolicyRCF-0158Removable media control · ProcessRCF-0159Removable media control · TechnicalRCF-0160Device hardening · PolicyRCF-0161Device hardening · ProcessRCF-0162Device hardening · TechnicalRCF-0175Secure DNS · PolicyRCF-0176Secure DNS · ProcessRCF-0177Secure DNS · TechnicalRCF-0193Time sync · PolicyRCF-0194Time sync · ProcessRCF-0195Time sync · TechnicalRCF-0223Configuration management · PolicyRCF-0224Configuration management · ProcessRCF-0225Configuration management · TechnicalRCF-0226Baseline compliance · PolicyRCF-0227Baseline compliance · ProcessRCF-0228Baseline compliance · TechnicalRCF-0229Patch prioritization · PolicyRCF-0230Patch prioritization · ProcessRCF-0231Patch prioritization · TechnicalRCF-0337CSPM posture · PolicyRCF-0338CSPM posture · ProcessRCF-0339CSPM posture · TechnicalRCF-0346Workload protection · PolicyRCF-0347Workload protection · ProcessRCF-0348Workload protection · TechnicalRCF-0352SaaS security configuration · PolicyRCF-0353SaaS security configuration · ProcessRCF-0354SaaS security configuration · TechnicalRCF-0424Patch/compensating controls (ICS) · PolicyRCF-0425Patch/compensating controls (ICS) · ProcessRCF-0426Patch/compensating controls (ICS) · Technical

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
Patch management report
The proof that security updates are applied on time across devices and systems, with tracking of what is still outstanding.
From the Sekit evidence catalog

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves PR.PS-02?”
Also via MCP, free with account