NIST CSF 2.0 · derived mapping target
RS.CO-03Information shared with stakeholders
Share the right information with designated stakeholders during an incident so everyone who needs to act has what they need, without leaking sensitive detail.
Mapping at a glance
RS.CO-03Information shared with stakeholdersNIST CSF 2.0
RS.CO-03 is covered by 3 Sekit CSF controls. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0271Notification & escalation · PolicyRCF-0272Notification & escalation · ProcessRCF-0273Notification & escalation · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Incident response plan
The plan defining how the company acts when a security incident occurs: who does what, who is notified, and within what timeframes.
Crisis communications plan
The plan defining how the company communicates during and after a serious incident: what is said to employees, customers, regulators and the public, who the spokesperson is, through which channels, and with what approved messaging.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves RS.CO-03?”
Also via MCP, free with account