Sekit CSF · Compliance & Audit · Policy
RCF-0382Audit readiness
The company formally maintains a state of readiness to demonstrate compliance to external auditors at any time
Mapping at a glance
RCF-0382Audit readinessCompliance & Audit · Policy
A.5.35Independent review of information securityISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022GV.RM-05Lines of communication for risk establishedNIST CSF 2.0ID.IM-03Improvements from operationsNIST CSF 2.0ID.IM-04Response and recovery plans maintainedNIST CSF 2.0
RCF-0382 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.35Independent review of information securitysupportsA commitment to continuous audit readiness, with defined scope and named response roles, makes this control's independent reviews easier to run without scrambling to prepare each time.A.5.36Compliance with policies, rules and standards for information securityenablesThis policy control commits in writing to continuous audit readiness with defined scope, current evidence and named response roles, the readiness posture A.5.36's compliance checking supports.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-05Lines of communication for risk establishedID.IM-03Improvements from operationsID.IM-04Response and recovery plans maintained
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Audit evidence and corrective actions log
The file where proof that controls work is kept, plus the tracking of audit findings through to closure.
From the Sekit evidence catalog
This topic through the other lenses
All Compliance & Audit controls
Ask Sekura: “What evidence proves RCF-0382?”
Also via MCP, free with account