Sekit CSF · Secure Operations · Policy
RCF-0400Change management
All changes to production systems are formally required to be reviewed and approved before implementation
Mapping at a glance
RCF-0400Change managementSecure Operations · Policy
RCF-0400 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.37Documented operating proceduressupportsThis policy control requires that no change reaches production without prior review and approval, one instance of the documented operating procedures A.5.37 requires for change management.A.8.32Change managementsupportsThis Sekit policy requires in writing that no change reaches production without prior review and approval, the written mandate the testing, records and rollback this ISO control requires are built on.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Change and release management records
The process to review and approve changes to production systems before applying them, and how new versions are released in a controlled way.
From the Sekit evidence catalog
This topic through the other lenses
All Secure Operations controls
Ask Sekura: “What evidence proves RCF-0400?”
Also via MCP, free with account