Sekit CSF · Application Security · Process
RCF-0131CI/CD hardening
Pipeline security controls are consistently applied and reviewed for every build and deployment
Mapping at a glance
RCF-0131CI/CD hardeningApplication Security · Process
RCF-0131 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cyclesupportsThe process facet applies and periodically re-verifies pipeline security controls on every build and deployment instead of configuring them once.A.8.32Change managementsupportsThe Sekit process control applies and periodically verifies pipeline security controls on every deployment, keeping the change pipeline this ISO control governs from degrading after initial setup.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0131?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.