Sekit CSF · Application Security · Process
RCF-0131CI/CD hardening
Pipeline security controls are consistently applied and reviewed for every build and deployment
Mapping at a glance
RCF-0131CI/CD hardeningApplication Security · Process
RCF-0131 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cyclesupportsThe process facet applies and periodically re-verifies pipeline security controls on every build and deployment instead of configuring them once.A.8.32Change managementsupportsThe Sekit process control applies and periodically verifies pipeline security controls on every deployment, keeping the change pipeline this ISO control governs from degrading after initial setup.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0131?”
Also via MCP, free with account