Sekit CSF · Cloud Security · Policy
RCF-0334Cloud IAM
Access to cloud environments is formally governed by policies defining who can access what and under what conditions
Mapping at a glance
RCF-0334Cloud IAMCloud Security · Policy
RCF-0334 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.15Access controlsupportsGoverning cloud roles, restricting administrator access and reviewing rights on a schedule extends A.5.15's access control requirement into cloud platforms specifically.A.5.23Information security for use of cloud servicessupportsThe cloud access policy facet supports A.5.23 by setting who gets which cloud role, how admin access is restricted, and when rights get reviewed.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.AA-01Identities and credentials managedPR.AA-03Users and devices authenticatedPR.AA-05Access permissions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Cloud Security controls
Ask Sekura: “What evidence proves RCF-0334?”
Also via MCP, free with account