Sekit CSF · Cloud Security · Process
RCF-0335Cloud IAM
Cloud access rights are consistently reviewed and aligned with the principle of least privilege
Mapping at a glance
RCF-0335Cloud IAMCloud Security · Process
RCF-0335 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.18Access rightssupportsReviewing cloud access rights on a recurring cycle and trimming what exceeds a person's role is A.5.18's access review requirement carried into cloud platforms.A.8.2Privileged access rightssupportsReviewing cloud access rights on a recurring cycle and removing leavers' access the day they go extends A.8.2's privileged access discipline into cloud environments.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.AA-01Identities and credentials managedPR.AA-03Users and devices authenticatedPR.AA-05Access permissions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Cloud Security controls
Ask Sekura: “What evidence proves RCF-0335?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.