Sekit CSF · Cloud Security · Technical
RCF-0336Cloud IAM
Technical controls enforce identity-based access policies across all cloud environments and services
Mapping at a glance
RCF-0336Cloud IAMCloud Security · Technical
RCF-0336 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.16Identity managementsupportsEnforcing MFA, role-based permissions and conditional restrictions in the cloud is identity management applied technically to cloud accounts, the systems A.5.16 asks organisations to cover.A.8.2Privileged access rightssupportsEnforcing MFA and role-based permissions instead of standing cloud admin rights is the technical control that delivers A.8.2's least-privilege objective in the cloud.A.8.5Secure authenticationsupportsCloud access enforces MFA for everyone and role-based permissions instead of standing admin rights, carrying A.8.5's authentication requirement into cloud environments.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.AA-01Identities and credentials managedPR.AA-03Users and devices authenticatedPR.AA-05Access permissions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Cloud Security controls
Ask Sekura: “What evidence proves RCF-0336?”
Also via MCP, free with account