Sekit CSF · Vulnerability & Configuration · Policy
RCF-0223Configuration management
Security configuration standards are formally defined and required for all system types
Mapping at a glance
RCF-0223Configuration managementVulnerability & Configuration · Policy
RCF-0223 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.1Policies for information securitysupportsSekit's Configuration management policy, one of the topic-specific policies A.5.1 expects, sets security configuration standards for each system type, covering at minimum operating systems, cloud services and network devices.A.8.9Configuration managementsupportsWritten security configuration standards for each system type, operating systems, cloud services, network devices, is the policy expression of A.8.9's requirement.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Device hardening baseline
The secure-configuration standard applied to devices when handed out (default settings, disabled services) and how compliance is checked.
From the Sekit evidence catalog
This topic through the other lenses
All Vulnerability & Configuration controls
Ask Sekura: “What evidence proves RCF-0223?”
Also via MCP, free with account