Sekit CSF · Application Security · Process
RCF-0140Container security
Container images and configurations are consistently reviewed against security standards
Mapping at a glance
RCF-0140Container securityApplication Security · Process
RCF-0140 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.9Configuration managementsupportsReviewing container images and runtime configurations against the standard on a schedule is A.8.9's baseline-review practice applied to containers.A.8.25Secure development life cyclerelatedThe process facet reviews container images and runtime configurations against the security standard on a recurring schedule.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-02Software maintainedPR.PS-04Logs generated for monitoring
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
CE2.1Remove unnecessary accounts and softwareCE3.1Use licensed and supported softwareCE3.2Apply critical updates within 14 days
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0140?”
Also via MCP, free with account