Sekit CSF · Governance & Risk · Policy
RCF-0031Control testing program
Security controls are regularly tested to verify they work as intended
Mapping at a glance
RCF-0031Control testing programGovernance & Risk · Policy
A.5.35Independent review of information securityISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022A.8.29Security testing in development and acceptanceISO/IEC 27001:2022GV.RM-05Lines of communication for risk establishedNIST CSF 2.0ID.IM-01Improvements from evaluationsNIST CSF 2.0
RCF-0031 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.35Independent review of information securitysupportsDefining which controls get tested, how often and by whom turns independent review from an occasional exercise into a planned obligation.A.5.36Compliance with policies, rules and standards for information securityenablesThis policy control defines in writing which controls get tested, how often and by whom, the testing programme A.5.36's compliance verification depends on.A.8.29Security testing in development and acceptancesupportsThis Sekit policy defines which controls get tested, how often and by whom, giving security testing before release the planned structure this ISO control requires.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-05Lines of communication for risk establishedID.IM-01Improvements from evaluationsID.IM-02Improvements from tests and exercisesID.IM-03Improvements from operations
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security metrics report
The report or dashboard the company uses to measure how its security is doing (e.g. incidents, pending patches, training completion) and present it to leadership.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0031?”
Also via MCP, free with account