SekitCrosswalk
Sekit CSF · Asset Management · Policy

RCF-0043Data inventory

All personal and sensitive data held by the company is formally required to be identified and recorded

Maps to ISO/IEC 27001:2022

Curated mapping with the reasoning, not just the codes.

Maps to NIST CSF 2.0

Curated mapping with the reasoning, not just the codes.

Maps to ISO/IEC 42001:2023 — Annex A

Curated mapping with the reasoning, not just the codes.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Data inventory and classification
The record of the personal and sensitive data the company holds, where it lives and how it is classified by sensitivity.
From the Sekit evidence catalog

This topic through the other lenses

All Asset Management controls

Ask Sekura: “What evidence proves RCF-0043?”
Also via MCP, free with account