Sekit CSF · Family
Data Security
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0091Data classification4 mappingsData is formally classified by sensitivity to determine appropriate protectionRCF-0106Data minimization4 mappingsDigital assets and sensitive data are formally inventoried and trackedRCF-0109Data retention & disposal6 mappingsSecure methods are used to permanently destroy data that is no longer neededRCF-0103DLP monitoring5 mappingsSensitive data is masked or anonymised where full access is not requiredRCF-0094Encryption at rest4 mappingsSensitive data is encrypted when stored to prevent unauthorised accessRCF-0097Encryption in transit4 mappingsSensitive data is encrypted when transmitted to prevent interceptionRCF-0100Key management3 mappingsControls prevent sensitive data from leaving the organisation inappropriatelyRCF-0112Secrets management4 mappingsBackups of critical data are taken regularly and stored securely
Process
RCF-0092Data classification5 mappingsData classification is consistently applied when handling and sharing dataRCF-0107Data minimization4 mappingsThe data inventory is kept current and reviewed regularlyRCF-0110Data retention & disposal5 mappingsSecure disposal procedures are consistently followed for all sensitive dataRCF-0104DLP monitoring6 mappingsData masking is consistently applied in non-production environmentsRCF-0095Encryption at rest3 mappingsEncryption of stored data is consistently applied to all sensitive informationRCF-0098Encryption in transit4 mappingsEncryption in transit is consistently applied to all sensitive communicationsRCF-0101Key management3 mappingsDLP rules are consistently applied to detect and block data exfiltrationRCF-0113Secrets management3 mappingsBackup procedures are consistently followed and backup integrity is verified
Technical
RCF-0093Data classification5 mappingsTechnical controls enforce data handling rules based on classification labelsRCF-0108Data minimization4 mappingsTechnical tools automatically discover and catalogue sensitive data assetsRCF-0111Data retention & disposal5 mappingsTechnical tools certify and log secure disposal of sensitive dataRCF-0105DLP monitoring5 mappingsTechnical controls automatically mask sensitive data in lower environmentsRCF-0096Encryption at rest4 mappingsTechnical controls enforce encryption at rest on all sensitive data storesRCF-0099Encryption in transit5 mappingsTechnical controls enforce encryption in transit across all channelsRCF-0102Key management3 mappingsTechnical DLP tools monitor and block unauthorised data transfersRCF-0114Secrets management3 mappingsTechnical controls automate backups and verify restoration capability
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in ISO/IEC 42001:2023 — Annex A
Ask Sekura: “What evidence proves Data Security?”
Also via MCP, free with account