Sekit CSF · Application Security · Policy
RCF-0142DevSecOps governance
Accountability for security within development and operations teams is formally defined
Mapping at a glance
RCF-0142DevSecOps governanceApplication Security · Policy
A.5.1Policies for information securityISO/IEC 27001:2022 · Annex A controlsA.5.2Information security roles and responsibilitiesISO/IEC 27001:2022 · Annex A controlsGV.PO-01Cybersecurity policy establishedNIST CSF 2.0PR.PS-01Configuration management appliedNIST CSF 2.0PR.PS-03Hardware maintainedNIST CSF 2.0
RCF-0142 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.1Policies for information securitysupportsSekit's DevSecOps governance policy, one of A.5.1's topic-specific policies, assigns and documents who is accountable for security inside the development and operations teams.A.5.2Information security roles and responsibilitiessupportsAssigning a named accountable person for development and operations security is a role definition inside a specific function, supporting A.5.2's broader requirement to map responsibilities to people.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.PO-01Cybersecurity policy establishedPR.PS-01Configuration management appliedPR.PS-03Hardware maintained
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0142?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.