Sekit CSF · Application Security · Process
RCF-0143DevSecOps governance
Security is consistently embedded into development team practices and sprint cycles
Mapping at a glance
RCF-0143DevSecOps governanceApplication Security · Process
RCF-0143 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.4Management responsibilitiesrelatedThis process control makes security a recurring part of sprint planning, a development-team instance of managers enforcing security expectations within their own domain.A.8.25Secure development life cycleenablesThis process facet makes security work a visible, recurring part of sprint planning, keeping A.8.25's security activities embedded rather than bolted on at the end.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.PO-01Cybersecurity policy establishedPR.PS-01Configuration management appliedPR.PS-03Hardware maintained
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0143?”
Also via MCP, free with account