Sekit CSF · Governance & Risk · Process
RCF-0014Exception management
Exception approvals follow a consistent process with defined time limits
Mapping at a glance
RCF-0014Exception managementGovernance & Risk · Process
RCF-0014 maps to 4 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.4Management responsibilitiessupportsThis process control runs exception approvals through a recorded, time-bound flow, giving managers a concrete mechanism to require policy compliance while handling justified deviations.A.5.36Compliance with policies, rules and standards for information securitysupportsThis process control runs exception approvals through a consistent, recorded flow and revisits every exception before it expires, the discipline A.5.36 checks compliance against.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Information security policy
The written, leadership-approved document that sets the company's security rules: what is protected, how, and who is responsible.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0014?”
Also via MCP, free with account