Sekit CSF · Vulnerability & Configuration · Process
RCF-0233Exposure management
External-facing assets are consistently inventoried and exposure is reduced where it is not business-justified
Mapping at a glance
RCF-0233Exposure managementVulnerability & Configuration · Process
A.5.9Inventory of information and other associated assetsISO/IEC 27001:2022 · Annex A controlsA.8.8Management of technical vulnerabilitiesISO/IEC 27001:2022 · Annex A controlsID.RA-01Vulnerabilities identified and recordedNIST CSF 2.0ID.RA-05Inherent risk understoodNIST CSF 2.0ID.RA-07Changes and exceptions managedNIST CSF 2.0
RCF-0233 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.9Inventory of information and other associated assetsrelatedThis process control keeps an accurate inventory of internet-facing assets and reduces unjustified exposure, a security-driven use of the same asset inventory A.5.9 requires.A.8.8Management of technical vulnerabilitiessupportsThe process facet keeps an accurate inventory of internet-facing assets and shuts down exposure lacking business justification.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.RA-01Vulnerabilities identified and recordedID.RA-05Inherent risk understoodID.RA-07Changes and exceptions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Vulnerability & Configuration controls
Ask Sekura: “What evidence proves RCF-0233?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.