Sekit CSF · Vulnerability & Configuration · Process
RCF-0233Exposure management
External-facing assets are consistently inventoried and exposure is reduced where it is not business-justified
Mapping at a glance
RCF-0233Exposure managementVulnerability & Configuration · Process
RCF-0233 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.9Inventory of information and other associated assetsrelatedThis process control keeps an accurate inventory of internet-facing assets and reduces unjustified exposure, a security-driven use of the same asset inventory A.5.9 requires.A.8.8Management of technical vulnerabilitiessupportsThe process facet keeps an accurate inventory of internet-facing assets and shuts down exposure lacking business justification.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.RA-01Vulnerabilities identified and recordedID.RA-05Inherent risk understoodID.RA-07Changes and exceptions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Vulnerability & Configuration controls
Ask Sekura: “What evidence proves RCF-0233?”
Also via MCP, free with account