Sekit CSF · Governance & Risk · Technical
RCF-0024Internal audit
Technical tools support automated audit evidence collection
Mapping at a glance
RCF-0024Internal auditGovernance & Risk · Technical
RCF-0024 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.28Collection of evidencerelatedAutomating audit evidence collection from system data is a parallel discipline to forensic evidence collection, both about making proof reliable rather than manually gathered, though for different purposes.A.8.15LoggingrelatedAutomated audit evidence collection draws on the logs A.8.15 requires exist, supporting audit efficiency rather than the logging practice itself.A.8.34Protection of information systems during audit testingsupportsThis Sekit technical control automates the collection of audit evidence from system data rather than manual screenshots, reducing the risk that the audit activity itself disrupts the systems being checked, as this ISO control requires.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-05Lines of communication for risk establishedID.IM-03Improvements from operationsID.IM-04Response and recovery plans maintained
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Internal audit report
The output of the internal reviews the company runs on its own security controls, with findings and improvement actions.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0024?”
Also via MCP, free with account