Sekit CSF · Governance & Risk · Policy
RCF-0034Issues management
Security issues and findings are formally tracked until resolution
Mapping at a glance
RCF-0034Issues managementGovernance & Risk · Policy
A.5.24Information security incident management planning and preparationISO/IEC 27001:2022A.5.25Assessment and decision on information security eventsISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022GV.RM-06Standardized risk method establishedNIST CSF 2.0GV.RM-07Strategic opportunities characterizedNIST CSF 2.0
RCF-0034 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.24Information security incident management planning and preparationsupportsA written rule that every security issue is logged in one place gives the incident plan a feeder system, so findings from audits or scans surface before they turn into incidents.A.5.25Assessment and decision on information security eventsrelatedLogging every security finding in one place is a broader governance habit that gives event triage somewhere to record confirmed incidents once assessed.A.5.36Compliance with policies, rules and standards for information securityenablesThis policy control keeps a written rule that every security issue is logged in one place and tracked until closed, the record A.5.36's compliance checking relies on.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-06Standardized risk method establishedGV.RM-07Strategic opportunities characterizedID.IM-04Response and recovery plans maintained
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0034?”
Also via MCP, free with account