Sekit CSF · Governance & Risk · Technical
RCF-0036Issues management
Technical tools track and escalate unresolved security issues
Mapping at a glance
RCF-0036Issues managementGovernance & Risk · Technical
RCF-0036 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.25Assessment and decision on information security eventsenablesA tool that timestamps and escalates overdue issues gives the assessment step a system of record instead of a spreadsheet that nobody chases.A.8.15LoggingrelatedA tool that timestamps and tracks security issues shares the record-keeping discipline of A.8.15, but the entries it keeps are remediation tickets, not the system activity events A.8.15 requires logged.A.8.16Monitoring activitiesrelatedTracking security issues with timestamps and escalation manages what monitoring surfaces, but the ticket record is follow-up paperwork, not the detection activity A.8.16 performs.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-06Standardized risk method establishedGV.RM-07Strategic opportunities characterizedID.IM-04Response and recovery plans maintained
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0036?”
Also via MCP, free with account