Sekit CSF · Identity & Access Management · Technical
RCF-0069Least privilege / RBAC
Permissions are enforced at the system level not based on user behaviour
Mapping at a glance
RCF-0069Least privilege / RBACIdentity & Access Management · Technical
RCF-0069 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.15Access controlsupportsEnforcing permissions at the platform level, with no shared logins standing in for real access control, is what makes A.5.15's role-based rules hold in practice.A.8.3Information access restrictionsupportsThe Sekit technical control enforces permissions at the platform level with no shared logins, the concrete enforcement mechanism this ISO control requires rather than a policy alone.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Identity & Access Management controls
Ask Sekura: “What evidence proves RCF-0069?”
Also via MCP, free with account