Sekit CSF · Governance & Risk · Process
RCF-0020Metrics & reporting
Security metrics are regularly reviewed and reported to leadership
Mapping at a glance
RCF-0020Metrics & reportingGovernance & Risk · Process
RCF-0020 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.4Management responsibilitiessupportsThis process control produces security indicators on schedule and reviews them with leadership, giving managers the data to see whether their teams follow policy.A.5.35Independent review of information securityrelatedReviewing agreed security indicators with leadership on schedule is management oversight, feeding the same risk picture an independent reviewer later examines. That routine reporting rhythm does not substitute for the independent review A.5.35 requires, so the link stays at related rather than supports.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-05Lines of communication for risk establishedGV.RM-06Standardized risk method establishedID.IM-01Improvements from evaluationsID.IM-02Improvements from tests and exercises
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security metrics report
The report or dashboard the company uses to measure how its security is doing (e.g. incidents, pending patches, training completion) and present it to leadership.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0020?”
Also via MCP, free with account