Sekit CSF · Governance & Risk · Technical
RCF-0021Metrics & reporting
Technical dashboards provide real-time visibility of security metrics
Mapping at a glance
RCF-0021Metrics & reportingGovernance & Risk · Technical
RCF-0021 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.7Threat intelligencerelatedThis technical control automates a metrics dashboard for security posture, a different data feed than threat intelligence but the same discipline of turning raw signal into visibility.A.8.15LoggingrelatedAutomating security metrics into a dashboard depends on the same underlying event data A.8.15 requires be logged, but the dashboard reports on posture rather than producing or protecting the logs.A.8.16Monitoring activitiesrelatedA dashboard of security metrics reports on what monitoring already detected, downstream of the detection activity A.8.16 requires.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-05Lines of communication for risk establishedGV.RM-06Standardized risk method establishedID.IM-01Improvements from evaluationsID.IM-02Improvements from tests and exercises
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security metrics report
The report or dashboard the company uses to measure how its security is doing (e.g. incidents, pending patches, training completion) and present it to leadership.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0021?”
Also via MCP, free with account