Sekit CSF · Endpoint Security · Policy
RCF-0154Patch management
The company formally requires that security patches are applied to all systems within defined timeframes
Mapping at a glance
RCF-0154Patch managementEndpoint Security · Policy
A.5.1Policies for information securityISO/IEC 27001:2022 · Annex A controlsA.8.8Management of technical vulnerabilitiesISO/IEC 27001:2022 · Annex A controlsID.RA-01Vulnerabilities identified and recordedNIST CSF 2.0PR.PS-02Software maintainedNIST CSF 2.0CE3.2Apply critical updates within 14 daysCyber Essentials
RCF-0154 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.1Policies for information securitysupportsSekit's Patch management policy is a topic-specific policy under A.5.1 that sets deadlines by severity for applying security updates across every system the company runs.A.8.8Management of technical vulnerabilitiessupportsThis policy facet sets written deadlines for applying security updates by severity across every system the company runs, the timeline backbone A.8.8 asks for.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Patch management report
The proof that security updates are applied on time across devices and systems, with tracking of what is still outstanding.
From the Sekit evidence catalog
This topic through the other lenses
All Endpoint Security controls
Ask Sekura: “What evidence proves RCF-0154?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.