Sekit CSF · Privacy · Technical
RCF-0366Privacy by design
Technical architecture enforces privacy controls by default
Mapping at a glance
RCF-0366Privacy by designPrivacy · Technical
A.5.34Privacy and protection of personal identifiable information (PII)ISO/IEC 27001:2022A.8.25Secure development life cycleISO/IEC 27001:2022A.8.27Secure system architecture and engineering principlesISO/IEC 27001:2022GV.PO-02Cybersecurity policy maintainedNIST CSF 2.0PR.DS-01Data-at-rest protectedNIST CSF 2.0
RCF-0366 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.34Privacy and protection of personal identifiable information (PII)supportsConfiguring systems so the privacy-protective option is the default, minimal fields, retention limits, opt-in sharing, is what privacy by design looks like at the technical level.A.8.25Secure development life cyclerelatedSystems default to the privacy-protective option, minimal fields, retention limits, opt-in sharing, a design-time control that complements A.8.25's secure-development focus.A.8.27Secure system architecture and engineering principlessupportsThe technical facet makes the privacy-protective option the default across systems, embedding a design principle rather than relying on developers to remember it.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.PO-02Cybersecurity policy maintainedPR.DS-01Data-at-rest protectedPR.PS-01Configuration management applied
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
DPIA and cross-border transfer records
The privacy impact assessments done before new data processing and the records of personal-data transfers to other countries.
From the Sekit evidence catalog
This topic through the other lenses
All Privacy controls
Ask Sekura: “What evidence proves RCF-0366?”
Also via MCP, free with account