Sekit CSF · Compliance & Audit · Policy
RCF-0379Regulatory mapping
All regulations and frameworks applicable to the company are formally identified and mapped to internal controls
Mapping at a glance
RCF-0379Regulatory mappingCompliance & Audit · Policy
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022GV.OC-01Organizational mission understoodNIST CSF 2.0GV.OC-02Stakeholder needs understoodNIST CSF 2.0GV.OC-05Dependencies understoodNIST CSF 2.0
RCF-0379 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.31Legal, statutory, regulatory and contractual requirementsequivalentAn approved register mapping every applicable law and framework to the internal controls that satisfy it is this control's requirement, made explicit and traceable.A.5.36Compliance with policies, rules and standards for information securityenablesThis policy control maintains an approved register of every law and framework applying to the company, mapped to the controls that satisfy it, the map A.5.36 checks compliance against.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.OC-01Organizational mission understoodGV.OC-02Stakeholder needs understoodGV.OC-05Dependencies understood
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Regulatory obligations register
The list of laws, regulations and frameworks that apply to the company (e.g. GDPR, sector rules) and how they map to your internal controls.
From the Sekit evidence catalog
This topic through the other lenses
All Compliance & Audit controls
Ask Sekura: “What evidence proves RCF-0379?”
Also via MCP, free with account