Sekit CSF · Compliance & Audit · Process
RCF-0380Regulatory mapping
Regulatory requirements are consistently translated into control obligations and assigned to accountable owners
Mapping at a glance
RCF-0380Regulatory mappingCompliance & Audit · Process
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022GV.OC-01Organizational mission understoodNIST CSF 2.0GV.OC-02Stakeholder needs understoodNIST CSF 2.0GV.OC-05Dependencies understoodNIST CSF 2.0
RCF-0380 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.31Legal, statutory, regulatory and contractual requirementssupportsTurning each identified regulatory requirement into a concrete, owned obligation is what makes the mapping behind this control actionable rather than a static list.A.5.36Compliance with policies, rules and standards for information securitysupportsThis process control turns each regulatory requirement into a concrete, owned obligation and reworks the mapping as regulations or the business change, keeping A.5.36's compliance basis current.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.OC-01Organizational mission understoodGV.OC-02Stakeholder needs understoodGV.OC-05Dependencies understood
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Regulatory obligations register
The list of laws, regulations and frameworks that apply to the company (e.g. GDPR, sector rules) and how they map to your internal controls.
From the Sekit evidence catalog
This topic through the other lenses
All Compliance & Audit controls
Ask Sekura: “What evidence proves RCF-0380?”
Also via MCP, free with account