Sekit CSF · Compliance & Audit · Technical
RCF-0381Regulatory mapping
Technical tools maintain a live mapping between regulatory requirements and the controls that address them
Mapping at a glance
RCF-0381Regulatory mappingCompliance & Audit · Technical
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022GV.OC-01Organizational mission understoodNIST CSF 2.0GV.OC-02Stakeholder needs understoodNIST CSF 2.0GV.OC-05Dependencies understoodNIST CSF 2.0
RCF-0381 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.31Legal, statutory, regulatory and contractual requirementsenablesA tool that keeps the requirement-to-control mapping current and shows gaps at a glance is how this control stays accurate as regulations and the business change.A.5.36Compliance with policies, rules and standards for information securityenablesThis technical control holds the requirement-to-control mapping in a tool that stays current and flags obligations lacking a covering control, supporting the visibility A.5.36's compliance checking needs.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.OC-01Organizational mission understoodGV.OC-02Stakeholder needs understoodGV.OC-05Dependencies understood
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Regulatory obligations register
The list of laws, regulations and frameworks that apply to the company (e.g. GDPR, sector rules) and how they map to your internal controls.
From the Sekit evidence catalog
This topic through the other lenses
All Compliance & Audit controls
Ask Sekura: “What evidence proves RCF-0381?”
Also via MCP, free with account