Sekit CSF · Secure Operations · Process
RCF-0404Release management
Releases are consistently tested, approved and deployed through a controlled release process
Mapping at a glance
RCF-0404Release managementSecure Operations · Process
RCF-0404 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.29Security testing in development and acceptancesupportsThis Sekit process control puts every release through testing and approval before deployment with records kept, the acceptance discipline this ISO control requires before software reaches production.A.8.31Separation of development, test and production environmentssupportsThe Sekit process control puts every release through testing and approval before deployment, the discipline this ISO control requires to keep unfinished work from reaching production.A.8.32Change managementsupportsThis Sekit process control puts every release through testing and approval with records kept, applying the change discipline this ISO control requires to the release step specifically.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Change and release management records
The process to review and approve changes to production systems before applying them, and how new versions are released in a controlled way.
From the Sekit evidence catalog
This topic through the other lenses
All Secure Operations controls
Ask Sekura: “What evidence proves RCF-0404?”
Also via MCP, free with account