Sekit CSF · Governance & Risk · Policy
RCF-0007Risk assessment
The company formally identifies and documents its security risks
Mapping at a glance
RCF-0007Risk assessmentGovernance & Risk · Policy
RCF-0007 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-01Risk management objectives establishedGV.RM-02Risk appetite and tolerance establishedGV.RM-03Cyber risk in enterprise risk managementID.RA-01Vulnerabilities identified and recordedID.RA-02Threat intelligence received
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0007?”
Also via MCP, free with account