Sekit CSF · Governance & Risk · Technical
RCF-0012Risk treatment
Technical controls implement the agreed risk treatment measures
Mapping at a glance
RCF-0012Risk treatmentGovernance & Risk · Technical
A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022A.8.8Management of technical vulnerabilitiesISO/IEC 27001:2022A.8.9Configuration managementISO/IEC 27001:2022GV.RM-04Risk response strategy establishedNIST CSF 2.0GV.RM-05Lines of communication for risk establishedNIST CSF 2.0
RCF-0012 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.36Compliance with policies, rules and standards for information securitysupportsThis technical control verifies that each agreed risk measure is genuinely configured and working in the live environment, confirming compliance A.5.36 checks for rather than assuming it.A.8.8Management of technical vulnerabilitiessupportsVerifying that each agreed technical risk measure is genuinely configured in the live environment closes the loop between a vulnerability decision and its implementation.A.8.9Configuration managementsupportsVerifying that each agreed technical risk measure is genuinely configured in the live environment is exactly the drift check A.8.9 requires.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-04Risk response strategy establishedGV.RM-05Lines of communication for risk establishedGV.RM-06Standardized risk method establishedGV.RM-07Strategic opportunities characterized
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Risk assessment and treatment plan
The record where the company identifies its security risks and decides what to do with each one (accept, reduce or transfer), with owners and deadlines.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0012?”
Also via MCP, free with account