Sekit CSF · Cloud Security · Process
RCF-0353SaaS security configuration
SaaS applications are consistently configured to meet security standards and reviewed when settings change
Mapping at a glance
RCF-0353SaaS security configurationCloud Security · Process
RCF-0353 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.22Monitoring, review and change management of supplier servicessupportsRe-checking SaaS security settings whenever a vendor changes them or the company changes plans is A.5.22's change management requirement applied to supplier-driven configuration changes.A.8.9Configuration managementsupportsConfiguring every SaaS application to the standard at adoption and re-checking when vendor settings change keeps SaaS configuration from silently drifting.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
CE2.1Remove unnecessary accounts and softwareCE2.2Change default and guessable passwordsCE4.3Require multi-factor authentication
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
From the Sekit evidence catalog
This topic through the other lenses
All Cloud Security controls
Ask Sekura: “What evidence proves RCF-0353?”
Also via MCP, free with account