Sekit CSF · Application Security · Technical
RCF-0126SAST/DAST
Automated SAST and DAST tools integrate into the pipeline and block releases with critical findings
Mapping at a glance
RCF-0126SAST/DASTApplication Security · Technical
RCF-0126 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cyclesupportsThe technical facet integrates SAST and DAST tools into the pipeline so a critical finding automatically stops the release.A.8.29Security testing in development and acceptancesupportsThis Sekit technical control integrates the test tools into the pipeline so a critical finding stops the release, the enforced gate this ISO control expects.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
DE.CM-01Networks monitoredPR.PS-01Configuration management appliedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Application security testing evidence
The proof that code and applications are automatically scanned for flaws (SAST/DAST), including dependencies and APIs.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0126?”
Also via MCP, free with account