Sekit CSF · Application Security · Technical
RCF-0126SAST/DAST
Automated SAST and DAST tools integrate into the pipeline and block releases with critical findings
Mapping at a glance
RCF-0126SAST/DASTApplication Security · Technical
A.8.25Secure development life cycleISO/IEC 27001:2022 · Annex A controlsA.8.29Security testing in development and acceptanceISO/IEC 27001:2022 · Annex A controlsDE.CM-01Networks monitoredNIST CSF 2.0PR.PS-01Configuration management appliedNIST CSF 2.0PR.PS-04Logs generated for monitoringNIST CSF 2.0
RCF-0126 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cyclesupportsThe technical facet integrates SAST and DAST tools into the pipeline so a critical finding automatically stops the release.A.8.29Security testing in development and acceptancesupportsThis Sekit technical control integrates the test tools into the pipeline so a critical finding stops the release, the enforced gate this ISO control expects.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
DE.CM-01Networks monitoredPR.PS-01Configuration management appliedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Application security testing evidence
The proof that code and applications are automatically scanned for flaws (SAST/DAST), including dependencies and APIs.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0126?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.