Sekit CSF · Application Security · Policy
RCF-0115Secure SDLC policy
Security requirements are formally integrated into the software development lifecycle from planning to release
Mapping at a glance
RCF-0115Secure SDLC policyApplication Security · Policy
RCF-0115 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.1Policies for information securitysupportsSekit's Secure SDLC policy, one of the topic-specific policies A.5.1 expects, builds security requirements into every stage of development, from design through release, for in-house and outsourced work alike.A.5.8Information security in project managementsupportsThis policy control builds security requirements into each stage of software development, from design through release, supporting A.5.8's wider requirement to embed security into every project, software or not.A.8.25Secure development life cyclesupportsThis policy facet builds security requirements into each development stage, from design through release, for in-house and outsourced work, matching A.8.25's core lifecycle requirement.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Secure development policy
The rules the development team follows to build software securely: security requirements, code review and threat modeling.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0115?”
Also via MCP, free with account