Sekit CSF · Application Security · Process
RCF-0116Secure SDLC policy
Security activities are consistently applied at each stage of the development process
Mapping at a glance
RCF-0116Secure SDLC policyApplication Security · Process
RCF-0116 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.25Secure development life cyclesupportsThe process facet runs the agreed security activities, requirements capture, code review, dependency checks, on every feature and release, not only the large ones.A.8.32Change managementsupportsThis Sekit process control performs security activities like code review on every release, one of the checks this ISO control requires before a change reaches production.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.6.1.3Processes for responsible design and development of AI systemssupportsRunning agreed security activities on every release gives the AI development process its operating cadence, but it covers code security, not AI-specific oversight or data governance.A.6.2.2AI system requirements and specificationsupportsApplying security activities consistently across releases gives requirements gathering a home in the development process, though it is not scoped to AI-specific requirements.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Secure development policy
The rules the development team follows to build software securely: security requirements, code review and threat modeling.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0116?”
Also via MCP, free with account