Sekit CSF · Asset Management · Policy
RCF-0058Shadow IT discovery
The company formally prohibits the use of unapproved applications and services
Mapping at a glance
RCF-0058Shadow IT discoveryAsset Management · Policy
A.5.10Acceptable use of information and other associated assetsISO/IEC 27001:2022 · Annex A controlsID.AM-01Hardware inventory maintainedNIST CSF 2.0ID.AM-02Software inventory maintainedNIST CSF 2.0ID.AM-08Assets managed through lifecycleNIST CSF 2.0CE2.1Remove unnecessary accounts and softwareCyber Essentials
RCF-0058 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.AM-01Hardware inventory maintainedID.AM-02Software inventory maintainedID.AM-08Assets managed through lifecycle
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
From the Sekit evidence catalog
This topic through the other lenses
All Asset Management controls
Ask Sekura: “What evidence proves RCF-0058?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.