Sekit CSF · Identity & Access Management · Technical
RCF-0075SSO & federation
All critical applications authenticate through a central identity provider
Mapping at a glance
RCF-0075SSO & federationIdentity & Access Management · Technical
RCF-0075 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.15Access controlenablesAuthenticating critical applications through the central identity provider rather than local accounts is the technical foundation that makes A.5.15's access rules enforceable across the estate.A.5.16Identity managementsupportsAuthenticating critical business applications through the central identity provider means every account there is tied to a known identity, the mapping A.5.16 requires.A.8.5Secure authenticationsupportsSSO federation routes critical applications through the central identity provider instead of local accounts, so authentication strength is set once and applied everywhere A.8.5 covers.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Identity & Access Management controls
Ask Sekura: “What evidence proves RCF-0075?”
Also via MCP, free with account