Sekit CSF · Family
Vulnerability & Configuration
21 controls in 7 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0226Baseline compliance7 mappingsThe company formally measures compliance of all systems against approved security configuration baselinesRCF-0223Configuration management6 mappingsSecurity configuration standards are formally defined and required for all system typesRCF-0232Exposure management6 mappingsThe company formally identifies and manages its external attack surface to reduce the risk of exploitationRCF-0229Patch prioritization6 mappingsThe company formally prioritises patches based on vulnerability severity, asset criticality and exploitation likelihoodRCF-0235Penetration testing4 mappingsThe company formally commissions periodic penetration tests to identify exploitable weaknessesRCF-0220Vulnerability remediation SLAs6 mappingsThe company formally defines how quickly vulnerabilities must be remediated based on their severityRCF-0217Vulnerability scanning4 mappingsThe company formally requires regular scanning of all systems to identify known security vulnerabilities
Process
RCF-0227Baseline compliance7 mappingsBaseline compliance is consistently monitored and non-compliant systems are remediated within agreed timelinesRCF-0224Configuration management6 mappingsSystem configurations are consistently reviewed against approved standards and deviations are correctedRCF-0233Exposure management7 mappingsExternal-facing assets are consistently inventoried and exposure is reduced where it is not business-justifiedRCF-0230Patch prioritization6 mappingsPatch prioritisation decisions are consistently applied and documented when deviating from the standard scheduleRCF-0236Penetration testing4 mappingsPenetration tests are consistently scoped, conducted and findings are tracked to remediationRCF-0221Vulnerability remediation SLAs6 mappingsVulnerability remediation deadlines are consistently tracked and escalated when at risk of being missedRCF-0218Vulnerability scanning4 mappingsVulnerability scans are consistently run on schedule and results are reviewed and acted upon
Technical
RCF-0228Baseline compliance4 mappingsTechnical tools report baseline compliance rates across the infrastructure and track remediation progressRCF-0225Configuration management3 mappingsTechnical tools continuously assess system configurations and automatically remediate or alert on deviationsRCF-0234Exposure management5 mappingsTechnical tools continuously monitor the external attack surface and alert on newly exposed or vulnerable assetsRCF-0231Patch prioritization5 mappingsTechnical tools integrate vulnerability severity and threat intelligence to automate patch prioritisationRCF-0237Penetration testing4 mappingsTechnical infrastructure supports controlled penetration testing without affecting production availabilityRCF-0222Vulnerability remediation SLAs4 mappingsTechnical tools track vulnerability age against defined SLAs and automatically escalate overdue itemsRCF-0219Vulnerability scanning3 mappingsTechnical tools conduct automated vulnerability scans and feed results into the remediation tracking process
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in Cyber Essentials
Ask Sekura: “What evidence proves Vulnerability & Configuration?”
Also via MCP, free with account