Sekit CSF · Familia
Data Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0091Data classification4 mapeosData is formally classified by sensitivity to determine appropriate protectionRCF-0106Data minimization4 mapeosDigital assets and sensitive data are formally inventoried and trackedRCF-0109Data retention & disposal6 mapeosSecure methods are used to permanently destroy data that is no longer neededRCF-0103DLP monitoring5 mapeosSensitive data is masked or anonymised where full access is not requiredRCF-0094Encryption at rest4 mapeosSensitive data is encrypted when stored to prevent unauthorised accessRCF-0097Encryption in transit4 mapeosSensitive data is encrypted when transmitted to prevent interceptionRCF-0100Key management3 mapeosControls prevent sensitive data from leaving the organisation inappropriatelyRCF-0112Secrets management4 mapeosBackups of critical data are taken regularly and stored securely
Proceso
RCF-0092Data classification5 mapeosData classification is consistently applied when handling and sharing dataRCF-0107Data minimization4 mapeosThe data inventory is kept current and reviewed regularlyRCF-0110Data retention & disposal5 mapeosSecure disposal procedures are consistently followed for all sensitive dataRCF-0104DLP monitoring6 mapeosData masking is consistently applied in non-production environmentsRCF-0095Encryption at rest3 mapeosEncryption of stored data is consistently applied to all sensitive informationRCF-0098Encryption in transit4 mapeosEncryption in transit is consistently applied to all sensitive communicationsRCF-0101Key management3 mapeosDLP rules are consistently applied to detect and block data exfiltrationRCF-0113Secrets management3 mapeosBackup procedures are consistently followed and backup integrity is verified
Técnica
RCF-0093Data classification5 mapeosTechnical controls enforce data handling rules based on classification labelsRCF-0108Data minimization4 mapeosTechnical tools automatically discover and catalogue sensitive data assetsRCF-0111Data retention & disposal5 mapeosTechnical tools certify and log secure disposal of sensitive dataRCF-0105DLP monitoring5 mapeosTechnical controls automatically mask sensitive data in lower environmentsRCF-0096Encryption at rest4 mapeosTechnical controls enforce encryption at rest on all sensitive data storesRCF-0099Encryption in transit5 mapeosTechnical controls enforce encryption in transit across all channelsRCF-0102Key management3 mapeosTechnical DLP tools monitor and block unauthorised data transfersRCF-0114Secrets management3 mapeosTechnical controls automate backups and verify restoration capability
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Pregúntale a Sekura: «¿Qué evidencia demuestra Data Security?»
También vía MCP, gratis con cuenta