Crosswalk de marcos Sekit CSF2 marcos Cada tema a través de tres lentes: política, proceso y técnica. Elige una familia y haz clic en cualquier control para iluminar sus mapeos.
432 controles · 20 familias · 2214 pares mapeados
Sekit CSF · Governance & Risk Crosswalk / Governance & Risk RCF-0001 Política 3 mapeados Policy management ISO 27001 A.5.1 NIST CSF GV.PO-01 NIST CSF GV.PO-02 RCF-0002 Proceso 5 mapeados Policy management ISO 27001 A.5.1 ISO 27001 A.5.36 ISO 27001 A.5.4 NIST CSF GV.PO-01 NIST CSF GV.PO-02 RCF-0003 Técnica 5 mapeados Policy management ISO 27001 A.5.36 ISO 27001 A.5.37 ISO 27001 A.8.9 NIST CSF GV.PO-01 NIST CSF GV.PO-02 RCF-0004 Política 5 mapeados Roles & responsibilities ISO 27001 A.5.2 NIST CSF GV.RR-01 NIST CSF GV.RR-02 NIST CSF GV.RR-03 NIST CSF GV.RR-04 RCF-0005 Proceso 7 mapeados Roles & responsibilities ISO 27001 A.5.2 ISO 27001 A.5.4 ISO 27001 A.6.2 NIST CSF GV.RR-01 NIST CSF GV.RR-02 NIST CSF GV.RR-03 RCF-0006 Técnica 7 mapeados Roles & responsibilities ISO 27001 A.5.15 ISO 27001 A.5.3 ISO 27001 A.8.2 NIST CSF GV.RR-01 NIST CSF GV.RR-02 NIST CSF GV.RR-03 RCF-0007 Política 6 mapeados Risk assessment ISO 27001 A.5.7 NIST CSF GV.RM-01 NIST CSF GV.RM-02 NIST CSF GV.RM-03 NIST CSF ID.RA-01 NIST CSF ID.RA-02 RCF-0008 Proceso 7 mapeados Risk assessment ISO 27001 A.5.35 ISO 27001 A.5.7 NIST CSF GV.RM-01 NIST CSF GV.RM-02 NIST CSF GV.RM-03 NIST CSF ID.RA-01 RCF-0009 Técnica 8 mapeados Risk assessment ISO 27001 A.5.7 ISO 27001 A.8.16 ISO 27001 A.8.8 NIST CSF GV.RM-01 NIST CSF GV.RM-02 NIST CSF GV.RM-03 RCF-0010 Política 5 mapeados Risk treatment ISO 27001 A.5.8 NIST CSF GV.RM-04 NIST CSF GV.RM-05 NIST CSF GV.RM-06 NIST CSF GV.RM-07 RCF-0011 Proceso 6 mapeados Risk treatment ISO 27001 A.5.26 ISO 27001 A.5.36 NIST CSF GV.RM-04 NIST CSF GV.RM-05 NIST CSF GV.RM-06 NIST CSF GV.RM-07 RCF-0012 Técnica 7 mapeados Risk treatment ISO 27001 A.5.36 ISO 27001 A.8.8 ISO 27001 A.8.9 NIST CSF GV.RM-04 NIST CSF GV.RM-05 NIST CSF GV.RM-06 RCF-0013 Política 4 mapeados Exception management ISO 27001 A.5.1 ISO 27001 A.5.36 NIST CSF GV.PO-02 NIST CSF GV.RM-06 RCF-0014 Proceso 4 mapeados Exception management ISO 27001 A.5.36 ISO 27001 A.5.4 NIST CSF GV.PO-02 NIST CSF GV.RM-06 RCF-0015 Técnica 4 mapeados Exception management ISO 27001 A.8.16 ISO 27001 A.8.9 NIST CSF GV.PO-02 NIST CSF GV.RM-06 RCF-0016 Política 6 mapeados Regulatory compliance ISO 27001 A.5.31 NIST CSF GV.OC-01 NIST CSF GV.OC-02 NIST CSF GV.OC-03 NIST CSF GV.OC-04 NIST CSF GV.OC-05 RCF-0017 Proceso 8 mapeados Regulatory compliance ISO 27001 A.5.31 ISO 27001 A.5.36 ISO 27001 A.5.4 NIST CSF GV.OC-01 NIST CSF GV.OC-02 NIST CSF GV.OC-03 RCF-0018 Técnica 9 mapeados Regulatory compliance ISO 27001 A.5.31 ISO 27001 A.5.33 ISO 27001 A.5.34 ISO 27001 A.8.24 NIST CSF GV.OC-01 NIST CSF GV.OC-02 RCF-0019 Política 6 mapeados Metrics & reporting ISO 27001 A.5.35 ISO 27001 A.5.36 NIST CSF GV.RM-05 NIST CSF GV.RM-06 NIST CSF ID.IM-01 NIST CSF ID.IM-02 RCF-0020 Proceso 6 mapeados Metrics & reporting ISO 27001 A.5.35 ISO 27001 A.5.4 NIST CSF GV.RM-05 NIST CSF GV.RM-06 NIST CSF ID.IM-01 NIST CSF ID.IM-02 RCF-0021 Técnica 7 mapeados Metrics & reporting ISO 27001 A.5.7 ISO 27001 A.8.15 ISO 27001 A.8.16 NIST CSF GV.RM-05 NIST CSF GV.RM-06 NIST CSF ID.IM-01 RCF-0022 Política 4 mapeados Internal audit ISO 27001 A.5.35 NIST CSF GV.RM-05 NIST CSF ID.IM-03 NIST CSF ID.IM-04 RCF-0023 Proceso 6 mapeados Internal audit ISO 27001 A.5.27 ISO 27001 A.5.35 ISO 27001 A.5.36 NIST CSF GV.RM-05 NIST CSF ID.IM-03 NIST CSF ID.IM-04 RCF-0024 Técnica 6 mapeados Internal audit ISO 27001 A.5.28 ISO 27001 A.8.15 ISO 27001 A.8.34 NIST CSF GV.RM-05 NIST CSF ID.IM-03 NIST CSF ID.IM-04 RCF-0025 Política 10 mapeados Third-party risk management ISO 27001 A.5.19 NIST CSF GV.SC-01 NIST CSF GV.SC-02 NIST CSF GV.SC-03 NIST CSF GV.SC-04 NIST CSF GV.SC-05 RCF-0026 Proceso 12 mapeados Third-party risk management ISO 27001 A.5.20 ISO 27001 A.5.21 ISO 27001 A.5.22 NIST CSF GV.SC-01 NIST CSF GV.SC-02 NIST CSF GV.SC-03 RCF-0027 Técnica 13 mapeados Third-party risk management ISO 27001 A.5.18 ISO 27001 A.5.22 ISO 27001 A.8.15 ISO 27001 A.8.16 NIST CSF GV.SC-01 NIST CSF GV.SC-02 RCF-0028 Política 6 mapeados Security charter ISO 27001 A.5.1 ISO 27001 A.5.2 ISO 27001 A.5.4 NIST CSF GV.OC-01 NIST CSF GV.PO-01 NIST CSF GV.RR-01 RCF-0029 Proceso 4 mapeados Security charter ISO 27001 A.5.4 NIST CSF GV.OC-01 NIST CSF GV.PO-01 NIST CSF GV.RR-01 RCF-0030 Técnica 3 mapeados Security charter NIST CSF GV.OC-01 NIST CSF GV.PO-01 NIST CSF GV.RR-01 RCF-0031 Política 7 mapeados Control testing program ISO 27001 A.5.35 ISO 27001 A.5.36 ISO 27001 A.8.29 NIST CSF GV.RM-05 NIST CSF ID.IM-01 NIST CSF ID.IM-02 RCF-0032 Proceso 7 mapeados Control testing program ISO 27001 A.5.27 ISO 27001 A.5.35 ISO 27001 A.5.36 NIST CSF GV.RM-05 NIST CSF ID.IM-01 NIST CSF ID.IM-02 RCF-0033 Técnica 7 mapeados Control testing program ISO 27001 A.8.16 ISO 27001 A.8.29 ISO 27001 A.8.8 NIST CSF GV.RM-05 NIST CSF ID.IM-01 NIST CSF ID.IM-02 RCF-0034 Política 6 mapeados Issues management ISO 27001 A.5.24 ISO 27001 A.5.25 ISO 27001 A.5.36 NIST CSF GV.RM-06 NIST CSF GV.RM-07 NIST CSF ID.IM-04 RCF-0035 Proceso 6 mapeados Issues management ISO 27001 A.5.25 ISO 27001 A.5.26 ISO 27001 A.5.27 NIST CSF GV.RM-06 NIST CSF GV.RM-07 NIST CSF ID.IM-04 RCF-0036 Técnica 6 mapeados Issues management ISO 27001 A.5.25 ISO 27001 A.8.15 ISO 27001 A.8.16 NIST CSF GV.RM-06 NIST CSF GV.RM-07 NIST CSF ID.IM-04
ISO/IEC 27001:2022 A.5.1 ISO 27001 Policies for information security A.5.2 ISO 27001 Information security roles and responsibilities A.5.3 ISO 27001 Segregation of duties A.5.4 ISO 27001 Management responsibilities A.5.7 ISO 27001 Threat intelligence A.5.8 ISO 27001 Information security in project management A.5.15 ISO 27001 Access control A.5.18 ISO 27001 Access rights A.5.19 ISO 27001 Information security in supplier relationships A.5.20 ISO 27001 Addressing information security within supplier agreements A.5.21 ISO 27001 Managing information security in the ICT supply chain A.5.22 ISO 27001 Monitoring, review and change management of supplier services A.5.24 ISO 27001 Information security incident management planning and preparation A.5.25 ISO 27001 Assessment and decision on information security events A.5.26 ISO 27001 Response to information security incidents A.5.27 ISO 27001 Learning from information security incidents A.5.28 ISO 27001 Collection of evidence A.5.31 ISO 27001 Legal, statutory, regulatory and contractual requirements A.5.33 ISO 27001 Protection of records A.5.34 ISO 27001 Privacy and protection of personal identifiable information (PII) A.5.35 ISO 27001 Independent review of information security A.5.36 ISO 27001 Compliance with policies, rules and standards for information security A.5.37 ISO 27001 Documented operating procedures A.6.2 ISO 27001 Terms and conditions of employment A.8.2 ISO 27001 Privileged access rights A.8.8 ISO 27001 Management of technical vulnerabilities A.8.9 ISO 27001 Configuration management A.8.15 ISO 27001 Logging A.8.16 ISO 27001 Monitoring activities A.8.24 ISO 27001 Use of cryptography A.8.29 ISO 27001 Security testing in development and acceptance A.8.34 ISO 27001 Protection of information systems during audit testing NIST CSF 2.0 GV.OC-01 NIST CSF Organizational mission understood GV.OC-02 NIST CSF Stakeholder needs understood GV.OC-03 NIST CSF Legal and regulatory requirements understood GV.OC-04 NIST CSF Critical objectives and services understood GV.OC-05 NIST CSF Dependencies understood GV.PO-01 NIST CSF Cybersecurity policy established GV.PO-02 NIST CSF Cybersecurity policy maintained GV.RM-01 NIST CSF Risk management objectives established GV.RM-02 NIST CSF Risk appetite and tolerance established GV.RM-03 NIST CSF Cyber risk in enterprise risk management GV.RM-04 NIST CSF Risk response strategy established GV.RM-05 NIST CSF Lines of communication for risk established GV.RM-06 NIST CSF Standardized risk method established GV.RM-07 NIST CSF Strategic opportunities characterized GV.RR-01 NIST CSF Leadership accountability for cyber risk GV.RR-02 NIST CSF Roles and responsibilities established GV.RR-03 NIST CSF Resources allocated for cybersecurity GV.RR-04 NIST CSF Cybersecurity in human resources GV.SC-01 NIST CSF Supply chain risk program established GV.SC-02 NIST CSF Supplier roles and responsibilities established GV.SC-03 NIST CSF Supply chain risk integrated GV.SC-04 NIST CSF Suppliers known and prioritized GV.SC-05 NIST CSF Supply chain requirements in contracts GV.SC-06 NIST CSF Due diligence before engagement GV.SC-07 NIST CSF Supplier risk managed over relationship GV.SC-08 NIST CSF Suppliers in incident planning GV.SC-09 NIST CSF Supply chain practices integrated in lifecycle ID.IM-01 NIST CSF Improvements from evaluations ID.IM-02 NIST CSF Improvements from tests and exercises ID.IM-03 NIST CSF Improvements from operations ID.IM-04 NIST CSF Response and recovery plans maintained ID.RA-01 NIST CSF Vulnerabilities identified and recorded ID.RA-02 NIST CSF Threat intelligence received