Sekit CSF · Family
Application Security
30 controls in 10 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0136API securityno mappings yetSecurity requirements for all application programming interfaces are formally defined and documentedRCF-0130CI/CD hardeningno mappings yetSecurity controls in the software build and deployment pipeline are formally defined and requiredRCF-0139Container securityno mappings yetSecurity standards for building and running containerised applications are formally definedRCF-0127Dependency/SBOM managementno mappings yetThe company formally tracks all software components and third-party libraries used in its applicationsRCF-0142DevSecOps governanceno mappings yetAccountability for security within development and operations teams is formally definedRCF-0133IaC scanningno mappings yetSecurity scanning of infrastructure-as-code templates is formally required before deploymentRCF-0124SAST/DASTno mappings yetFormal policy requires automated security testing of application code and running applicationsRCF-0121Secure code reviewno mappings yetSecurity review of code is formally required before it is released to productionRCF-0115Secure SDLC policyno mappings yetSecurity requirements are formally integrated into the software development lifecycle from planning to releaseRCF-0118Threat modelingno mappings yetThe company formally identifies and documents potential threats to applications before development begins
Process
RCF-0137API securityno mappings yetAPIs are consistently designed, tested and monitored to meet security requirementsRCF-0131CI/CD hardeningno mappings yetPipeline security controls are consistently applied and reviewed for every build and deploymentRCF-0140Container securityno mappings yetContainer images and configurations are consistently reviewed against security standardsRCF-0128Dependency/SBOM managementno mappings yetSoftware bills of materials are consistently maintained and reviewed for known vulnerabilitiesRCF-0143DevSecOps governanceno mappings yetSecurity is consistently embedded into development team practices and sprint cyclesRCF-0134IaC scanningno mappings yetInfrastructure templates are consistently scanned for misconfigurations before being appliedRCF-0125SAST/DASTno mappings yetStatic and dynamic security tests are consistently run as part of the build and release processRCF-0122Secure code reviewno mappings yetCode reviews consistently include security checks performed by trained developersRCF-0116Secure SDLC policyno mappings yetSecurity activities are consistently applied at each stage of the development processRCF-0119Threat modelingno mappings yetThreat modeling is consistently conducted for new features and significant changes
Technical
RCF-0138API securityno mappings yetTechnical controls enforce authentication, authorisation and rate limiting on all API endpointsRCF-0132CI/CD hardeningno mappings yetTechnical controls protect the build pipeline from tampering and enforce security gates at each stageRCF-0141Container securityno mappings yetTechnical tools scan container images and enforce runtime security policies automaticallyRCF-0129Dependency/SBOM managementno mappings yetTechnical tools automatically identify vulnerable dependencies and alert or block affected buildsRCF-0144DevSecOps governanceno mappings yetTechnical dashboards provide visibility of security posture across all development pipelinesRCF-0135IaC scanningno mappings yetAutomated tools scan infrastructure code for security issues and block deployment of non-compliant templatesRCF-0126SAST/DASTno mappings yetAutomated SAST and DAST tools integrate into the pipeline and block releases with critical findingsRCF-0123Secure code reviewno mappings yetAutomated tools scan code for security vulnerabilities as part of the development workflowRCF-0117Secure SDLC policyno mappings yetTechnical gates enforce security checks before code can progress through the development pipelineRCF-0120Threat modelingno mappings yetTechnical tools support structured threat modeling and track identified risks to resolution
Ask Sekura: “What evidence proves Application Security?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.