Sekit CSF · Family
Endpoint Security
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0145Configuration baselinesno mappings yetApproved security configuration standards are formally defined for all device types used by the companyRCF-0160Device hardeningno mappings yetSecurity hardening requirements are formally defined to reduce the attack surface of all company devicesRCF-0163Disk encryptionno mappings yetFull disk encryption is formally required on all portable devices and devices that handle sensitive dataRCF-0148EDR/anti-malwareno mappings yetThe company formally requires endpoint detection and response or anti-malware protection on all devicesRCF-0166Local admin controlno mappings yetThe use of local administrator rights on company devices is formally restricted and requires approvalRCF-0151MDM/MAMno mappings yetMobile devices and applications used for work are formally required to be managed through an approved systemRCF-0154Patch managementno mappings yetThe company formally requires that security patches are applied to all systems within defined timeframesRCF-0157Removable media controlno mappings yetThe use of removable storage devices such as USB drives is formally restricted to authorised business needs
Process
RCF-0146Configuration baselinesno mappings yetDevices are consistently configured to the approved baseline when deployed and after significant changesRCF-0161Device hardeningno mappings yetDevices are consistently hardened by disabling unnecessary services and applying approved security settingsRCF-0164Disk encryptionno mappings yetDisk encryption is consistently enabled and verified on all devices within scopeRCF-0149EDR/anti-malwareno mappings yetEndpoint protection tools are consistently deployed, updated and alerts are investigated promptlyRCF-0167Local admin controlno mappings yetLocal administrator access is consistently limited to authorised personnel and reviewed regularlyRCF-0152MDM/MAMno mappings yetMobile device management policies are consistently applied and devices are enrolled before accessing company dataRCF-0155Patch managementno mappings yetPatches are consistently applied on schedule and patch status is tracked across all managed endpointsRCF-0158Removable media controlno mappings yetRemovable media use is consistently monitored and unauthorised devices are reported and removed
Technical
RCF-0147Configuration baselinesno mappings yetTechnical tools automatically assess device configurations against the approved baseline and report deviationsRCF-0162Device hardeningno mappings yetTechnical tools apply and enforce hardening configurations automatically across the device estateRCF-0165Disk encryptionno mappings yetTechnical controls enforce disk encryption and can verify encryption status across the entire device fleetRCF-0150EDR/anti-malwareno mappings yetEDR tools continuously monitor endpoint behaviour and automatically contain threats when detectedRCF-0168Local admin controlno mappings yetTechnical controls prevent users from running with local administrator privileges without approvalRCF-0153MDM/MAMno mappings yetTechnical MDM controls enforce security policies on mobile devices and can remotely wipe lost or stolen devicesRCF-0156Patch managementno mappings yetTechnical tools automate patch deployment and report on outstanding patches by age and severityRCF-0159Removable media controlno mappings yetTechnical controls block or restrict the use of removable storage devices at the operating system level
Ask Sekura: “What evidence proves Endpoint Security?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.