Sekit CSF · Family
Governance & Risk
36 controls in 12 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0031Control testing programno mappings yetSecurity controls are regularly tested to verify they work as intendedRCF-0013Exception managementno mappings yetExceptions to security policies are formally documented and approvedRCF-0022Internal auditno mappings yetThe company conducts formal internal audits of its security controlsRCF-0034Issues managementno mappings yetSecurity issues and findings are formally tracked until resolutionRCF-0019Metrics & reportingno mappings yetSecurity performance is measured using defined metricsRCF-0001Policy managementno mappings yetThe company has a formal written security policy approved by leadershipRCF-0016Regulatory complianceno mappings yetThe company formally tracks applicable laws and regulationsRCF-0007Risk assessmentno mappings yetThe company formally identifies and documents its security risksRCF-0010Risk treatmentno mappings yetThe company has a formal plan to address identified security risksRCF-0004Roles & responsibilitiesno mappings yetSecurity roles and responsibilities are formally defined and assignedRCF-0028Security charterno mappings yetLeadership has formally approved and sponsored the security programmeRCF-0025Third-party risk managementno mappings yetThird party suppliers and vendors are formally assessed for security risk
Process
RCF-0032Control testing programno mappings yetControl testing results are tracked and drive remediation actionsRCF-0014Exception managementno mappings yetException approvals follow a consistent process with defined time limitsRCF-0023Internal auditno mappings yetInternal audit findings are tracked and remediated within agreed timelinesRCF-0035Issues managementno mappings yetIssues are assigned owners and resolved within agreed timelinesRCF-0020Metrics & reportingno mappings yetSecurity metrics are regularly reviewed and reported to leadershipRCF-0002Policy managementno mappings yetSecurity policies are consistently communicated and followed across the organisationRCF-0017Regulatory complianceno mappings yetRegulatory requirements are consistently implemented across the organisationRCF-0008Risk assessmentno mappings yetRisk assessments are conducted regularly and drive security decisionsRCF-0011Risk treatmentno mappings yetRisk treatment actions are tracked and completed within agreed timelinesRCF-0005Roles & responsibilitiesno mappings yetSecurity responsibilities are understood and consistently fulfilledRCF-0029Security charterno mappings yetThe security programme has visible leadership support and adequate resourcesRCF-0026Third-party risk managementno mappings yetThird party security requirements are consistently enforced through contracts
Technical
RCF-0033Control testing programno mappings yetAutomated tools regularly test technical controlsRCF-0015Exception managementno mappings yetTechnical controls flag or compensate for approved policy exceptionsRCF-0024Internal auditno mappings yetTechnical tools support automated audit evidence collectionRCF-0036Issues managementno mappings yetTechnical tools track and escalate unresolved security issuesRCF-0021Metrics & reportingno mappings yetTechnical dashboards provide real-time visibility of security metricsRCF-0003Policy managementno mappings yetTechnical controls enforce compliance with security policiesRCF-0018Regulatory complianceno mappings yetTechnical controls support compliance with regulatory requirementsRCF-0009Risk assessmentno mappings yetRisk assessment processes are supported by technical tools and dataRCF-0012Risk treatmentno mappings yetTechnical controls implement the agreed risk treatment measuresRCF-0006Roles & responsibilitiesno mappings yetSystems enforce role-based security responsibilitiesRCF-0030Security charterno mappings yetTechnical infrastructure reflects leadership commitment to security investmentRCF-0027Third-party risk managementno mappings yetTechnical controls monitor third party access and activity
Ask Sekura: “What evidence proves Governance & Risk?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.