Sekit CSF · Family
Cloud Security
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0334Cloud IAMno mappings yetAccess to cloud environments is formally governed by policies defining who can access what and under what conditionsRCF-0343Cloud loggingno mappings yetThe company formally requires that all significant cloud activity is logged and retainedRCF-0337CSPM postureno mappings yetThe company formally requires continuous assessment of cloud environment configurations against security standardsRCF-0340KMS & HSMno mappings yetThe company formally governs how encryption keys are created, stored, rotated and retiredRCF-0349Multi-tenancy controlsno mappings yetThe company formally addresses the risk of data leakage between tenants in shared cloud environmentsRCF-0352SaaS security configurationno mappings yetSecurity configuration requirements for all software-as-a-service applications are formally definedRCF-0331Shared responsibility modelno mappings yetSecurity responsibilities between the company and its cloud providers are formally understood and documentedRCF-0346Workload protectionno mappings yetSecurity standards for protecting workloads running in cloud environments are formally defined
Process
RCF-0335Cloud IAMno mappings yetCloud access rights are consistently reviewed and aligned with the principle of least privilegeRCF-0344Cloud loggingno mappings yetCloud audit logs are consistently enabled across all accounts and services and reviewed regularlyRCF-0338CSPM postureno mappings yetCloud security posture is consistently monitored and misconfigurations are remediated within agreed timelinesRCF-0341KMS & HSMno mappings yetEncryption key management procedures are consistently followed and key material is never exposed in plain textRCF-0350Multi-tenancy controlsno mappings yetMulti-tenant boundaries are consistently verified and configurations that could enable cross-tenant access are avoidedRCF-0353SaaS security configurationno mappings yetSaaS applications are consistently configured to meet security standards and reviewed when settings changeRCF-0332Shared responsibility modelno mappings yetTeams consistently apply the correct security controls for their side of the cloud shared responsibility modelRCF-0347Workload protectionno mappings yetCloud workloads are consistently assessed against security standards and anomalies are investigated
Technical
RCF-0336Cloud IAMno mappings yetTechnical controls enforce identity-based access policies across all cloud environments and servicesRCF-0345Cloud loggingno mappings yetTechnical controls ensure cloud activity logs are centralised, tamper-proof and available for investigationRCF-0339CSPM postureno mappings yetCloud security posture management tools continuously scan for and alert on misconfigured cloud resourcesRCF-0342KMS & HSMno mappings yetTechnical key management systems and hardware security modules protect cryptographic material at rest and in useRCF-0351Multi-tenancy controlsno mappings yetTechnical controls enforce strict tenant isolation to prevent unauthorised access to other customers' dataRCF-0354SaaS security configurationno mappings yetTechnical tools assess SaaS application configurations and alert on deviations from security baselinesRCF-0333Shared responsibility modelno mappings yetTechnical controls fill the security gaps that fall on the company's side of the cloud shared responsibility boundaryRCF-0348Workload protectionno mappings yetTechnical tools monitor cloud workloads for threats and enforce security policies at the workload level
Ask Sekura: “What evidence proves Cloud Security?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.