Sekit CSF · Family
Data Security
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0091Data classificationno mappings yetData is formally classified by sensitivity to determine appropriate protectionRCF-0106Data minimizationno mappings yetDigital assets and sensitive data are formally inventoried and trackedRCF-0109Data retention & disposalno mappings yetSecure methods are used to permanently destroy data that is no longer neededRCF-0103DLP monitoringno mappings yetSensitive data is masked or anonymised where full access is not requiredRCF-0094Encryption at restno mappings yetSensitive data is encrypted when stored to prevent unauthorised accessRCF-0097Encryption in transitno mappings yetSensitive data is encrypted when transmitted to prevent interceptionRCF-0100Key managementno mappings yetControls prevent sensitive data from leaving the organisation inappropriatelyRCF-0112Secrets managementno mappings yetBackups of critical data are taken regularly and stored securely
Process
RCF-0092Data classificationno mappings yetData classification is consistently applied when handling and sharing dataRCF-0107Data minimizationno mappings yetThe data inventory is kept current and reviewed regularlyRCF-0110Data retention & disposalno mappings yetSecure disposal procedures are consistently followed for all sensitive dataRCF-0104DLP monitoringno mappings yetData masking is consistently applied in non-production environmentsRCF-0095Encryption at restno mappings yetEncryption of stored data is consistently applied to all sensitive informationRCF-0098Encryption in transitno mappings yetEncryption in transit is consistently applied to all sensitive communicationsRCF-0101Key managementno mappings yetDLP rules are consistently applied to detect and block data exfiltrationRCF-0113Secrets managementno mappings yetBackup procedures are consistently followed and backup integrity is verified
Technical
RCF-0093Data classificationno mappings yetTechnical controls enforce data handling rules based on classification labelsRCF-0108Data minimizationno mappings yetTechnical tools automatically discover and catalogue sensitive data assetsRCF-0111Data retention & disposalno mappings yetTechnical tools certify and log secure disposal of sensitive dataRCF-0105DLP monitoringno mappings yetTechnical controls automatically mask sensitive data in lower environmentsRCF-0096Encryption at restno mappings yetTechnical controls enforce encryption at rest on all sensitive data storesRCF-0099Encryption in transitno mappings yetTechnical controls enforce encryption in transit across all channelsRCF-0102Key managementno mappings yetTechnical DLP tools monitor and block unauthorised data transfersRCF-0114Secrets managementno mappings yetTechnical controls automate backups and verify restoration capability
Ask Sekura: “What evidence proves Data Security?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.