Sekit CSF · Family
Network Security
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0178Email securityno mappings yetFormal controls are required to protect against phishing, spoofing and malicious email contentRCF-0172Firewall managementno mappings yetFormal policies govern which network traffic is permitted and how firewall rules are created and reviewedRCF-0169Network segmentationno mappings yetThe company formally divides its network into zones to limit the spread of threats between systemsRCF-0175Secure DNSno mappings yetThe company formally requires that domain name resolution is protected against manipulation and abuseRCF-0181TLS termination/hardeningno mappings yetThe company formally requires that encrypted communications use strong protocols and current cipher suitesRCF-0187VPN managementno mappings yetRemote network access through virtual private networks is formally governed and restricted to approved users and devicesRCF-0190Wireless securityno mappings yetThe company formally defines security requirements for all wireless networks it operates or permitsRCF-0184Zero Trust network accessno mappings yetThe company formally adopts the principle that no user or device is trusted by default regardless of network location
Process
RCF-0179Email securityno mappings yetEmail security controls are consistently maintained and suspicious emails are investigated and reportedRCF-0173Firewall managementno mappings yetFirewall rules are consistently reviewed and unused or overly permissive rules are removedRCF-0170Network segmentationno mappings yetNetwork zones are consistently maintained and traffic between them is controlled and reviewedRCF-0176Secure DNSno mappings yetDNS configurations are consistently reviewed and DNS traffic is monitored for malicious activityRCF-0182TLS termination/hardeningno mappings yetTLS configurations are consistently reviewed and weak protocols or ciphers are disabledRCF-0188VPN managementno mappings yetVPN access is consistently provisioned, reviewed and removed when no longer requiredRCF-0191Wireless securityno mappings yetWireless networks are consistently configured to security standards and unauthorised access points are identifiedRCF-0185Zero Trust network accessno mappings yetZero trust access principles are consistently applied and all access requests are verified before being granted
Technical
RCF-0180Email securityno mappings yetTechnical tools enforce SPF, DKIM, DMARC and scan incoming email for malicious links and attachmentsRCF-0174Firewall managementno mappings yetTechnical tools manage firewall rule sets and alert on changes or rules that conflict with security policyRCF-0171Network segmentationno mappings yetTechnical controls enforce network boundaries and restrict traffic between zones based on policyRCF-0177Secure DNSno mappings yetTechnical controls implement DNS filtering, DNSSEC and monitoring to detect and block malicious domainsRCF-0183TLS termination/hardeningno mappings yetTechnical controls enforce TLS version and cipher standards across all services and flag non-compliant endpointsRCF-0189VPN managementno mappings yetTechnical controls enforce authentication, encryption and access policy for all VPN connectionsRCF-0192Wireless securityno mappings yetTechnical controls enforce wireless encryption, segment guest networks and detect rogue access pointsRCF-0186Zero Trust network accessno mappings yetTechnical controls enforce continuous verification of identity and device health before granting network access
Ask Sekura: “What evidence proves Network Security?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.