Sekit CSF · Family
Vulnerability & Configuration
21 controls in 7 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0226Baseline complianceno mappings yetThe company formally measures compliance of all systems against approved security configuration baselinesRCF-0223Configuration managementno mappings yetSecurity configuration standards are formally defined and required for all system typesRCF-0232Exposure managementno mappings yetThe company formally identifies and manages its external attack surface to reduce the risk of exploitationRCF-0229Patch prioritizationno mappings yetThe company formally prioritises patches based on vulnerability severity, asset criticality and exploitation likelihoodRCF-0235Penetration testingno mappings yetThe company formally commissions periodic penetration tests to identify exploitable weaknessesRCF-0220Vulnerability remediation SLAsno mappings yetThe company formally defines how quickly vulnerabilities must be remediated based on their severityRCF-0217Vulnerability scanningno mappings yetThe company formally requires regular scanning of all systems to identify known security vulnerabilities
Process
RCF-0227Baseline complianceno mappings yetBaseline compliance is consistently monitored and non-compliant systems are remediated within agreed timelinesRCF-0224Configuration managementno mappings yetSystem configurations are consistently reviewed against approved standards and deviations are correctedRCF-0233Exposure managementno mappings yetExternal-facing assets are consistently inventoried and exposure is reduced where it is not business-justifiedRCF-0230Patch prioritizationno mappings yetPatch prioritisation decisions are consistently applied and documented when deviating from the standard scheduleRCF-0236Penetration testingno mappings yetPenetration tests are consistently scoped, conducted and findings are tracked to remediationRCF-0221Vulnerability remediation SLAsno mappings yetVulnerability remediation deadlines are consistently tracked and escalated when at risk of being missedRCF-0218Vulnerability scanningno mappings yetVulnerability scans are consistently run on schedule and results are reviewed and acted upon
Technical
RCF-0228Baseline complianceno mappings yetTechnical tools report baseline compliance rates across the infrastructure and track remediation progressRCF-0225Configuration managementno mappings yetTechnical tools continuously assess system configurations and automatically remediate or alert on deviationsRCF-0234Exposure managementno mappings yetTechnical tools continuously monitor the external attack surface and alert on newly exposed or vulnerable assetsRCF-0231Patch prioritizationno mappings yetTechnical tools integrate vulnerability severity and threat intelligence to automate patch prioritisationRCF-0237Penetration testingno mappings yetTechnical infrastructure supports controlled penetration testing without affecting production availabilityRCF-0222Vulnerability remediation SLAsno mappings yetTechnical tools track vulnerability age against defined SLAs and automatically escalate overdue itemsRCF-0219Vulnerability scanningno mappings yetTechnical tools conduct automated vulnerability scans and feed results into the remediation tracking process
Ask Sekura: “What evidence proves Vulnerability & Configuration?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.