Zurück zu Sicherheit und Compliance

DORA

141 konforme Kontrollen von 141

Letzte Synchronisierung :

Der Zähler nennt die Anzahl der Kontrollen, die unsere Plattform für kontinuierliche Überwachung Aikido Security für dieses Rahmenwerk als erfüllt meldet, bezogen auf alle von ihr geprüften Kontrollen. Sie sind unten einzeln aufgeführt.

Die Bezeichnungen der Bewertungen, Typen und Kontrollen stammen aus den ursprünglichen Rahmenwerken und sind daher auf Englisch.

Sicherheitsauditbericht anfordern

Has deletion protection for cloud resources

KontrolleStatus
Cloud SQL instances have deletion protection enabledkonform
Deletion protection is disabled for RDS databasekonform
VM instances have deletion protection enabledkonform

Uses load balancers

KontrolleStatus
Load Balancers only accept HTTPS connectionskonform

Configured monitoring for domains

KontrolleStatus
Connected public facing domainskonform

Has connected cloud environments

KontrolleStatus
Cloud environments are connectedkonform

Has connected code repositories

KontrolleStatus
Code repositories are connectedkonform

Has connected container repositories

KontrolleStatus
Container repositories are connectedkonform

Cloud Infrastructure Configuration

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
AKS API server does not limit access by IP rangeskonform
Amazon EKS Clusters public endpoints should not allow traffic from any IPkonform
Azure Cognitive Services allows unrestricted public network accesskonform
Azure Cognitive Services Network ACLs do not have IP rules configuredkonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rules allow unrestricted RDP accesskonform
Firewall rules allow unrestricted SSH accesskonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
Kubernetes master endpoint is not publicly availablekonform
Vertex AI notebook instance has a public IP addresskonform

Data Protection and Encryption

KontrolleStatus
API Gateway endpoints do not require an API key or authorizationkonform
AWS EKS Node groups have implicit SSH access from any IPkonform
Azure Cosmos DB is publicly reachablekonform
Azure Key Vault allows public network accesskonform
BigQuery table is anonymously or publicly accessiblekonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Cloud Storage bucket does not enforce public access preventionkonform
Cloud Storage bucket does not enforce uniform bucket-level accesskonform
Cloud Storage bucket is publicly accessiblekonform
Dataproc cluster is anonymously or publicly accessiblekonform
Default network exists in GCP projectkonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules allow RDP access from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Key Vault is publicly accessiblekonform
KMS cryptographic key policy allows public accesskonform
KMS keys have strict access permissionskonform
Kubernetes dashboard might be deployedkonform
Profiling endpoint automatically exposed on /debug/pprofkonform
Pub/Sub topic is anonymously or publicly accessiblekonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
SQL Server is publicly reachablekonform

Encryption at Rest Enabled

KontrolleStatus
Amazon EKS Clusters should have secrets encryption enabledkonform
API Gateway REST API caching is unencryptedkonform
AWS ElastiCache Redis cluster should have encryption at rest enabledkonform
Docker image repository not encrypted at restkonform
Elasticsearch domain is not encrypted at restkonform
Ensure all data stored in the RDS is securely encrypted at restkonform
KMS keys have key rotation enabledkonform
SNS topics are not encrypted at restkonform
SQS queue data is not encryptedkonform
Virtual Machines have confidential computing enabledkonform

Enforces HTTPS traffic to cloud instances

KontrolleStatus
Cloud functions require HTTPS invocationskonform
Load Balancers only accept HTTPS connectionskonform

Identity and Access Management (IAM)

KontrolleStatus
Users are logging in securelykonform

Network Security

KontrolleStatus
Compute instances do not have public IP addresseskonform
Firewall rules restrict public ingress to port 11214konform
Firewall rules restrict public ingress to port 11215konform
Firewall rules restrict public ingress to port 135konform
Firewall rules restrict public ingress to port 137konform
Firewall rules restrict public ingress to port 138konform
Firewall rules restrict public ingress to port 139konform
Firewall rules restrict public ingress to port 1433konform
Firewall rules restrict public ingress to port 1434konform
Firewall rules restrict public ingress to port 2383konform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 27017konform
Firewall rules restrict public ingress to port 27018konform
Firewall rules restrict public ingress to port 27019konform
Firewall rules restrict public ingress to port 3306konform
Firewall rules restrict public ingress to port 389konform
Firewall rules restrict public ingress to port 4505konform
Firewall rules restrict public ingress to port 4506konform
Firewall rules restrict public ingress to port 61621konform
Firewall rules restrict public ingress to port 636konform
Firewall rules restrict public ingress to port 7001konform
Firewall rules restrict public ingress to port 8000konform
Firewall rules restrict public ingress to port 9200konform
Firewall rules restrict public ingress to port 9300konform
No firewall rule allows access to Open Telemtry metrics endpoint from the internetkonform
No firewall rule allows access to port 1720 from the internetkonform
No firewall rule allows cPanel access from the internetkonform
No firewall rule allows etcd access from the internetkonform
No firewall rule allows MongoDB access from the internetkonform
No firewall rule allows NFS access from the internetkonform
No firewall rule allows Telnet access from the internetkonform
No firewall rule allows Tomcat Cluster Receiver access from the internetkonform

Storage and Backup Security

KontrolleStatus
Azure Storage Account allow public accesskonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Azure Storage blobs do not restrict public access for nested itemskonform
Firewall rules restrict public ingress to port 3020konform
S3 bucket grants public access to all contentskonform
S3 Buckets should have block public access globallykonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform
Storage buckets have uniform bucket-level access enabledkonform

Use of Cryptography: Enforces SSL

KontrolleStatus
Cloud SQL db not enforcing SSLkonform
Deprecated SSL Protocol Usage Detectedkonform
Deprecated SSL Protocol Usage Detectedkonform
NodeJS talks to database without encryptionkonform
SSL certificate verification turned off during requestskonform
SSL certificate verification turned off during requestskonform

Use of Cryptography: Enforces TLS

KontrolleStatus
API Gateway stages are not using TLS 1.2 or higherkonform
Elasticsearch domain might have outdated TLS versionkonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Storage account does not enforce HTTPS-only traffickonform

Use of Cryptography: Secure Cookies

KontrolleStatus
Cookie missing HttpOnly flagkonform
Laravel cookies can be sent unencryptedkonform

Cloud Resource Logging Enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform
Amazon EKS Clusters should have control plane logging enabledkonform
Audit Configuration logging is enabledkonform
Logging and alerts are enabled for Project Ownership assignmentskonform
Storage Permissions logging is enabledkonform
VPC Firewall has Rule logging enabledkonform

Does not have any issues outside of their SLA

KontrolleStatus
Configure SLAskonform
No critical issues outside of SLAkonform
No high severity issues outside of SLAkonform
No low severity issues outside of SLAkonform
No medium severity issues outside of SLAkonform

Has email notifications set up

KontrolleStatus
Email notifications are enabledkonform

Has enabled security notifications

KontrolleStatus
Security notifications are enabledkonform

Has backups for stateful cloud resources

KontrolleStatus
Databases have automated backups enabledkonform

Is GDPR Compliant

KontrolleStatus
GDPR Compliancekonform

Does not have any issues outside of their SLA

KontrolleStatus
Configure SLAskonform
No critical issues outside of SLAkonform
No high severity issues outside of SLAkonform
No low severity issues outside of SLAkonform
No medium severity issues outside of SLAkonform

Has email notifications set up

KontrolleStatus
Email notifications are enabledkonform

Has enabled security notifications

KontrolleStatus
Security notifications are enabledkonform

Configured monitoring for code repositories

KontrolleStatus
Configured monitoring for all code repositorieskonform

Configured monitoring for container images

KontrolleStatus
Configured monitoring for all container imageskonform