Zurück zu Sicherheit und Compliance

RGPD

175 konforme Kontrollen von 175

Letzte Synchronisierung :

Der Zähler stammt von unserer Plattform für kontinuierliche Überwachung Aikido Security, die Detailliste führt die von ihr als erfüllt gemeldeten Kontrollen auf. Beide Zahlen können leicht voneinander abweichen.

Die Bezeichnungen der Bewertungen, Typen und Kontrollen stammen aus den ursprünglichen Rahmenwerken und sind daher auf Englisch.

Sicherheitsauditbericht anfordern

Enforces Multi-Factor Authentication (MFA)

KontrolleStatus
Users are logging in securelykonform

Proper Access Management for Resources

KontrolleStatus
Access Approval is enabled for the projectkonform
AKS local admin account is still enabledkonform
Compute instances have OS Login enabledkonform
Dangerous Impersonate permission given to ServiceAccount or nodekonform
GKE clusters have the Kubernetes Dashboard disabledkonform
Kubernetes pods are isolatedkonform
No instance uses the default service accountkonform
No user has both the Service Account User and Service Account Admin rolekonform
Project-wide SSH keys are blockedkonform
Service accounts have strict access permissionskonform
ServiceAccount or node can read all secretskonform
VM instances have strict access permissionskonform

Proper Access Management for Users

KontrolleStatus
Users are only allowed to use corporate emailskonform

Proper Access Management to Resources

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
AKS API server does not limit access by IP rangeskonform
Amazon EKS Clusters public endpoints should not allow traffic from any IPkonform
API Gateway endpoints do not require an API key or authorizationkonform
AWS EKS Node groups have implicit SSH access from any IPkonform
Azure Cognitive Services allows unrestricted public network accesskonform
Azure Cosmos DB is publicly reachablekonform
Azure Key Vault allows public network accesskonform
Azure Storage Account allow public accesskonform
Azure Storage blobs do not restrict public access for nested itemskonform
BigQuery table is anonymously or publicly accessiblekonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Cloud Storage bucket does not enforce public access preventionkonform
Cloud Storage bucket does not enforce uniform bucket-level accesskonform
Cloud Storage bucket is publicly accessiblekonform
Dataproc cluster is anonymously or publicly accessiblekonform
Default network exists in GCP projectkonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules allow RDP access from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow unrestricted RDP accesskonform
Firewall rules allow unrestricted SSH accesskonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
Key Vault is publicly accessiblekonform
KMS cryptographic key policy allows public accesskonform
KMS keys have strict access permissionskonform
Kubernetes dashboard might be deployedkonform
Kubernetes master endpoint is not publicly availablekonform
Profiling endpoint automatically exposed on /debug/pprofkonform
Pub/Sub topic is anonymously or publicly accessiblekonform
S3 bucket grants public access to all contentskonform
S3 Buckets should have block public access globallykonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
SQL Server is publicly reachablekonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform
Vertex AI notebook instance has a public IP addresskonform

Encryption at Rest Enabled

KontrolleStatus
Amazon EKS Clusters should have secrets encryption enabledkonform
API Gateway REST API caching is unencryptedkonform
AWS ElastiCache Redis cluster should have encryption at rest enabledkonform
Docker image repository not encrypted at restkonform
Elasticsearch domain is not encrypted at restkonform
Ensure all data stored in the RDS is securely encrypted at restkonform
KMS keys have key rotation enabledkonform
SNS topics are not encrypted at restkonform
SQS queue data is not encryptedkonform
Virtual Machines have confidential computing enabledkonform

Enforces HTTPS traffic to cloud instances

KontrolleStatus
Cloud functions require HTTPS invocationskonform
Load Balancers only accept HTTPS connectionskonform

Runtimes are up to date

KontrolleStatus
AWS MQBroker version is outdatedkonform
GKE clusters use stable release channels with automatic upgradeskonform
GKE node pools have node auto-upgrade enabledkonform
No AKS cluster upgrade channel is chosenkonform
No Critical End-of-Life (EOL) Issueskonform
No High End-of-Life (EOL) Issueskonform

Use of Cryptography Libraries

KontrolleStatus
Hashes should include an unpredictable saltkonform
Usage of deprecated or broken encryption detectedkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Using deprecated cryptographic librarykonform

Use of Cryptography: Enforces SSL

KontrolleStatus
Cloud SQL db not enforcing SSLkonform
Deprecated SSL Protocol Usage Detectedkonform
Deprecated SSL Protocol Usage Detectedkonform
NodeJS talks to database without encryptionkonform
SSL certificate verification turned off during requestskonform
SSL certificate verification turned off during requestskonform

Use of Cryptography: Enforces TLS

KontrolleStatus
API Gateway stages are not using TLS 1.2 or higherkonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Elasticsearch domain might have outdated TLS versionkonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Storage account does not enforce HTTPS-only traffickonform

Use of Cryptography: Secure Cookies

KontrolleStatus
Cookie missing HttpOnly flagkonform
Laravel cookies can be sent unencryptedkonform

Backups Enabled

KontrolleStatus
Databases have automated backups enabledkonform
DynamoDB backups are offkonform

Logging Enabled

KontrolleStatus
Amazon EKS Clusters should have control plane logging enabledkonform
Audit Configuration logging is enabledkonform
Logging and alerts are enabled for Project Ownership assignmentskonform
Storage Permissions logging is enabledkonform
VPC Firewall has Rule logging enabledkonform

Threat Detection Enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform

Encryption at Rest Enabled

KontrolleStatus
Amazon EKS Clusters should have secrets encryption enabledkonform
API Gateway REST API caching is unencryptedkonform
AWS ElastiCache Redis cluster should have encryption at rest enabledkonform
Docker image repository not encrypted at restkonform
Elasticsearch domain is not encrypted at restkonform
Ensure all data stored in the RDS is securely encrypted at restkonform
KMS keys have key rotation enabledkonform
SNS topics are not encrypted at restkonform
SQS queue data is not encryptedkonform
Virtual Machines have confidential computing enabledkonform

Enforces HTTPS traffic to cloud instances

KontrolleStatus
Cloud functions require HTTPS invocationskonform
Load Balancers only accept HTTPS connectionskonform

Use of Cryptography Libraries

KontrolleStatus
Hashes should include an unpredictable saltkonform
Usage of deprecated or broken encryption detectedkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Using deprecated cryptographic librarykonform

Use of Cryptography: Enforces SSL

KontrolleStatus
Cloud SQL db not enforcing SSLkonform
Deprecated SSL Protocol Usage Detectedkonform
Deprecated SSL Protocol Usage Detectedkonform
NodeJS talks to database without encryptionkonform
SSL certificate verification turned off during requestskonform
SSL certificate verification turned off during requestskonform

Use of Cryptography: Enforces TLS

KontrolleStatus
API Gateway stages are not using TLS 1.2 or higherkonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Elasticsearch domain might have outdated TLS versionkonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Storage account does not enforce HTTPS-only traffickonform

Use of Cryptography: Secure Cookies

KontrolleStatus
Cookie missing HttpOnly flagkonform
Laravel cookies can be sent unencryptedkonform