Zurück zu Sicherheit und Compliance

NIS2

148 konforme Kontrollen von 148

Letzte Synchronisierung :

Der Zähler stammt von unserer Plattform für kontinuierliche Überwachung Aikido Security, die Detailliste führt die von ihr als erfüllt gemeldeten Kontrollen auf. Beide Zahlen können leicht voneinander abweichen.

Die Bezeichnungen der Bewertungen, Typen und Kontrollen stammen aus den ursprünglichen Rahmenwerken und sind daher auf Englisch.

Sicherheitsauditbericht anfordern

Applies the least privilege principle for cloud resource

KontrolleStatus
Access Approval is enabled for the projectkonform
Compute instances have OS Login enabledkonform
GKE clusters have the Kubernetes Dashboard disabledkonform
Kubernetes pods are isolatedkonform
No instance uses the default service accountkonform
No user has both the Service Account User and Service Account Admin rolekonform
Project-wide SSH keys are blockedkonform
Service accounts have strict access permissionskonform
VM instances have strict access permissionskonform

Applies the least privilege principle for cloud users

KontrolleStatus
Firewall rules restrict public ingress to port 636konform
Users are logging in securelykonform
Users are only allowed to use corporate emailskonform

Applies the least privilege principle to cloud resources

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
KMS keys have strict access permissionskonform
Kubernetes master endpoint is not publicly availablekonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform

Has backups for stateful cloud resources

KontrolleStatus
Databases have automated backups enabledkonform

Configured SLAs to resolve issues

KontrolleStatus
Configure SLAskonform

Tracks progress via an issue tracker

KontrolleStatus
Integration with issue tracker enabledkonform

Configured monitoring for code repositories

KontrolleStatus
Configured monitoring for all code repositorieskonform

Configured monitoring for container images

KontrolleStatus
Configured monitoring for cloud environmentkonform

Configured monitoring for public facing domains

KontrolleStatus
Configured monitoring for public facing domainskonform

Has configured exposure for repositories

KontrolleStatus
Has configured exposure for resourceskonform

Has measurements against unauthorized network access

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
Kubernetes master endpoint is not publicly availablekonform

Has separate production and test environments

KontrolleStatus
No cloud environment used for mixed purposes (eg production and staging)konform

Uses firewalls

KontrolleStatus
Firewall rules restrict public ingress to port 11214konform
Firewall rules restrict public ingress to port 11215konform
Firewall rules restrict public ingress to port 135konform
Firewall rules restrict public ingress to port 137konform
Firewall rules restrict public ingress to port 138konform
Firewall rules restrict public ingress to port 139konform
Firewall rules restrict public ingress to port 1433konform
Firewall rules restrict public ingress to port 1434konform
Firewall rules restrict public ingress to port 2383konform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 27017konform
Firewall rules restrict public ingress to port 27018konform
Firewall rules restrict public ingress to port 27019konform
Firewall rules restrict public ingress to port 3020konform
Firewall rules restrict public ingress to port 3306konform
Firewall rules restrict public ingress to port 389konform
Firewall rules restrict public ingress to port 4505konform
Firewall rules restrict public ingress to port 4506konform
Firewall rules restrict public ingress to port 61621konform
Firewall rules restrict public ingress to port 636konform
Firewall rules restrict public ingress to port 7001konform
Firewall rules restrict public ingress to port 8000konform
Firewall rules restrict public ingress to port 9200konform
Firewall rules restrict public ingress to port 9300konform
No firewall rule allows access to Open Telemtry metrics endpoint from the internetkonform
No firewall rule allows access to port 1720 from the internetkonform
No firewall rule allows cPanel access from the internetkonform
No firewall rule allows etcd access from the internetkonform
No firewall rule allows MongoDB access from the internetkonform
No firewall rule allows NFS access from the internetkonform
No firewall rule allows Telnet access from the internetkonform
No firewall rule allows Tomcat Cluster Receiver access from the internetkonform

No issues outside of sla

KontrolleStatus
No issues outside of slakonform

Uses Lockfiles to pin code dependencies

KontrolleStatus
Use lockfiles in reposkonform

Enforces safe SSL protocol usage

KontrolleStatus
Amazon EKS Clusters should have secrets encryption enabledkonform
API Gateway REST API caching is unencryptedkonform
API Gateway stages are not using TLS 1.2 or higherkonform
App does not validate SSL certificates properlykonform
App uses an outdated TLS protocolkonform
App uses an outdated TLS protocolkonform
AWS ElastiCache Redis cluster should have encryption at rest enabledkonform
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHkonform
Azure Network Security Rule allows plaintext HTTP connectionskonform
Azure Network Security Rule allows plaintext HTTP connectionskonform
Azure Storage Account allows plaintext HTTP connectionskonform
Azure Storage Account allows plaintext HTTP connectionskonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Cloud functions require HTTPS invocationskonform
Cloud SQL db not enforcing SSLkonform
Cloud SQL instance requires SSL connectionskonform
Deprecated SSL Protocol Usage Detectedkonform
Deprecated SSL Protocol Usage Detectedkonform
DNSSEC is disabledkonform
DNSSEC is enabled for all managed zoneskonform
Docker image repository not encrypted at restkonform
Elasticsearch domain is not encrypted at restkonform
Elasticsearch domain might have outdated TLS versionkonform
Ensure all data stored in the RDS is securely encrypted at restkonform
Express is not emitting security headerskonform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 636konform
HTTP Client misconfigured with SSL validation disabledkonform
Insecure gRPC connection can lead to remote code executionkonform
Insecure gRPC connection can lead to remote code executionkonform
Insecure HTTP Request detectedkonform
Insecure TLS configuration detectedkonform
Insecure usage of `requests` sends data over cleartextkonform
Insecure websocket connection sends data over cleartextkonform
KMS keys have key rotation enabledkonform
Load balancer allows invalid HTTP headerskonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Load Balancers only accept HTTPS connectionskonform
NodeJS talks to database without encryptionkonform
NodeJS talks to database without encryptionkonform
Outbound Ansible connections are not encryptedkonform
Outbound Ansible connections are not encryptedkonform
Server certificates are not verified during SSL/TLS connectionskonform
Server hostnames not verified during SSL/TLS connectionskonform
Signature validation for dnf packages is offkonform
SNS topics are not encrypted at restkonform
SQS queue data is not encryptedkonform
SSL certificate verification turned off during requestskonform
SSL certificate verification turned off during requestskonform
Storage account does not enforce HTTPS-only traffickonform
TLS Certificate Validation Disabledkonform
TLS Certificate Validation Disabledkonform
Turning off TLS verification enables man-in-the-middle attackskonform
Using potentially unsafe FTP connections to move datakonform
Using potentially unsafe FTP connections to move datakonform
Virtual Machines have confidential computing enabledkonform
Weak SSL/TLS protocols usedkonform

Uses secure cookies

KontrolleStatus
Cookie missing HttpOnly flagkonform
Laravel cookies can be sent unencryptedkonform

Uses up-to-date cryptographic libraries

KontrolleStatus
Hashes should include an unpredictable saltkonform
Usage of deprecated or broken encryption detectedkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Using deprecated cryptographic librarykonform

Requires MFA for cloud users

KontrolleStatus
Users are logging in securelykonform