Zurück zu Sicherheit und Compliance

SOC 2

523 konforme Kontrollen von 525

Letzte Synchronisierung :

Der Zähler stammt von unserer Plattform für kontinuierliche Überwachung Aikido Security, die Detailliste führt die von ihr als erfüllt gemeldeten Kontrollen auf. Beide Zahlen können leicht voneinander abweichen.

Die Bezeichnungen der Bewertungen, Typen und Kontrollen stammen aus den ursprünglichen Rahmenwerken und sind daher auf Englisch.

Sicherheitsauditbericht anfordern

Configured monitoring for code repositories

KontrolleStatus
Configured monitoring for all code repositorieskonform

Configured monitoring for container images

KontrolleStatus
Configured monitoring for all container imageskonform

Configured monitoring for domains

KontrolleStatus
Configured monitoring for domainskonform

Does not have any severe open source dependency issues

KontrolleStatus
No active critical open source dependency issueskonform
No active high severity open source dependency issueskonform

Does not have any severe surface monitoring issues

KontrolleStatus
No active critical surface monitoring issueskonform
No active high severity surface monitoring issueskonform

Properly manages the identity of cloud users

KontrolleStatus
Firewall rules restrict public ingress to port 636konform
No user has both the Service Account User and Service Account Admin rolekonform
Service accounts have strict access permissionskonform
Users are logging in securelykonform
Users are only allowed to use corporate emailskonform

Threat detection is enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform

Applies the least privilege principle for cloud resource

KontrolleStatus
Access Approval is enabled for the projectkonform
Compute instances have OS Login enabledkonform
GKE clusters have the Kubernetes Dashboard disabledkonform
Kubernetes pods are isolatedkonform
No instance uses the default service accountkonform
No user has both the Service Account User and Service Account Admin rolekonform
Project-wide SSH keys are blockedkonform
Service accounts have strict access permissionskonform
VM instances have strict access permissionskonform

Applies the least privilege principle to cloud resources

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
KMS keys have strict access permissionskonform
Kubernetes master endpoint is not publicly availablekonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform

Enabled security logging for cloud instances

KontrolleStatus
Audit Configuration logging is enabledkonform
Logging and alerts are enabled for Project Ownership assignmentskonform
Storage Permissions logging is enabledkonform
VPC Firewall has Rule logging enabledkonform

Requires MFA for cloud users

KontrolleStatus
Users are logging in securelykonform

Threat detection is enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform

Applies the least privilege principle for cloud resource

KontrolleStatus
Access Approval is enabled for the projectkonform
Compute instances have OS Login enabledkonform
GKE clusters have the Kubernetes Dashboard disabledkonform
Kubernetes pods are isolatedkonform
Load Balancers only accept HTTPS connectionskonform
No instance uses the default service accountkonform
No user has both the Service Account User and Service Account Admin rolekonform
Project-wide SSH keys are blockedkonform
Service accounts have strict access permissionskonform
VM instances have strict access permissionskonform

Does not have any severe infrastructure as code issues

KontrolleStatus
No active critical infrastructure as code issueskonform
No active high severity infrastructure as code issueskonform

Has deletion protection for cloud resources

KontrolleStatus
Cloud SQL instances have deletion protection enabledkonform
VM instances have deletion protection enabledkonform

Properly manages the identity of cloud users

KontrolleStatus
Firewall rules restrict public ingress to port 636konform
Users are logging in securelykonform
Users are only allowed to use corporate emailskonform

Has separate production and test environments

KontrolleStatus
No cloud environment used for mixed purposes (eg production and staging)konform

Prevents unauthorized access via ssh

KontrolleStatus
AWS EKS Node groups have implicit SSH access from any IPkonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules allow RDP access from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow unrestricted SSH accesskonform

Prevents unauthorized public access to database

KontrolleStatus
BigQuery table is anonymously or publicly accessiblekonform
Firewall rules restrict public ingress to port 1433konform
Firewall rules restrict public ingress to port 1434konform
Firewall rules restrict public ingress to port 2383konform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 27017konform
Firewall rules restrict public ingress to port 27018konform
Firewall rules restrict public ingress to port 27019konform
Firewall rules restrict public ingress to port 3306konform
Firewall rules restrict public ingress to port 61621konform
Firewall rules restrict public ingress to port 7001konform
Firewall rules restrict public ingress to port 9200konform
Firewall rules restrict public ingress to port 9300konform
No firewall rule allows MongoDB access from the internetkonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform

Prevents unauthorized public access to file storage

KontrolleStatus
Azure Storage Account allow public accesskonform
Azure Storage blobs do not restrict public access for nested itemskonform
Firewall rules restrict public ingress to port 3020konform
S3 bucket grants public access to all contentskonform
S3 Buckets should have block public access globallykonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform

Has secured load balancer access points

KontrolleStatus
Users are logging in securelykonform

Has secured load balancer access points

KontrolleStatus
AWS EKS Node groups have implicit SSH access from any IPkonform
Compute instances have OS Login enabledkonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules allow RDP access from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow unrestricted SSH accesskonform
Load Balancers only accept HTTPS connectionskonform
Project-wide SSH keys are blockedkonform

Applies the least privilege principle to cloud resources

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
KMS keys have strict access permissionskonform
Kubernetes master endpoint is not publicly availablekonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform

Encrypts data at rest

KontrolleStatus
Amazon EKS Clusters should have secrets encryption enabledkonform
API Gateway REST API caching is unencryptedkonform
AWS ElastiCache Redis cluster should have encryption at rest enabledkonform
Docker image repository not encrypted at restkonform
Elasticsearch domain is not encrypted at restkonform
Ensure all data stored in the RDS is securely encrypted at restkonform
KMS keys have key rotation enabledkonform
SNS topics are not encrypted at restkonform
SQS queue data is not encryptedkonform
Virtual Machines have confidential computing enabledkonform

Enforces encryption of data in transit

KontrolleStatus
API Gateway stages are not using TLS 1.2 or higherkonform
App does not validate SSL certificates properlykonform
App uses an outdated TLS protocolkonform
App uses an outdated TLS protocolkonform
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHkonform
Azure Network Security Rule allows plaintext HTTP connectionskonform
Azure Network Security Rule allows plaintext HTTP connectionskonform
Azure Storage Account allows plaintext HTTP connectionskonform
Azure Storage Account allows plaintext HTTP connectionskonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Cloud functions require HTTPS invocationskonform
Cloud SQL db not enforcing SSLkonform
Cloud SQL instance requires SSL connectionskonform
Cookie missing HttpOnly flagkonform
Deprecated SSL Protocol Usage Detectedkonform
Deprecated SSL Protocol Usage Detectedkonform
DNSSEC is disabledkonform
DNSSEC is enabled for all managed zoneskonform
Elasticsearch domain might have outdated TLS versionkonform
Express is not emitting security headerskonform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 636konform
HTTP Client misconfigured with SSL validation disabledkonform
Insecure gRPC connection can lead to remote code executionkonform
Insecure gRPC connection can lead to remote code executionkonform
Insecure HTTP Request detectedkonform
Insecure TLS configuration detectedkonform
Insecure usage of `requests` sends data over cleartextkonform
Insecure websocket connection sends data over cleartextkonform
Laravel cookies can be sent unencryptedkonform
Load balancer allows invalid HTTP headerskonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Load Balancers only accept HTTPS connectionskonform
NodeJS talks to database without encryptionkonform
NodeJS talks to database without encryptionkonform
Outbound Ansible connections are not encryptedkonform
Outbound Ansible connections are not encryptedkonform
Server certificates are not verified during SSL/TLS connectionskonform
Server hostnames not verified during SSL/TLS connectionskonform
Signature validation for dnf packages is offkonform
SSL certificate verification turned off during requestskonform
SSL certificate verification turned off during requestskonform
Storage account does not enforce HTTPS-only traffickonform
TLS Certificate Validation Disabledkonform
TLS Certificate Validation Disabledkonform
Turning off TLS verification enables man-in-the-middle attackskonform
Usage of deprecated or broken encryption detectedkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Using potentially unsafe FTP connections to move datakonform
Using potentially unsafe FTP connections to move datakonform
Weak SSL/TLS protocols usedkonform

Has measures against SQL injection attacks

KontrolleStatus
NoSQL injection attack possiblekonform
NoSQL injection attack possiblekonform
NoSQL injection attack possiblekonform
Potential NoSQL injection via string-based query concatenationkonform
Potential NoSQL injection via string-based query concatenationkonform
Potential NoSQL injection via string-based query concatenationkonform
Potential NoSQL injection via string-based query concatenationkonform
Potential SQL injection in Doctrine's QueryBuilderkonform
Potential SQL injection in sqlite3 via string-based query concatenationkonform
Potential SQL injection through JDBC via string-based query concatenationkonform
Potential SQL injection using sqflite execute sinkkonform
Potential SQL injection via Drupal database functionalitykonform
Potential SQL injection via dynamic raw query constructionkonform
Potential SQL injection via dynamic raw query constructionkonform
Potential SQL injection via dynamic raw query constructionkonform
Potential SQL injection via Laravel functionkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenationkonform
Potential SQL injection via string-based query concatenation using AuraSQL framework functionskonform
Potential SQL injection via Yii functionkonform
Potential SQL injection when bypassing Django ORM with extra()konform
Potential SQL injection when bypassing Django ORM with RawSQL()konform
Potential SQL injection when bypassing Doctrine ORM with raw querykonform

Is protected against command injections attacks

KontrolleStatus
A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input.konform
Possible command injection via Process.Startkonform
Possible command injection via Process.Startkonform
Possible command injection via shell scriptkonform
Possible command injection via user-controlled input to clojure.java.shell/shkonform
Potential command injection via Command APIkonform
Potential command injection via Process.runkonform
Use of vulnerable ingress-nginx controllerkonform
Xpath injection attack could lead to information extractionkonform
Xpath injection attack could lead to information extractionkonform

Is protected against SSRF attacks

KontrolleStatus
A timing attack might allow hackers to bruteforce passwordskonform
EC2 IAM roles vulnerable to SSRF attackskonform
GCP Kubernetes engine clusters vulnerable to SSRF attackskonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
HTTP request might enable SSRF attackkonform
Potential file inclusion attack via reading filekonform
Potential file inclusion attack via reading filekonform
Potential file inclusion attack via reading filekonform
Potential user input in HTTP request may allow SSRF attackkonform
Potential user input in HTTP request may allow SSRF attackkonform
Simple DOS attack possible due to http.server misconfigurationkonform
User data used in Puppeteer methods can result in SSRFkonform
User data used in Puppeteer methods can result in SSRFkonform

Prevents the exposure of sensitive data

KontrolleStatus
Currently there are no exposed secretskonform

Prevents XSS attacks

KontrolleStatus
Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilitieskonform
Directly writing unsanitized input to http.ResponseWriter can lead to XSSkonform
Disabling JSON HTML Escaping in ActiveSupport may lead to XSSkonform
DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinkskonform
HttpServletResponse output can be used for XSS attackskonform
Improper sanitization in dynamic attribute bindings can lead to XSS attackskonform
Input validation disabled in controllerkonform
Jinja2 template config can lead to XSS attackskonform
Potential Cross Site Scripting (XSS) via window.location.hrefkonform
Potential XSS due to enabling bypassSecurityTrustUrlkonform
Potential XSS via MarkupStr(...) in Razor template may lead to XSSkonform
Rendering unescaped input can lead to XSS attackskonform
Rendering unescaped input can lead to XSS attackskonform
Rendering unescaped input can lead to XSS attackskonform
Rendering unescaped input can lead to XSS attackskonform
Rendering unescaped input can lead to XSS attackskonform
Rendering unescaped input can lead to XSS attackskonform
Rendering unescaped input in EJS template can lead to XSS attackskonform
Rendering unescaped input in handlebar/mustache template can lead to XSS attackskonform
Rendering unescaped input in HTML template can lead to XSS attackskonform
Unsanitized user input in jQuery DOM handling methods detectedkonform
Unsanitized user input leads to cross-site scripting (XSS)konform
Using dangerouslySetInnerHTML in React can lead to XSS attackskonform
Using document write methods can lead to XSS attackskonform
Using document write methods can lead to XSS attackskonform
Using document write methods can lead to XSS attackskonform
Using raw on potential user input can leads to XSSkonform
Using v-html in Vue templates can lead to XSS attackskonform

Requires MFA for cloud users

KontrolleStatus
Users are logging in securelykonform

Threat detection is enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform

Encrypts data at rest

KontrolleStatus
Amazon EKS Clusters should have secrets encryption enabledkonform
API Gateway REST API caching is unencryptedkonform
AWS ElastiCache Redis cluster should have encryption at rest enabledkonform
Docker image repository not encrypted at restkonform
Elasticsearch domain is not encrypted at restkonform
Ensure all data stored in the RDS is securely encrypted at restkonform
KMS keys have key rotation enabledkonform
SNS topics are not encrypted at restkonform
Virtual Machines have confidential computing enabledkonform

Enforces encryption of data in transit

KontrolleStatus
API Gateway stages are not using TLS 1.2 or higherkonform
App does not validate SSL certificates properlykonform
App uses an outdated TLS protocolkonform
App uses an outdated TLS protocolkonform
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHkonform
Azure Network Security Rule allows plaintext HTTP connectionskonform
Azure Network Security Rule allows plaintext HTTP connectionskonform
Azure Storage Account allows plaintext HTTP connectionskonform
Azure Storage Account allows plaintext HTTP connectionskonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Cloud functions require HTTPS invocationskonform
Cloud SQL db not enforcing SSLkonform
Cloud SQL instance requires SSL connectionskonform
Cookie missing HttpOnly flagkonform
Deprecated SSL Protocol Usage Detectedkonform
Deprecated SSL Protocol Usage Detectedkonform
DNSSEC is disabledkonform
DNSSEC is enabled for all managed zoneskonform
Elasticsearch domain might have outdated TLS versionkonform
Express is not emitting security headerskonform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 636konform
HTTP Client misconfigured with SSL validation disabledkonform
Insecure gRPC connection can lead to remote code executionkonform
Insecure gRPC connection can lead to remote code executionkonform
Insecure HTTP Request detectedkonform
Insecure TLS configuration detectedkonform
Insecure usage of `requests` sends data over cleartextkonform
Insecure websocket connection sends data over cleartextkonform
Laravel cookies can be sent unencryptedkonform
Load balancer allows invalid HTTP headerskonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Load Balancers only accept HTTPS connectionskonform
NodeJS talks to database without encryptionkonform
NodeJS talks to database without encryptionkonform
Outbound Ansible connections are not encryptedkonform
Outbound Ansible connections are not encryptedkonform
Server certificates are not verified during SSL/TLS connectionskonform
Server hostnames not verified during SSL/TLS connectionskonform
Signature validation for dnf packages is offkonform
SQS queue data is not encryptedkonform
SSL certificate verification turned off during requestskonform
SSL certificate verification turned off during requestskonform
Storage account does not enforce HTTPS-only traffickonform
TLS Certificate Validation Disabledkonform
TLS Certificate Validation Disabledkonform
Turning off TLS verification enables man-in-the-middle attackskonform
Using potentially unsafe FTP connections to move datakonform
Using potentially unsafe FTP connections to move datakonform
Weak SSL/TLS protocols usedkonform

Uses up to date cryptography libraries

KontrolleStatus
Hashes should include an unpredictable saltkonform
Usage of deprecated or broken encryption detectedkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Using deprecated cryptographic librarykonform

Applies the least privilege principle for cloud resource

KontrolleStatus
Access Approval is enabled for the projectkonform
Access to BigQuery datasets are restrictedkonform
API key restricts usage to certain APIskonform
API key restricts usage to certain clientskonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Compute instances have IP forwarding disabledkonform
Compute instances have OS Login enabledkonform
Compute instances have serial port access disabledkonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
GKE clusters have the GKE Metadata Server enabledkonform
GKE clusters have the Kubernetes Dashboard disabledkonform
GKE node pools use dedicated service accountskonform
KMS keys have strict access permissionskonform
Kubernetes master endpoint is not publicly availablekonform
Kubernetes pods are isolatedkonform
No instance uses the default service accountkonform
No user has both the Service Account User and Service Account Admin rolekonform
Project-wide SSH keys are blockedkonform
Service accounts have strict access permissionskonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform
Storage buckets have uniform bucket-level access enabledkonform
Users are logging in securelykonform
VM instances have strict access permissionskonform

MFA is enforced for cloud users

KontrolleStatus
Users are logging in securelykonform

Prevents public access to cloud resources

KontrolleStatus
Access to BigQuery datasets are restrictedkonform
AKS API server does not limit access by IP rangeskonform
Amazon EKS Clusters public endpoints should not allow traffic from any IPkonform
API Gateway endpoints do not require an API key or authorizationkonform
AWS EKS Node groups have implicit SSH access from any IPkonform
Azure Cognitive Services allows unrestricted public network accesskonform
Azure Cosmos DB is publicly reachablekonform
Azure Key Vault allows public network accesskonform
Azure Storage Account allow public accesskonform
Azure Storage blobs do not restrict public access for nested itemskonform
BigQuery table is anonymously or publicly accessiblekonform
Cloud functions are not publicly accessiblekonform
Cloud functions have strict access policieskonform
Cloud Storage bucket does not enforce public access preventionkonform
Cloud Storage bucket does not enforce uniform bucket-level accesskonform
Cloud Storage bucket is publicly accessiblekonform
Compute instances do not have public IP addresseskonform
Dataproc cluster is anonymously or publicly accessiblekonform
Default network exists in GCP projectkonform
Firewall rule prevents Docker API access from anywherekonform
Firewall rule prevents RDP access from anywherekonform
Firewall rule prevents SSH access from anywherekonform
Firewall rules allow RDP access from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow SSH from any public IPkonform
Firewall rules allow unrestricted RDP accesskonform
Firewall rules allow unrestricted SSH accesskonform
Firewall rules do not allow unrestricted ingress to all ports and protocolskonform
Firewall rules restrict public ingress to port 11214konform
Firewall rules restrict public ingress to port 11215konform
Firewall rules restrict public ingress to port 135konform
Firewall rules restrict public ingress to port 137konform
Firewall rules restrict public ingress to port 138konform
Firewall rules restrict public ingress to port 139konform
Firewall rules restrict public ingress to port 1433konform
Firewall rules restrict public ingress to port 1434konform
Firewall rules restrict public ingress to port 23konform
Firewall rules restrict public ingress to port 2379konform
Firewall rules restrict public ingress to port 2383konform
Firewall rules restrict public ingress to port 2484konform
Firewall rules restrict public ingress to port 27017konform
Firewall rules restrict public ingress to port 27018konform
Firewall rules restrict public ingress to port 27019konform
Firewall rules restrict public ingress to port 3000konform
Firewall rules restrict public ingress to port 3020konform
Firewall rules restrict public ingress to port 3306konform
Firewall rules restrict public ingress to port 389konform
Firewall rules restrict public ingress to port 4505konform
Firewall rules restrict public ingress to port 4506konform
Firewall rules restrict public ingress to port 5500konform
Firewall rules restrict public ingress to port 5800konform
Firewall rules restrict public ingress to port 61621konform
Firewall rules restrict public ingress to port 636konform
Firewall rules restrict public ingress to port 7001konform
Firewall rules restrict public ingress to port 8000konform
Firewall rules restrict public ingress to port 9200konform
Firewall rules restrict public ingress to port 9300konform
Key Vault is publicly accessiblekonform
KMS cryptographic key policy allows public accesskonform
KMS keys have strict access permissionskonform
Kubernetes dashboard might be deployedkonform
Kubernetes master endpoint is not publicly availablekonform
No firewall rule allows access to Open Telemtry metrics endpoint from the internetkonform
No firewall rule allows access to port 1720 from the internetkonform
No firewall rule allows cPanel access from the internetkonform
No firewall rule allows etcd access from the internetkonform
No firewall rule allows MongoDB access from the internetkonform
No firewall rule allows NFS access from the internetkonform
No firewall rule allows Telnet access from the internetkonform
No firewall rule allows Tomcat Cluster Receiver access from the internetkonform
Profiling endpoint automatically exposed on /debug/pprofkonform
Pub/Sub topic is anonymously or publicly accessiblekonform
S3 bucket grants public access to all contentskonform
S3 Buckets should have block public access globallykonform
SQL instance root user has strict access permissionskonform
SQL instances do not have a public IP assignedkonform
SQL instances have strict access permissionkonform
SQL Server is publicly reachablekonform
Storage Buckets have proper access ruleskonform
Storage buckets have public access prevention enabledkonform
Vertex AI notebook instance has a public IP addresskonform

Enforces latest TLS version

KontrolleStatus
API Gateway stages are not using TLS 1.2 or higherkonform
Azure Storage Accounts does not enforce latest TLS versionkonform
Elasticsearch domain might have outdated TLS versionkonform
Load balancer allows unencrypted or encrypted traffic with outdated TLS policykonform
Storage account does not enforce HTTPS-only traffickonform

Uses up to date cryptography libraries

KontrolleStatus
Hashes should include an unpredictable saltkonform
Usage of deprecated or broken encryption detectedkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Use of broken or outdated encryptionkonform
Using deprecated cryptographic librarykonform

Enabled security logging for cloud instances

KontrolleStatus
Alerting policies have a notification channel configuredkonform
Amazon EKS Clusters should have control plane logging enabledkonform
Audit Configuration logging is enabledkonform
Logging and alerts are enabled for Project Ownership assignmentskonform
Storage Permissions logging is enabledkonform
VPC Firewall has Rule logging enabledkonform

Prevents container orchestration takeover

KontrolleStatus
AKS local admin account is still enabledkonform
Dangerous Impersonate permission given to ServiceAccount or nodekonform

Protects unauthorized runtime access

KontrolleStatus
Container processes can gain more privileges than its parentkonform
Container running as root can allow attacker to escalate attackskonform
Default Kubernetes settings allow containers to eavesdrop on traffic.konform
Default security context allows pods to access host system.konform
Docker container configured to run as user with root privilegeskonform
Docker container runs as default root userkonform
Filesystem for docker container should not be writeablekonform
Privileged container can allow attackers to escalate attackskonform

Aikido Malware Scanner is enabled

KontrolleStatus
Aikido Malware Scanner is enabledkonform

Threat detection is enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform

Connected code repositories

KontrolleStatus
Connect code repositorieskonform

Connected public facing domain

KontrolleStatus
Connect public facing domainkonform

Does not have any issues outside of their SLA

KontrolleStatus
No issues outside of slakonform

Uses Lockfiles to pin code dependencies

KontrolleStatus
Use lockfiles in reposkonform

Does not have risky licenses

KontrolleStatus
No risky licenses in dependencieskonform

Connected code repositories

KontrolleStatus
Connect code repositorieskonform

Threat detection is enabled

KontrolleStatus
Alerting policies have a notification channel configuredkonform

Configured SLAs to resolve issues

KontrolleStatus
Configure SLAskonform

Connected cloud environment

KontrolleStatus
Connect a cloud environmentkonform

Connected code repositories

KontrolleStatus
Connect code repositorieskonform

Connected public facing domain

KontrolleStatus
Connect public facing domainkonform

Enabled security logging for cloud instances

KontrolleStatus
Alerting policies have a notification channel configuredkonform
Amazon EKS Clusters should have control plane logging enabledkonform
Audit Configuration logging is enabledkonform
Logging and alerts are enabled for Project Ownership assignmentskonform
Storage Permissions logging is enabledkonform
VPC Firewall has Rule logging enabledkonform

Has no critical open source dependency issues

KontrolleStatus
There are critical open source dependency issueskonform

Runtimes are up to date

KontrolleStatus
AWS MQBroker version is outdatedkonform
GKE clusters use stable release channels with automatic upgradeskonform
GKE node pools have node auto-upgrade enabledkonform
No AKS cluster upgrade channel is chosenkonform

Prevents the exposure of sensitive data

KontrolleStatus
Currently there are no exposed secretskonform

Tracks progress via an issue tracker

KontrolleStatus
Integration with issue tracker enabledkonform

Has backups for stateful cloud resources

KontrolleStatus
Databases have automated backups enabledkonform
DynamoDB backups are offkonform