Back to Security and compliance

CIS Controls v8

456 complying controls out of 456

Last synchronised :

The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Enforces safe SSL protocol usage

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Cookie missing HttpOnly flagcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Elasticsearch domain might have outdated TLS versioncomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Laravel cookies can be sent unencryptedcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SQS queue data is not encryptedcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Runtimes are up to date

ControlStatus
AWS MQBroker version is outdatedcomplying
GKE clusters use stable release channels with automatic upgradescomplying
GKE node pools have node auto-upgrade enabledcomplying
No AKS cluster upgrade channel is chosencomplying

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
AKS local admin account is still enabledcomplying
Compute instances have OS Login enabledcomplying
Dangerous Impersonate permission given to ServiceAccount or nodecomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
ServiceAccount or node can read all secretscomplying
VM instances have strict access permissionscomplying

Applies the least privilege principle for cloud users

ControlStatus
Firewall rules restrict public ingress to port 636complying
Users are logging in securelycomplying
Users are only allowed to use corporate emailscomplying

Applies the least privilege principle to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
API Gateway endpoints do not require an API key or authorizationcomplying
AWS EKS Node groups have implicit SSH access from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Azure Cosmos DB is publicly reachablecomplying
Azure Key Vault allows public network accesscomplying
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
BigQuery table is anonymously or publicly accessiblecomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Cloud Storage bucket does not enforce public access preventioncomplying
Cloud Storage bucket does not enforce uniform bucket-level accesscomplying
Cloud Storage bucket is publicly accessiblecomplying
Dataproc cluster is anonymously or publicly accessiblecomplying
Default network exists in GCP projectcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules allow unrestricted SSH accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Key Vault is publicly accessiblecomplying
KMS cryptographic key policy allows public accesscomplying
KMS keys have strict access permissionscomplying
Kubernetes dashboard might be deployedcomplying
Kubernetes master endpoint is not publicly availablecomplying
Profiling endpoint automatically exposed on /debug/pprofcomplying
Pub/Sub topic is anonymously or publicly accessiblecomplying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
SQL Server is publicly reachablecomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying
Vertex AI notebook instance has a public IP addresscomplying

Enabled security logging for cloud instances

ControlStatus
Cloud SQL instances have deletion protection enabledcomplying
Deletion protection is disabled for RDS databasecomplying
VM instances have deletion protection enabledcomplying

Enforces encryption of data in transit

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Cookie missing HttpOnly flagcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Domain SSL Certificate Expirationcomplying
Elasticsearch domain might have outdated TLS versioncomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HSTS header has malformed contentcomplying
HSTS header has malformed Max-Age directivecomplying
HSTS header is defined via meta tagcomplying
HSTS header is disabledcomplying
HSTS header is malformed directivecomplying
HSTS header is missingcomplying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Laravel cookies can be sent unencryptedcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
Multiple HSTS headers are being setcomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SQS queue data is not encryptedcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
TLS not enforced with valid HSTS headercomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Encrypts data at rest

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enabled security logging for cloud instances

ControlStatus
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Enforces encryption of data in transit

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Compute instances do not have public IP addressescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules allow unrestricted SSH accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
Kubernetes master endpoint is not publicly availablecomplying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying
Vertex AI notebook instance has a public IP addresscomplying

Prevents unauthorized public access to database

ControlStatus
BigQuery table is anonymously or publicly accessiblecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying

Prevents unauthorized public access to file storage

ControlStatus
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Enforces encryption of data in transit

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Compute instances do not have public IP addressescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules allow unrestricted SSH accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
Kubernetes master endpoint is not publicly availablecomplying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying
Vertex AI notebook instance has a public IP addresscomplying

Enforces HTTPS traffic to cloud instances

ControlStatus
Load Balancers only accept HTTPS connectionscomplying

Enforces latest TLS version

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Storage account does not enforce HTTPS-only trafficcomplying

Uses DNSSEC extensions

ControlStatus
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
AKS local admin account is still enabledcomplying
Compute instances have OS Login enabledcomplying
Dangerous Impersonate permission given to ServiceAccount or nodecomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
ServiceAccount or node can read all secretscomplying
VM instances have strict access permissionscomplying

Requires MFA for access to cloud resources

ControlStatus
Users are logging in securelycomplying

Requires MFA for access to cloud resources

ControlStatus
Users are logging in securelycomplying

Requires MFA for access to cloud resources

ControlStatus
Users are logging in securelycomplying

Configured SLAs to resolve issues

ControlStatus
Configure SLAscomplying

Enabled security logging for cloud instances

ControlStatus
Alerting policies have a notification channel configuredcomplying
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

No malware issues

ControlStatus
No open malware issuescomplying

Prevents unwanted write operations to filesystems

ControlStatus
Container processes can gain more privileges than its parentcomplying
Container running as root can allow attacker to escalate attackscomplying
Default Kubernetes settings allow containers to eavesdrop on traffic.complying
Default security context allows pods to access host system.complying
Docker container configured to run as user with root privilegescomplying
Docker container runs as default root usercomplying
Filesystem for docker container should not be writeablecomplying
Privileged container can allow attackers to escalate attackscomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Uses Lockfiles to pin code dependencies

ControlStatus
Use lockfiles in reposcomplying

Has backups for stateful cloud resources

ControlStatus
Databases have automated backups enabledcomplying
DynamoDB backups are offcomplying

Enforces HTTPS traffic to cloud instances

ControlStatus
Cloud functions require HTTPS invocationscomplying
Load Balancers only accept HTTPS connectionscomplying

Prevents unauthorized public access to database

ControlStatus
BigQuery table is anonymously or publicly accessiblecomplying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
No firewall rule allows MongoDB access from the internetcomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying

Prevents unauthorized public access to networks and instances

ControlStatus
AWS EKS Node groups have implicit SSH access from any IPcomplying
Compute instances have OS Login enabledcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted SSH accesscomplying
Project-wide SSH keys are blockedcomplying

Enforces encryption of data in transit

ControlStatus
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL instance requires SSL connectionscomplying
Cookie missing HttpOnly flagcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Laravel cookies can be sent unencryptedcomplying
Load balancer allows invalid HTTP headerscomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SQS queue data is not encryptedcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Prevents unauthorized public access to networks and instances

ControlStatus
AWS EKS Node groups have implicit SSH access from any IPcomplying
Compute instances have OS Login enabledcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted SSH accesscomplying
Project-wide SSH keys are blockedcomplying

Uses secure communications protocols

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud SQL db not enforcing SSLcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
NodeJS talks to database without encryptioncomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying

Enabled security logging for cloud instances

ControlStatus
Alerting policies have a notification channel configuredcomplying
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Tracks progress via an issue tracker

ControlStatus
Integration with issue tracker enabledcomplying

Configured SLAs to resolve issues

ControlStatus
Configure SLAscomplying

No risky licenses in 3rd party dependencies

ControlStatus
No risky licenses in dependenciescomplying

no_issues_outside_of_sla

ControlStatus
No issues outside of slacomplying

Has separate production and test environments

ControlStatus
No cloud environment used for mixed purposes (eg production and staging)complying

Configured monitoring for code repositories

ControlStatus
Configured monitoring for all code repositoriescomplying