Back to Security and compliance

DORA

141 complying controls out of 141

Last synchronised :

The counter is the number of controls our continuous monitoring platform Aikido Security reports as satisfied, out of every control it assesses for this framework. They are all listed below, one by one.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Has deletion protection for cloud resources

ControlStatus
Cloud SQL instances have deletion protection enabledcomplying
Deletion protection is disabled for RDS databasecomplying
VM instances have deletion protection enabledcomplying

Uses load balancers

ControlStatus
Load Balancers only accept HTTPS connectionscomplying

Configured monitoring for domains

ControlStatus
Connected public facing domainscomplying

Has connected cloud environments

ControlStatus
Cloud environments are connectedcomplying

Has connected code repositories

ControlStatus
Code repositories are connectedcomplying

Has connected container repositories

ControlStatus
Container repositories are connectedcomplying

Cloud Infrastructure Configuration

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Azure Cognitive Services Network ACLs do not have IP rules configuredcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules allow unrestricted SSH accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Kubernetes master endpoint is not publicly availablecomplying
Vertex AI notebook instance has a public IP addresscomplying

Data Protection and Encryption

ControlStatus
API Gateway endpoints do not require an API key or authorizationcomplying
AWS EKS Node groups have implicit SSH access from any IPcomplying
Azure Cosmos DB is publicly reachablecomplying
Azure Key Vault allows public network accesscomplying
BigQuery table is anonymously or publicly accessiblecomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Cloud Storage bucket does not enforce public access preventioncomplying
Cloud Storage bucket does not enforce uniform bucket-level accesscomplying
Cloud Storage bucket is publicly accessiblecomplying
Dataproc cluster is anonymously or publicly accessiblecomplying
Default network exists in GCP projectcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Key Vault is publicly accessiblecomplying
KMS cryptographic key policy allows public accesscomplying
KMS keys have strict access permissionscomplying
Kubernetes dashboard might be deployedcomplying
Profiling endpoint automatically exposed on /debug/pprofcomplying
Pub/Sub topic is anonymously or publicly accessiblecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
SQL Server is publicly reachablecomplying

Encryption at Rest Enabled

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces HTTPS traffic to cloud instances

ControlStatus
Cloud functions require HTTPS invocationscomplying
Load Balancers only accept HTTPS connectionscomplying

Identity and Access Management (IAM)

ControlStatus
Users are logging in securelycomplying

Network Security

ControlStatus
Compute instances do not have public IP addressescomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying

Storage and Backup Security

ControlStatus
Azure Storage Account allow public accesscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
Firewall rules restrict public ingress to port 3020complying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying
Storage buckets have uniform bucket-level access enabledcomplying

Use of Cryptography: Enforces SSL

ControlStatus
Cloud SQL db not enforcing SSLcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
NodeJS talks to database without encryptioncomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying

Use of Cryptography: Enforces TLS

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Storage account does not enforce HTTPS-only trafficcomplying

Use of Cryptography: Secure Cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying

Cloud Resource Logging Enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Does not have any issues outside of their SLA

ControlStatus
Configure SLAscomplying
No critical issues outside of SLAcomplying
No high severity issues outside of SLAcomplying
No low severity issues outside of SLAcomplying
No medium severity issues outside of SLAcomplying

Has email notifications set up

ControlStatus
Email notifications are enabledcomplying

Has enabled security notifications

ControlStatus
Security notifications are enabledcomplying

Has backups for stateful cloud resources

ControlStatus
Databases have automated backups enabledcomplying

Is GDPR Compliant

ControlStatus
GDPR Compliancecomplying

Does not have any issues outside of their SLA

ControlStatus
Configure SLAscomplying
No critical issues outside of SLAcomplying
No high severity issues outside of SLAcomplying
No low severity issues outside of SLAcomplying
No medium severity issues outside of SLAcomplying

Has email notifications set up

ControlStatus
Email notifications are enabledcomplying

Has enabled security notifications

ControlStatus
Security notifications are enabledcomplying

Configured monitoring for code repositories

ControlStatus
Configured monitoring for all code repositoriescomplying

Configured monitoring for container images

ControlStatus
Configured monitoring for all container imagescomplying