Back to Security and compliance

RGPD

175 complying controls out of 175

Last synchronised :

The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Enforces Multi-Factor Authentication (MFA)

ControlStatus
Users are logging in securelycomplying

Proper Access Management for Resources

ControlStatus
Access Approval is enabled for the projectcomplying
AKS local admin account is still enabledcomplying
Compute instances have OS Login enabledcomplying
Dangerous Impersonate permission given to ServiceAccount or nodecomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
ServiceAccount or node can read all secretscomplying
VM instances have strict access permissionscomplying

Proper Access Management for Users

ControlStatus
Users are only allowed to use corporate emailscomplying

Proper Access Management to Resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
API Gateway endpoints do not require an API key or authorizationcomplying
AWS EKS Node groups have implicit SSH access from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Azure Cosmos DB is publicly reachablecomplying
Azure Key Vault allows public network accesscomplying
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
BigQuery table is anonymously or publicly accessiblecomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Cloud Storage bucket does not enforce public access preventioncomplying
Cloud Storage bucket does not enforce uniform bucket-level accesscomplying
Cloud Storage bucket is publicly accessiblecomplying
Dataproc cluster is anonymously or publicly accessiblecomplying
Default network exists in GCP projectcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules allow unrestricted SSH accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Key Vault is publicly accessiblecomplying
KMS cryptographic key policy allows public accesscomplying
KMS keys have strict access permissionscomplying
Kubernetes dashboard might be deployedcomplying
Kubernetes master endpoint is not publicly availablecomplying
Profiling endpoint automatically exposed on /debug/pprofcomplying
Pub/Sub topic is anonymously or publicly accessiblecomplying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
SQL Server is publicly reachablecomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying
Vertex AI notebook instance has a public IP addresscomplying

Encryption at Rest Enabled

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces HTTPS traffic to cloud instances

ControlStatus
Cloud functions require HTTPS invocationscomplying
Load Balancers only accept HTTPS connectionscomplying

Runtimes are up to date

ControlStatus
AWS MQBroker version is outdatedcomplying
GKE clusters use stable release channels with automatic upgradescomplying
GKE node pools have node auto-upgrade enabledcomplying
No AKS cluster upgrade channel is chosencomplying
No Critical End-of-Life (EOL) Issuescomplying
No High End-of-Life (EOL) Issuescomplying

Use of Cryptography Libraries

ControlStatus
Hashes should include an unpredictable saltcomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using deprecated cryptographic librarycomplying

Use of Cryptography: Enforces SSL

ControlStatus
Cloud SQL db not enforcing SSLcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
NodeJS talks to database without encryptioncomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying

Use of Cryptography: Enforces TLS

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Storage account does not enforce HTTPS-only trafficcomplying

Use of Cryptography: Secure Cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying

Backups Enabled

ControlStatus
Databases have automated backups enabledcomplying
DynamoDB backups are offcomplying

Logging Enabled

ControlStatus
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Threat Detection Enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Encryption at Rest Enabled

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces HTTPS traffic to cloud instances

ControlStatus
Cloud functions require HTTPS invocationscomplying
Load Balancers only accept HTTPS connectionscomplying

Use of Cryptography Libraries

ControlStatus
Hashes should include an unpredictable saltcomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using deprecated cryptographic librarycomplying

Use of Cryptography: Enforces SSL

ControlStatus
Cloud SQL db not enforcing SSLcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
NodeJS talks to database without encryptioncomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying

Use of Cryptography: Enforces TLS

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Storage account does not enforce HTTPS-only trafficcomplying

Use of Cryptography: Secure Cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying