Back to Security and compliance

ISO 27001:2022

455 complying controls out of 455

Last synchronised :

The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
Compute instances have OS Login enabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
VM instances have strict access permissionscomplying

Applies the least privilege principle for cloud users

ControlStatus
Firewall rules restrict public ingress to port 636complying
Users are logging in securelycomplying
Users are only allowed to use corporate emailscomplying

Applies the least privilege principle to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
KMS keys have strict access permissionscomplying
Kubernetes master endpoint is not publicly availablecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Prevents the exposure of sensitive data

ControlStatus
Currently there are no exposed secretscomplying

Has backups for stateful cloud resources

ControlStatus
Databases have automated backups enabledcomplying

Uses load balancers correctly

ControlStatus
Load Balancers only accept HTTPS connectionscomplying

Tracks progress via an issue tracker

ControlStatus
Integration with issue tracker enabledcomplying

Enabled security logging for cloud instances

ControlStatus
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Has enabled threat detection

ControlStatus
Alerting policies have a notification channel configuredcomplying

Runs cloud instances on up-to-date versions

ControlStatus
GKE clusters use stable release channels with automatic upgradescomplying
GKE node pools have node auto-upgrade enabledcomplying

Uses Lockfiles to pin code dependencies

ControlStatus
Usage of lockfiles in code repositoriescomplying

Encrypts data at rest

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces encryption of data in transit

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Cookie missing HttpOnly flagcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Elasticsearch domain might have outdated TLS versioncomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Laravel cookies can be sent unencryptedcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Has measures against SQL injection attacks

ControlStatus
NoSQL injection attack possiblecomplying
NoSQL injection attack possiblecomplying
NoSQL injection attack possiblecomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential SQL injection in Doctrine's QueryBuildercomplying
Potential SQL injection in sqlite3 via string-based query concatenationcomplying
Potential SQL injection through JDBC via string-based query concatenationcomplying
Potential SQL injection using sqflite execute sinkcomplying
Potential SQL injection via Drupal database functionalitycomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via Laravel functioncomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenation using AuraSQL framework functionscomplying
Potential SQL injection via Yii functioncomplying
Potential SQL injection when bypassing Django ORM with extra()complying
Potential SQL injection when bypassing Django ORM with RawSQL()complying
Potential SQL injection when bypassing Doctrine ORM with raw querycomplying

Is protected against SSRF attacks

ControlStatus
A timing attack might allow hackers to bruteforce passwordscomplying
EC2 IAM roles vulnerable to SSRF attackscomplying
GCP Kubernetes engine clusters vulnerable to SSRF attackscomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
Potential file inclusion attack via reading filecomplying
Potential file inclusion attack via reading filecomplying
Potential user input in HTTP request may allow SSRF attackcomplying
Potential user input in HTTP request may allow SSRF attackcomplying
Simple DOS attack possible due to http.server misconfigurationcomplying
User data used in Puppeteer methods can result in SSRFcomplying
User data used in Puppeteer methods can result in SSRFcomplying

Prevents remote code execution

ControlStatus
A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input.complying
Arbitrary Code Execution via Unsafe Clojure Deserializationcomplying
Enabling NodeJS in Electron can lead to remote code executioncomplying
Enabling NodeJS in Electron can lead to remote code executioncomplying
Flask app debug mode may allow remote code executioncomplying
Handling potential user-controlled inputs into java.lang.Runtime calls can lead to command injection.complying
Insecure Deserialization in torch.load() leading to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
LDAP query injection may lead to data exposurecomplying
LDAP query injection may lead to data exposurecomplying
LDAP query injection may lead to data exposurecomplying
Object deserialization can lead to remote code executioncomplying
Object deserialization can lead to remote code executioncomplying
Object deserialization can lead to remote code executioncomplying
Object deserialization can lead to remote code executioncomplying
POSIX function called with arguments that trigger Buffer Overflowcomplying
Possible command injection via exec()-type functionscomplying
Possible command injection via Process.Startcomplying
Possible command injection via Process.Startcomplying
Possible command injection via shell scriptcomplying
Possible command injection via user-controlled input to clojure.java.shell/shcomplying
Potential command injection via Command APIcomplying
Potential command injection via Process.runcomplying
Potential file inclusion attack via reading filecomplying
Remote Code Execution possible via eval()-type functionscomplying
Remote Code Execution possible via eval()-type functionscomplying
Remote Code Execution possible via eval()-type functionscomplying
Ruby reflection via constantize may lead to remote code executioncomplying
Ruby reflection via send may lead to RCEcomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe exec usage can lead to remote code executioncomplying
Unsafe exec usage can lead to remote code executioncomplying
Unsafe exec usage can lead to remote code executioncomplying
Unsafe subprocess usage can lead to remote code executioncomplying
Unsafe yaml load can lead to remote code executioncomplying
Unsafe yaml load can lead to remote code executioncomplying
Unsafe yaml load can lead to remote code executioncomplying
Usage of HttpInvokerServiceExporter can lead to remote code executioncomplying
Use of vulnerable ingress-nginx controllercomplying
Use of vulnerable ingress-nginx controllercomplying
Using backticks in PHP can lead to remote code executioncomplying
Using Marshal can lead to remote code executioncomplying
Using Pickle can lead to remote code executioncomplying
Using unserialize can lead to remote code executioncomplying
XXE attack can lead to remote code executioncomplying

Prevents XSS attacks

ControlStatus
Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilitiescomplying
Directly writing unsanitized input to http.ResponseWriter can lead to XSScomplying
Disabling JSON HTML Escaping in ActiveSupport may lead to XSScomplying
DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinkscomplying
HttpServletResponse output can be used for XSS attackscomplying
Improper sanitization in dynamic attribute bindings can lead to XSS attackscomplying
Input validation disabled in controllercomplying
Jinja2 template config can lead to XSS attackscomplying
Potential Cross Site Scripting (XSS) via window.location.hrefcomplying
Potential XSS due to enabling bypassSecurityTrustUrlcomplying
Potential XSS via MarkupStr(...) in Razor template may lead to XSScomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input in EJS template can lead to XSS attackscomplying
Rendering unescaped input in handlebar/mustache template can lead to XSS attackscomplying
Rendering unescaped input in HTML template can lead to XSS attackscomplying
Unsanitized user input in jQuery DOM handling methods detectedcomplying
Unsanitized user input leads to cross-site scripting (XSS)complying
Using dangerouslySetInnerHTML in React can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using raw on potential user input can leads to XSScomplying
Using v-html in Vue templates can lead to XSS attackscomplying

Securely stores files

ControlStatus
Firewall rules restrict public ingress to port 3020complying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying
Storage buckets have uniform bucket-level access enabledcomplying

Properly manages the identity of cloud users

ControlStatus
Firewall rules restrict public ingress to port 636complying
No user has both the Service Account User and Service Account Admin rolecomplying
Service accounts have strict access permissionscomplying
Users are logging in securelycomplying
Users are only allowed to use corporate emailscomplying

Has proper access controls for cloud resources

ControlStatus
Access Approval is enabled for the projectcomplying
API key restricts usage to certain APIscomplying
API key restricts usage to certain clientscomplying
Compute instances have OS Login enabledcomplying
Compute instances have serial port access disabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
Storage buckets have uniform bucket-level access enabledcomplying
VM instances have strict access permissionscomplying

Prevents public access to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Compute instances do not have public IP addressescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
KMS keys have strict access permissionscomplying
Kubernetes master endpoint is not publicly availablecomplying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Enabled security logging for cloud instances

ControlStatus
Alerting policies have a notification channel configuredcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Does not have any issues outside of their SLA

ControlStatus
No critical issues outside of SLAcomplying
No high severity issues outside of SLAcomplying
No low severity issues outside of SLAcomplying
No medium severity issues outside of SLAcomplying

Has connected a cloud environment

ControlStatus
Has connected cloud environmentcomplying

Has enabled threat detection

ControlStatus
Alerting policies have a notification channel configuredcomplying

Receives security alerts in real time

ControlStatus
Security notifications are enabledcomplying

Prevents ssh access to cloud resources from anywhere

ControlStatus
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying

Prevents unauthorized network access

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Kubernetes master endpoint is not publicly availablecomplying

Has checks in place for enforcing permissions

ControlStatus
Access Approval is enabled for the projectcomplying
Compute instances have OS Login enabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
VM instances have strict access permissionscomplying

Has enabled threat detection

ControlStatus
Alerting policies have a notification channel configuredcomplying

Prevents unwanted write operations to filesystems

ControlStatus
Container processes can gain more privileges than its parentcomplying
Container running as root can allow attacker to escalate attackscomplying
Default Kubernetes settings allow containers to eavesdrop on traffic.complying
Default security context allows pods to access host system.complying
Docker container configured to run as user with root privilegescomplying
Docker container runs as default root usercomplying
Filesystem for docker container should not be writeablecomplying
Privileged container can allow attackers to escalate attackscomplying

Uses Lockfiles to pin code dependencies

ControlStatus
Usage of lockfiles in code repositoriescomplying

Prevents public access to cloud resources

ControlStatus
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
No firewall rule allows MongoDB access from the internetcomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying

Enforces encryption of data in transit

ControlStatus
Cloud functions require HTTPS invocationscomplying
Cloud SQL instance requires SSL connectionscomplying
DNSSEC is enabled for all managed zonescomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
Load Balancers only accept HTTPS connectionscomplying

Requires MFA for cloud users

ControlStatus
Users are logging in securelycomplying

Does not have any issues outside of their SLA

ControlStatus
No critical SAST issues outside of SLAcomplying
No high severity SAST issues outside of SLAcomplying
No low severity SAST issues outside of SLAcomplying
No medium severity SAST issues outside of SLAcomplying

Has connected a cloud environment

ControlStatus
A cloud environment is connectedcomplying

Has connected a code repository

ControlStatus
Code repositories are connectedcomplying

Uses a CI integration

ControlStatus
The Aikido CI integration is enabledcomplying

Has separate production and test environments

ControlStatus
No cloud environment used for mixed purposes (eg production and staging)complying

Enforces safe SSL protocol usage

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Elasticsearch domain might have outdated TLS versioncomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
KMS keys have key rotation enabledcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Virtual Machines have confidential computing enabledcomplying
Weak SSL/TLS protocols usedcomplying

Uses secure cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying

Uses up-to-date cryptographic libraries

ControlStatus
Hashes should include an unpredictable saltcomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using deprecated cryptographic librarycomplying

Enforces secure access for cloud users

ControlStatus
Cloud SQL instances have deletion protection enabledcomplying
VM instances have deletion protection enabledcomplying

Has proper access controls for cloud resources

ControlStatus
No user has both the Service Account User and Service Account Admin rolecomplying
Service accounts have strict access permissionscomplying

Prevents the exposure of sensitive data

ControlStatus
Currently there are no exposed secretscomplying

Requires MFA for cloud users

ControlStatus
Users are logging in securelycomplying