Back to Security and compliance
ISO 27001:2022
455 complying controls out of 455
Last synchronised :
The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.
Assessment, type and control names are those of the original frameworks.
Request the security audit report
Applies the least privilege principle for cloud resource
| Control | Status |
|---|---|
| Access Approval is enabled for the project | complying |
| Compute instances have OS Login enabled | complying |
| GKE clusters have the Kubernetes Dashboard disabled | complying |
| Kubernetes pods are isolated | complying |
| No instance uses the default service account | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Project-wide SSH keys are blocked | complying |
| Service accounts have strict access permissions | complying |
| VM instances have strict access permissions | complying |
Applies the least privilege principle for cloud users
| Control | Status |
|---|---|
| Firewall rules restrict public ingress to port 636 | complying |
| Users are logging in securely | complying |
| Users are only allowed to use corporate emails | complying |
Applies the least privilege principle to cloud resources
| Control | Status |
|---|---|
| Access to BigQuery datasets are restricted | complying |
| Cloud functions are not publicly accessible | complying |
| Cloud functions have strict access policies | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| KMS keys have strict access permissions | complying |
| Kubernetes master endpoint is not publicly available | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
Prevents the exposure of sensitive data
| Control | Status |
|---|---|
| Currently there are no exposed secrets | complying |
Has backups for stateful cloud resources
| Control | Status |
|---|---|
| Databases have automated backups enabled | complying |
Uses load balancers correctly
| Control | Status |
|---|---|
| Load Balancers only accept HTTPS connections | complying |
Tracks progress via an issue tracker
| Control | Status |
|---|---|
| Integration with issue tracker enabled | complying |
Enabled security logging for cloud instances
| Control | Status |
|---|---|
| Audit Configuration logging is enabled | complying |
| Logging and alerts are enabled for Project Ownership assignments | complying |
| Storage Permissions logging is enabled | complying |
| VPC Firewall has Rule logging enabled | complying |
Has enabled threat detection
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Runs cloud instances on up-to-date versions
| Control | Status |
|---|---|
| GKE clusters use stable release channels with automatic upgrades | complying |
| GKE node pools have node auto-upgrade enabled | complying |
Uses Lockfiles to pin code dependencies
| Control | Status |
|---|---|
| Usage of lockfiles in code repositories | complying |
Encrypts data at rest
| Control | Status |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | complying |
| API Gateway REST API caching is unencrypted | complying |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | complying |
| Docker image repository not encrypted at rest | complying |
| Elasticsearch domain is not encrypted at rest | complying |
| Ensure all data stored in the RDS is securely encrypted at rest | complying |
| KMS keys have key rotation enabled | complying |
| SNS topics are not encrypted at rest | complying |
| SQS queue data is not encrypted | complying |
| Virtual Machines have confidential computing enabled | complying |
Enforces encryption of data in transit
| Control | Status |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | complying |
| App does not validate SSL certificates properly | complying |
| App uses an outdated TLS protocol | complying |
| App uses an outdated TLS protocol | complying |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Accounts does not enforce latest TLS version | complying |
| Cloud functions require HTTPS invocations | complying |
| Cloud SQL db not enforcing SSL | complying |
| Cloud SQL instance requires SSL connections | complying |
| Cookie missing HttpOnly flag | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| DNSSEC is disabled | complying |
| DNSSEC is enabled for all managed zones | complying |
| Elasticsearch domain might have outdated TLS version | complying |
| Express is not emitting security headers | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| HTTP Client misconfigured with SSL validation disabled | complying |
| Insecure HTTP Request detected | complying |
| Insecure TLS configuration detected | complying |
| Insecure usage of `requests` sends data over cleartext | complying |
| Insecure websocket connection sends data over cleartext | complying |
| Laravel cookies can be sent unencrypted | complying |
| Load balancer allows invalid HTTP headers | complying |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | complying |
| Load Balancers only accept HTTPS connections | complying |
| NodeJS talks to database without encryption | complying |
| NodeJS talks to database without encryption | complying |
| Outbound Ansible connections are not encrypted | complying |
| Outbound Ansible connections are not encrypted | complying |
| Server certificates are not verified during SSL/TLS connections | complying |
| Server hostnames not verified during SSL/TLS connections | complying |
| Signature validation for dnf packages is off | complying |
| SSL certificate verification turned off during requests | complying |
| SSL certificate verification turned off during requests | complying |
| Storage account does not enforce HTTPS-only traffic | complying |
| TLS Certificate Validation Disabled | complying |
| TLS Certificate Validation Disabled | complying |
| Turning off TLS verification enables man-in-the-middle attacks | complying |
| Usage of deprecated or broken encryption detected | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Weak SSL/TLS protocols used | complying |
Has measures against SQL injection attacks
| Control | Status |
|---|---|
| NoSQL injection attack possible | complying |
| NoSQL injection attack possible | complying |
| NoSQL injection attack possible | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential SQL injection in Doctrine's QueryBuilder | complying |
| Potential SQL injection in sqlite3 via string-based query concatenation | complying |
| Potential SQL injection through JDBC via string-based query concatenation | complying |
| Potential SQL injection using sqflite execute sink | complying |
| Potential SQL injection via Drupal database functionality | complying |
| Potential SQL injection via dynamic raw query construction | complying |
| Potential SQL injection via dynamic raw query construction | complying |
| Potential SQL injection via dynamic raw query construction | complying |
| Potential SQL injection via Laravel function | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation using AuraSQL framework functions | complying |
| Potential SQL injection via Yii function | complying |
| Potential SQL injection when bypassing Django ORM with extra() | complying |
| Potential SQL injection when bypassing Django ORM with RawSQL() | complying |
| Potential SQL injection when bypassing Doctrine ORM with raw query | complying |
Is protected against SSRF attacks
| Control | Status |
|---|---|
| A timing attack might allow hackers to bruteforce passwords | complying |
| EC2 IAM roles vulnerable to SSRF attacks | complying |
| GCP Kubernetes engine clusters vulnerable to SSRF attacks | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| Potential file inclusion attack via reading file | complying |
| Potential file inclusion attack via reading file | complying |
| Potential user input in HTTP request may allow SSRF attack | complying |
| Potential user input in HTTP request may allow SSRF attack | complying |
| Simple DOS attack possible due to http.server misconfiguration | complying |
| User data used in Puppeteer methods can result in SSRF | complying |
| User data used in Puppeteer methods can result in SSRF | complying |
Prevents remote code execution
| Control | Status |
|---|---|
| A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input. | complying |
| Arbitrary Code Execution via Unsafe Clojure Deserialization | complying |
| Enabling NodeJS in Electron can lead to remote code execution | complying |
| Enabling NodeJS in Electron can lead to remote code execution | complying |
| Flask app debug mode may allow remote code execution | complying |
| Handling potential user-controlled inputs into java.lang.Runtime calls can lead to command injection. | complying |
| Insecure Deserialization in torch.load() leading to remote code execution | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| LDAP query injection may lead to data exposure | complying |
| LDAP query injection may lead to data exposure | complying |
| LDAP query injection may lead to data exposure | complying |
| Object deserialization can lead to remote code execution | complying |
| Object deserialization can lead to remote code execution | complying |
| Object deserialization can lead to remote code execution | complying |
| Object deserialization can lead to remote code execution | complying |
| POSIX function called with arguments that trigger Buffer Overflow | complying |
| Possible command injection via exec()-type functions | complying |
| Possible command injection via Process.Start | complying |
| Possible command injection via Process.Start | complying |
| Possible command injection via shell script | complying |
| Possible command injection via user-controlled input to clojure.java.shell/sh | complying |
| Potential command injection via Command API | complying |
| Potential command injection via Process.run | complying |
| Potential file inclusion attack via reading file | complying |
| Remote Code Execution possible via eval()-type functions | complying |
| Remote Code Execution possible via eval()-type functions | complying |
| Remote Code Execution possible via eval()-type functions | complying |
| Ruby reflection via constantize may lead to remote code execution | complying |
| Ruby reflection via send may lead to RCE | complying |
| Unsafe eval usage can lead to remote code execution | complying |
| Unsafe eval usage can lead to remote code execution | complying |
| Unsafe eval usage can lead to remote code execution | complying |
| Unsafe eval usage can lead to remote code execution | complying |
| Unsafe exec usage can lead to remote code execution | complying |
| Unsafe exec usage can lead to remote code execution | complying |
| Unsafe exec usage can lead to remote code execution | complying |
| Unsafe subprocess usage can lead to remote code execution | complying |
| Unsafe yaml load can lead to remote code execution | complying |
| Unsafe yaml load can lead to remote code execution | complying |
| Unsafe yaml load can lead to remote code execution | complying |
| Usage of HttpInvokerServiceExporter can lead to remote code execution | complying |
| Use of vulnerable ingress-nginx controller | complying |
| Use of vulnerable ingress-nginx controller | complying |
| Using backticks in PHP can lead to remote code execution | complying |
| Using Marshal can lead to remote code execution | complying |
| Using Pickle can lead to remote code execution | complying |
| Using unserialize can lead to remote code execution | complying |
| XXE attack can lead to remote code execution | complying |
Prevents XSS attacks
| Control | Status |
|---|---|
| Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilities | complying |
| Directly writing unsanitized input to http.ResponseWriter can lead to XSS | complying |
| Disabling JSON HTML Escaping in ActiveSupport may lead to XSS | complying |
| DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinks | complying |
| HttpServletResponse output can be used for XSS attacks | complying |
| Improper sanitization in dynamic attribute bindings can lead to XSS attacks | complying |
| Input validation disabled in controller | complying |
| Jinja2 template config can lead to XSS attacks | complying |
| Potential Cross Site Scripting (XSS) via window.location.href | complying |
| Potential XSS due to enabling bypassSecurityTrustUrl | complying |
| Potential XSS via MarkupStr(...) in Razor template may lead to XSS | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input in EJS template can lead to XSS attacks | complying |
| Rendering unescaped input in handlebar/mustache template can lead to XSS attacks | complying |
| Rendering unescaped input in HTML template can lead to XSS attacks | complying |
| Unsanitized user input in jQuery DOM handling methods detected | complying |
| Unsanitized user input leads to cross-site scripting (XSS) | complying |
| Using dangerouslySetInnerHTML in React can lead to XSS attacks | complying |
| Using document write methods can lead to XSS attacks | complying |
| Using document write methods can lead to XSS attacks | complying |
| Using document write methods can lead to XSS attacks | complying |
| Using raw on potential user input can leads to XSS | complying |
| Using v-html in Vue templates can lead to XSS attacks | complying |
Securely stores files
| Control | Status |
|---|---|
| Firewall rules restrict public ingress to port 3020 | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
| Storage buckets have uniform bucket-level access enabled | complying |
Properly manages the identity of cloud users
| Control | Status |
|---|---|
| Firewall rules restrict public ingress to port 636 | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Service accounts have strict access permissions | complying |
| Users are logging in securely | complying |
| Users are only allowed to use corporate emails | complying |
Has proper access controls for cloud resources
| Control | Status |
|---|---|
| Access Approval is enabled for the project | complying |
| API key restricts usage to certain APIs | complying |
| API key restricts usage to certain clients | complying |
| Compute instances have OS Login enabled | complying |
| Compute instances have serial port access disabled | complying |
| GKE clusters have the Kubernetes Dashboard disabled | complying |
| Kubernetes pods are isolated | complying |
| No instance uses the default service account | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Project-wide SSH keys are blocked | complying |
| Service accounts have strict access permissions | complying |
| Storage buckets have uniform bucket-level access enabled | complying |
| VM instances have strict access permissions | complying |
Prevents public access to cloud resources
| Control | Status |
|---|---|
| Access to BigQuery datasets are restricted | complying |
| Cloud functions are not publicly accessible | complying |
| Cloud functions have strict access policies | complying |
| Compute instances do not have public IP addresses | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 11214 | complying |
| Firewall rules restrict public ingress to port 11215 | complying |
| Firewall rules restrict public ingress to port 135 | complying |
| Firewall rules restrict public ingress to port 137 | complying |
| Firewall rules restrict public ingress to port 138 | complying |
| Firewall rules restrict public ingress to port 139 | complying |
| Firewall rules restrict public ingress to port 1433 | complying |
| Firewall rules restrict public ingress to port 1434 | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 2383 | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 27017 | complying |
| Firewall rules restrict public ingress to port 27018 | complying |
| Firewall rules restrict public ingress to port 27019 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 3020 | complying |
| Firewall rules restrict public ingress to port 3306 | complying |
| Firewall rules restrict public ingress to port 389 | complying |
| Firewall rules restrict public ingress to port 4505 | complying |
| Firewall rules restrict public ingress to port 4506 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| Firewall rules restrict public ingress to port 61621 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| Firewall rules restrict public ingress to port 7001 | complying |
| Firewall rules restrict public ingress to port 8000 | complying |
| Firewall rules restrict public ingress to port 9200 | complying |
| Firewall rules restrict public ingress to port 9300 | complying |
| KMS keys have strict access permissions | complying |
| Kubernetes master endpoint is not publicly available | complying |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | complying |
| No firewall rule allows access to port 1720 from the internet | complying |
| No firewall rule allows cPanel access from the internet | complying |
| No firewall rule allows etcd access from the internet | complying |
| No firewall rule allows MongoDB access from the internet | complying |
| No firewall rule allows NFS access from the internet | complying |
| No firewall rule allows Telnet access from the internet | complying |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
Enabled security logging for cloud instances
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
| Audit Configuration logging is enabled | complying |
| Logging and alerts are enabled for Project Ownership assignments | complying |
| Storage Permissions logging is enabled | complying |
| VPC Firewall has Rule logging enabled | complying |
Does not have any issues outside of their SLA
| Control | Status |
|---|---|
| No critical issues outside of SLA | complying |
| No high severity issues outside of SLA | complying |
| No low severity issues outside of SLA | complying |
| No medium severity issues outside of SLA | complying |
Has connected a cloud environment
| Control | Status |
|---|---|
| Has connected cloud environment | complying |
Has enabled threat detection
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Receives security alerts in real time
| Control | Status |
|---|---|
| Security notifications are enabled | complying |
Prevents ssh access to cloud resources from anywhere
| Control | Status |
|---|---|
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
Prevents unauthorized network access
| Control | Status |
|---|---|
| Access to BigQuery datasets are restricted | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| Kubernetes master endpoint is not publicly available | complying |
Has checks in place for enforcing permissions
| Control | Status |
|---|---|
| Access Approval is enabled for the project | complying |
| Compute instances have OS Login enabled | complying |
| GKE clusters have the Kubernetes Dashboard disabled | complying |
| Kubernetes pods are isolated | complying |
| No instance uses the default service account | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Project-wide SSH keys are blocked | complying |
| Service accounts have strict access permissions | complying |
| VM instances have strict access permissions | complying |
Has enabled threat detection
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Prevents unwanted write operations to filesystems
| Control | Status |
|---|---|
| Container processes can gain more privileges than its parent | complying |
| Container running as root can allow attacker to escalate attacks | complying |
| Default Kubernetes settings allow containers to eavesdrop on traffic. | complying |
| Default security context allows pods to access host system. | complying |
| Docker container configured to run as user with root privileges | complying |
| Docker container runs as default root user | complying |
| Filesystem for docker container should not be writeable | complying |
| Privileged container can allow attackers to escalate attacks | complying |
Uses Lockfiles to pin code dependencies
| Control | Status |
|---|---|
| Usage of lockfiles in code repositories | complying |
Prevents public access to cloud resources
| Control | Status |
|---|---|
| Firewall rules restrict public ingress to port 1433 | complying |
| Firewall rules restrict public ingress to port 1434 | complying |
| Firewall rules restrict public ingress to port 2383 | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 27017 | complying |
| Firewall rules restrict public ingress to port 27018 | complying |
| Firewall rules restrict public ingress to port 27019 | complying |
| Firewall rules restrict public ingress to port 3306 | complying |
| Firewall rules restrict public ingress to port 61621 | complying |
| Firewall rules restrict public ingress to port 7001 | complying |
| Firewall rules restrict public ingress to port 9200 | complying |
| Firewall rules restrict public ingress to port 9300 | complying |
| No firewall rule allows MongoDB access from the internet | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
Enforces encryption of data in transit
| Control | Status |
|---|---|
| Cloud functions require HTTPS invocations | complying |
| Cloud SQL instance requires SSL connections | complying |
| DNSSEC is enabled for all managed zones | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| Load Balancers only accept HTTPS connections | complying |
Requires MFA for cloud users
| Control | Status |
|---|---|
| Users are logging in securely | complying |
Does not have any issues outside of their SLA
| Control | Status |
|---|---|
| No critical SAST issues outside of SLA | complying |
| No high severity SAST issues outside of SLA | complying |
| No low severity SAST issues outside of SLA | complying |
| No medium severity SAST issues outside of SLA | complying |
Has connected a cloud environment
| Control | Status |
|---|---|
| A cloud environment is connected | complying |
Has connected a code repository
| Control | Status |
|---|---|
| Code repositories are connected | complying |
Uses a CI integration
| Control | Status |
|---|---|
| The Aikido CI integration is enabled | complying |
Has separate production and test environments
| Control | Status |
|---|---|
| No cloud environment used for mixed purposes (eg production and staging) | complying |
Enforces safe SSL protocol usage
| Control | Status |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | complying |
| API Gateway REST API caching is unencrypted | complying |
| API Gateway stages are not using TLS 1.2 or higher | complying |
| App does not validate SSL certificates properly | complying |
| App uses an outdated TLS protocol | complying |
| App uses an outdated TLS protocol | complying |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | complying |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Accounts does not enforce latest TLS version | complying |
| Cloud functions require HTTPS invocations | complying |
| Cloud SQL db not enforcing SSL | complying |
| Cloud SQL instance requires SSL connections | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| DNSSEC is disabled | complying |
| DNSSEC is enabled for all managed zones | complying |
| Docker image repository not encrypted at rest | complying |
| Elasticsearch domain is not encrypted at rest | complying |
| Elasticsearch domain might have outdated TLS version | complying |
| Ensure all data stored in the RDS is securely encrypted at rest | complying |
| Express is not emitting security headers | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| HTTP Client misconfigured with SSL validation disabled | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure HTTP Request detected | complying |
| Insecure TLS configuration detected | complying |
| Insecure usage of `requests` sends data over cleartext | complying |
| Insecure websocket connection sends data over cleartext | complying |
| KMS keys have key rotation enabled | complying |
| Load balancer allows invalid HTTP headers | complying |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | complying |
| Load Balancers only accept HTTPS connections | complying |
| NodeJS talks to database without encryption | complying |
| NodeJS talks to database without encryption | complying |
| Outbound Ansible connections are not encrypted | complying |
| Outbound Ansible connections are not encrypted | complying |
| Server certificates are not verified during SSL/TLS connections | complying |
| Server hostnames not verified during SSL/TLS connections | complying |
| Signature validation for dnf packages is off | complying |
| SNS topics are not encrypted at rest | complying |
| SQS queue data is not encrypted | complying |
| SSL certificate verification turned off during requests | complying |
| SSL certificate verification turned off during requests | complying |
| Storage account does not enforce HTTPS-only traffic | complying |
| TLS Certificate Validation Disabled | complying |
| TLS Certificate Validation Disabled | complying |
| Turning off TLS verification enables man-in-the-middle attacks | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Virtual Machines have confidential computing enabled | complying |
| Weak SSL/TLS protocols used | complying |
Uses secure cookies
| Control | Status |
|---|---|
| Cookie missing HttpOnly flag | complying |
| Laravel cookies can be sent unencrypted | complying |
Uses up-to-date cryptographic libraries
| Control | Status |
|---|---|
| Hashes should include an unpredictable salt | complying |
| Usage of deprecated or broken encryption detected | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Using deprecated cryptographic library | complying |
Enforces secure access for cloud users
| Control | Status |
|---|---|
| Cloud SQL instances have deletion protection enabled | complying |
| VM instances have deletion protection enabled | complying |
Has proper access controls for cloud resources
| Control | Status |
|---|---|
| No user has both the Service Account User and Service Account Admin role | complying |
| Service accounts have strict access permissions | complying |
Prevents the exposure of sensitive data
| Control | Status |
|---|---|
| Currently there are no exposed secrets | complying |
Requires MFA for cloud users
| Control | Status |
|---|---|
| Users are logging in securely | complying |
