Back to Security and compliance

NIS2

148 complying controls out of 148

Last synchronised :

The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
Compute instances have OS Login enabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
VM instances have strict access permissionscomplying

Applies the least privilege principle for cloud users

ControlStatus
Firewall rules restrict public ingress to port 636complying
Users are logging in securelycomplying
Users are only allowed to use corporate emailscomplying

Applies the least privilege principle to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
KMS keys have strict access permissionscomplying
Kubernetes master endpoint is not publicly availablecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Has backups for stateful cloud resources

ControlStatus
Databases have automated backups enabledcomplying

Configured SLAs to resolve issues

ControlStatus
Configure SLAscomplying

Tracks progress via an issue tracker

ControlStatus
Integration with issue tracker enabledcomplying

Configured monitoring for code repositories

ControlStatus
Configured monitoring for all code repositoriescomplying

Configured monitoring for container images

ControlStatus
Configured monitoring for cloud environmentcomplying

Configured monitoring for public facing domains

ControlStatus
Configured monitoring for public facing domainscomplying

Has configured exposure for repositories

ControlStatus
Has configured exposure for resourcescomplying

Has measurements against unauthorized network access

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Kubernetes master endpoint is not publicly availablecomplying

Has separate production and test environments

ControlStatus
No cloud environment used for mixed purposes (eg production and staging)complying

Uses firewalls

ControlStatus
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying

No issues outside of sla

ControlStatus
No issues outside of slacomplying

Uses Lockfiles to pin code dependencies

ControlStatus
Use lockfiles in reposcomplying

Enforces safe SSL protocol usage

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Elasticsearch domain might have outdated TLS versioncomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
KMS keys have key rotation enabledcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Virtual Machines have confidential computing enabledcomplying
Weak SSL/TLS protocols usedcomplying

Uses secure cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying

Uses up-to-date cryptographic libraries

ControlStatus
Hashes should include an unpredictable saltcomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using deprecated cryptographic librarycomplying

Requires MFA for cloud users

ControlStatus
Users are logging in securelycomplying