Back to Security and compliance

PCI DSS

372 complying controls out of 373

Last synchronised :

The counter is the number of controls our continuous monitoring platform Aikido Security reports as satisfied, out of every control it assesses for this framework. They are all listed below, one by one.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
AKS local admin account is still enabledcomplying
Compute instances have OS Login enabledcomplying
Dangerous Impersonate permission given to ServiceAccount or nodecomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
ServiceAccount or node can read all secretscomplying
VM instances have strict access permissionscomplying

Prevents unauthorized access via ssh

ControlStatus
AWS EKS Node groups have implicit SSH access from any IPcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted SSH accesscomplying

Prevents unauthorized public access to database

ControlStatus
BigQuery table is anonymously or publicly accessiblecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying

Prevents unauthorized public access to file storage

ControlStatus
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Prevents unauthorized public access to networks and instances

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Compute instances do not have public IP addressescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
Kubernetes master endpoint is not publicly availablecomplying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying
Vertex AI notebook instance has a public IP addresscomplying

Enforces connections to use the latest SSL version

ControlStatus
Cloud SQL db not enforcing SSLcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
NodeJS talks to database without encryptioncomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying

Enforces connections using secure TLS version

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Storage account does not enforce HTTPS-only trafficcomplying

Enforces the use of secure connections

ControlStatus
Cloud functions require HTTPS invocationscomplying
Load Balancers only accept HTTPS connectionscomplying

Prevents abuse of cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying

Has proper access controls for cloud resources

ControlStatus
No user has both the Service Account User and Service Account Admin rolecomplying
Service accounts have strict access permissionscomplying

Requires MFA for access to cloud resources

ControlStatus
Users are logging in securelycomplying

Encrypts data at rest

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces connections to use the latest SSL version

ControlStatus
Cloud SQL db not enforcing SSLcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
NodeJS talks to database without encryptioncomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying

Enforces connections using secure TLS version

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL instance requires SSL connectionscomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Elasticsearch domain might have outdated TLS versioncomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SQS queue data is not encryptedcomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Enforces encryption of data in transit

ControlStatus
Domain SSL Certificate Expirationcomplying
HSTS header has malformed contentcomplying
HSTS header has malformed Max-Age directivecomplying
HSTS header is defined via meta tagcomplying
HSTS header is disabledcomplying
HSTS header is malformed directivecomplying
HSTS header is missingcomplying
Multiple HSTS headers are being setcomplying
TLS not enforced with valid HSTS headercomplying

Prevents abuse of cookies

ControlStatus
Cookie missing HttpOnly flagcomplying
Laravel cookies can be sent unencryptedcomplying

No malware issues

ControlStatus
No open malware issuescomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Configured monitoring for code repositories

ControlStatus
Configured monitoring for all code repositoriescomplying

Connected public facing domain

ControlStatus
Configured monitoring for domainscomplying

Configured SLAs to resolve issues

ControlStatus
Has configured SLA settings for critical issuescomplying

App scanned for SQL injection attack

ControlStatus
NoSQL injection attack possiblecomplying
NoSQL injection attack possiblecomplying
NoSQL injection attack possiblecomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential SQL injection in Doctrine's QueryBuildercomplying
Potential SQL injection in sqlite3 via string-based query concatenationcomplying
Potential SQL injection through JDBC via string-based query concatenationcomplying
Potential SQL injection using sqflite execute sinkcomplying
Potential SQL injection via Drupal database functionalitycomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via Laravel functioncomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenation using AuraSQL framework functionscomplying
Potential SQL injection via Yii functioncomplying
Potential SQL injection when bypassing Django ORM with extra()complying
Potential SQL injection when bypassing Django ORM with RawSQL()complying
Potential SQL injection when bypassing Doctrine ORM with raw querycomplying

Prevents Cross Site Scripting (XSS)

ControlStatus
Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilitiescomplying
Directly writing unsanitized input to http.ResponseWriter can lead to XSScomplying
Disabling JSON HTML Escaping in ActiveSupport may lead to XSScomplying
DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinkscomplying
HttpServletResponse output can be used for XSS attackscomplying
Improper sanitization in dynamic attribute bindings can lead to XSS attackscomplying
Input validation disabled in controllercomplying
Jinja2 template config can lead to XSS attackscomplying
Potential Cross Site Scripting (XSS) via window.location.hrefcomplying
Potential XSS due to enabling bypassSecurityTrustUrlcomplying
Potential XSS via MarkupStr(...) in Razor template may lead to XSScomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input in EJS template can lead to XSS attackscomplying
Rendering unescaped input in handlebar/mustache template can lead to XSS attackscomplying
Rendering unescaped input in HTML template can lead to XSS attackscomplying
Unsanitized user input in jQuery DOM handling methods detectedcomplying
Unsanitized user input leads to cross-site scripting (XSS)complying
Using dangerouslySetInnerHTML in React can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using raw on potential user input can leads to XSScomplying
Using v-html in Vue templates can lead to XSS attackscomplying

Prevents CSRF attacks

ControlStatus
CSRF protection disabled on purposecomplying

Prevents remote code execution

ControlStatus
A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input.complying
Arbitrary Code Execution via Unsafe Clojure Deserializationcomplying
Enabling NodeJS in Electron can lead to remote code executioncomplying
Enabling NodeJS in Electron can lead to remote code executioncomplying
Flask app debug mode may allow remote code executioncomplying
Handling potential user-controlled inputs into java.lang.Runtime calls can lead to command injection.complying
Insecure Deserialization in torch.load() leading to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
LDAP query injection may lead to data exposurecomplying
LDAP query injection may lead to data exposurecomplying
LDAP query injection may lead to data exposurecomplying
Object deserialization can lead to remote code executioncomplying
Object deserialization can lead to remote code executioncomplying
Object deserialization can lead to remote code executioncomplying
Object deserialization can lead to remote code executioncomplying
POSIX function called with arguments that trigger Buffer Overflowcomplying
Possible command injection via exec()-type functionscomplying
Possible command injection via Process.Startcomplying
Possible command injection via Process.Startcomplying
Possible command injection via shell scriptcomplying
Possible command injection via user-controlled input to clojure.java.shell/shcomplying
Potential command injection via Command APIcomplying
Potential command injection via Process.runcomplying
Potential file inclusion attack via reading filecomplying
Remote Code Execution possible via eval()-type functionscomplying
Remote Code Execution possible via eval()-type functionscomplying
Remote Code Execution possible via eval()-type functionscomplying
Ruby reflection via constantize may lead to remote code executioncomplying
Ruby reflection via send may lead to RCEcomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe eval usage can lead to remote code executioncomplying
Unsafe exec usage can lead to remote code executioncomplying
Unsafe exec usage can lead to remote code executioncomplying
Unsafe exec usage can lead to remote code executioncomplying
Unsafe subprocess usage can lead to remote code executioncomplying
Unsafe yaml load can lead to remote code executioncomplying
Unsafe yaml load can lead to remote code executioncomplying
Unsafe yaml load can lead to remote code executioncomplying
Usage of HttpInvokerServiceExporter can lead to remote code executioncomplying
Use of vulnerable ingress-nginx controllercomplying
Use of vulnerable ingress-nginx controllercomplying
Using backticks in PHP can lead to remote code executioncomplying
Using Marshal can lead to remote code executioncomplying
Using Pickle can lead to remote code executioncomplying
Using unserialize can lead to remote code executioncomplying
XXE attack can lead to remote code executioncomplying

Applies the least privilege principle for cloud users

ControlStatus
Users are only allowed to use corporate emailscomplying

Requires MFA for access to cloud resources

ControlStatus
Users are logging in securelycomplying

Applies the least privilege principle for cloud resource

ControlStatus
No user has both the Service Account User and Service Account Admin rolecomplying
Service accounts have strict access permissionscomplying
Users are logging in securelycomplying

Prevents unauthorized access via ssh

ControlStatus
AWS EKS Node groups have implicit SSH access from any IPcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted SSH accesscomplying

Prevents unauthorized public access to database

ControlStatus
BigQuery table is anonymously or publicly accessiblecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying

Prevents unauthorized public access to file storage

ControlStatus
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Prevents unauthorized public access to networks and instances

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Compute instances do not have public IP addressescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
Kubernetes master endpoint is not publicly availablecomplying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying
Vertex AI notebook instance has a public IP addresscomplying

Requires MFA for access to cloud resources

ControlStatus
Users are logging in securelycomplying

Enabled security logging for cloud instances

ControlStatus
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Has backups for stateful cloud resources

ControlStatus
Databases have automated backups enabledcomplying

Configured SLAs to resolve issues

ControlStatus
Configured SLAs to resolve issuescomplying

Has connected a cloud environment

ControlStatus
Configured monitoring for cloud environmentcomplying

Receives security alerts in real time

ControlStatus
Security notifications are enabledcomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Configured monitoring for code repositories

ControlStatus
Configured monitoring for all code repositoriescomplying

Has connected a cloud environment

ControlStatus
A cloud environment is connectedcomplying

Connected public facing domain

ControlStatus
Configured monitoring for domainscomplying