Back to Security and compliance
SOC 2
523 complying controls out of 525
Last synchronised :
The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.
Assessment, type and control names are those of the original frameworks.
Request the security audit report
Configured monitoring for code repositories
| Control | Status |
|---|---|
| Configured monitoring for all code repositories | complying |
Configured monitoring for container images
| Control | Status |
|---|---|
| Configured monitoring for all container images | complying |
Configured monitoring for domains
| Control | Status |
|---|---|
| Configured monitoring for domains | complying |
Does not have any severe open source dependency issues
| Control | Status |
|---|---|
| No active critical open source dependency issues | complying |
| No active high severity open source dependency issues | complying |
Does not have any severe surface monitoring issues
| Control | Status |
|---|---|
| No active critical surface monitoring issues | complying |
| No active high severity surface monitoring issues | complying |
Properly manages the identity of cloud users
| Control | Status |
|---|---|
| Firewall rules restrict public ingress to port 636 | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Service accounts have strict access permissions | complying |
| Users are logging in securely | complying |
| Users are only allowed to use corporate emails | complying |
Threat detection is enabled
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Applies the least privilege principle for cloud resource
| Control | Status |
|---|---|
| Access Approval is enabled for the project | complying |
| Compute instances have OS Login enabled | complying |
| GKE clusters have the Kubernetes Dashboard disabled | complying |
| Kubernetes pods are isolated | complying |
| No instance uses the default service account | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Project-wide SSH keys are blocked | complying |
| Service accounts have strict access permissions | complying |
| VM instances have strict access permissions | complying |
Applies the least privilege principle to cloud resources
| Control | Status |
|---|---|
| Access to BigQuery datasets are restricted | complying |
| Cloud functions are not publicly accessible | complying |
| Cloud functions have strict access policies | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| KMS keys have strict access permissions | complying |
| Kubernetes master endpoint is not publicly available | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
Enabled security logging for cloud instances
| Control | Status |
|---|---|
| Audit Configuration logging is enabled | complying |
| Logging and alerts are enabled for Project Ownership assignments | complying |
| Storage Permissions logging is enabled | complying |
| VPC Firewall has Rule logging enabled | complying |
Requires MFA for cloud users
| Control | Status |
|---|---|
| Users are logging in securely | complying |
Threat detection is enabled
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Applies the least privilege principle for cloud resource
| Control | Status |
|---|---|
| Access Approval is enabled for the project | complying |
| Compute instances have OS Login enabled | complying |
| GKE clusters have the Kubernetes Dashboard disabled | complying |
| Kubernetes pods are isolated | complying |
| Load Balancers only accept HTTPS connections | complying |
| No instance uses the default service account | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Project-wide SSH keys are blocked | complying |
| Service accounts have strict access permissions | complying |
| VM instances have strict access permissions | complying |
Does not have any severe infrastructure as code issues
| Control | Status |
|---|---|
| No active critical infrastructure as code issues | complying |
| No active high severity infrastructure as code issues | complying |
Has deletion protection for cloud resources
| Control | Status |
|---|---|
| Cloud SQL instances have deletion protection enabled | complying |
| VM instances have deletion protection enabled | complying |
Properly manages the identity of cloud users
| Control | Status |
|---|---|
| Firewall rules restrict public ingress to port 636 | complying |
| Users are logging in securely | complying |
| Users are only allowed to use corporate emails | complying |
Has separate production and test environments
| Control | Status |
|---|---|
| No cloud environment used for mixed purposes (eg production and staging) | complying |
Prevents unauthorized access via ssh
| Control | Status |
|---|---|
| AWS EKS Node groups have implicit SSH access from any IP | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules allow RDP access from any public IP | complying |
| Firewall rules allow SSH from any public IP | complying |
| Firewall rules allow SSH from any public IP | complying |
| Firewall rules allow unrestricted SSH access | complying |
Prevents unauthorized public access to database
| Control | Status |
|---|---|
| BigQuery table is anonymously or publicly accessible | complying |
| Firewall rules restrict public ingress to port 1433 | complying |
| Firewall rules restrict public ingress to port 1434 | complying |
| Firewall rules restrict public ingress to port 2383 | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 27017 | complying |
| Firewall rules restrict public ingress to port 27018 | complying |
| Firewall rules restrict public ingress to port 27019 | complying |
| Firewall rules restrict public ingress to port 3306 | complying |
| Firewall rules restrict public ingress to port 61621 | complying |
| Firewall rules restrict public ingress to port 7001 | complying |
| Firewall rules restrict public ingress to port 9200 | complying |
| Firewall rules restrict public ingress to port 9300 | complying |
| No firewall rule allows MongoDB access from the internet | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
Prevents unauthorized public access to file storage
| Control | Status |
|---|---|
| Azure Storage Account allow public access | complying |
| Azure Storage blobs do not restrict public access for nested items | complying |
| Firewall rules restrict public ingress to port 3020 | complying |
| S3 bucket grants public access to all contents | complying |
| S3 Buckets should have block public access globally | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
Has secured load balancer access points
| Control | Status |
|---|---|
| Users are logging in securely | complying |
Has secured load balancer access points
| Control | Status |
|---|---|
| AWS EKS Node groups have implicit SSH access from any IP | complying |
| Compute instances have OS Login enabled | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules allow RDP access from any public IP | complying |
| Firewall rules allow SSH from any public IP | complying |
| Firewall rules allow SSH from any public IP | complying |
| Firewall rules allow unrestricted SSH access | complying |
| Load Balancers only accept HTTPS connections | complying |
| Project-wide SSH keys are blocked | complying |
Applies the least privilege principle to cloud resources
| Control | Status |
|---|---|
| Access to BigQuery datasets are restricted | complying |
| Cloud functions are not publicly accessible | complying |
| Cloud functions have strict access policies | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| KMS keys have strict access permissions | complying |
| Kubernetes master endpoint is not publicly available | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
Encrypts data at rest
| Control | Status |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | complying |
| API Gateway REST API caching is unencrypted | complying |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | complying |
| Docker image repository not encrypted at rest | complying |
| Elasticsearch domain is not encrypted at rest | complying |
| Ensure all data stored in the RDS is securely encrypted at rest | complying |
| KMS keys have key rotation enabled | complying |
| SNS topics are not encrypted at rest | complying |
| SQS queue data is not encrypted | complying |
| Virtual Machines have confidential computing enabled | complying |
Enforces encryption of data in transit
| Control | Status |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | complying |
| App does not validate SSL certificates properly | complying |
| App uses an outdated TLS protocol | complying |
| App uses an outdated TLS protocol | complying |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Accounts does not enforce latest TLS version | complying |
| Cloud functions require HTTPS invocations | complying |
| Cloud SQL db not enforcing SSL | complying |
| Cloud SQL instance requires SSL connections | complying |
| Cookie missing HttpOnly flag | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| DNSSEC is disabled | complying |
| DNSSEC is enabled for all managed zones | complying |
| Elasticsearch domain might have outdated TLS version | complying |
| Express is not emitting security headers | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| HTTP Client misconfigured with SSL validation disabled | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure HTTP Request detected | complying |
| Insecure TLS configuration detected | complying |
| Insecure usage of `requests` sends data over cleartext | complying |
| Insecure websocket connection sends data over cleartext | complying |
| Laravel cookies can be sent unencrypted | complying |
| Load balancer allows invalid HTTP headers | complying |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | complying |
| Load Balancers only accept HTTPS connections | complying |
| NodeJS talks to database without encryption | complying |
| NodeJS talks to database without encryption | complying |
| Outbound Ansible connections are not encrypted | complying |
| Outbound Ansible connections are not encrypted | complying |
| Server certificates are not verified during SSL/TLS connections | complying |
| Server hostnames not verified during SSL/TLS connections | complying |
| Signature validation for dnf packages is off | complying |
| SSL certificate verification turned off during requests | complying |
| SSL certificate verification turned off during requests | complying |
| Storage account does not enforce HTTPS-only traffic | complying |
| TLS Certificate Validation Disabled | complying |
| TLS Certificate Validation Disabled | complying |
| Turning off TLS verification enables man-in-the-middle attacks | complying |
| Usage of deprecated or broken encryption detected | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Weak SSL/TLS protocols used | complying |
Has measures against SQL injection attacks
| Control | Status |
|---|---|
| NoSQL injection attack possible | complying |
| NoSQL injection attack possible | complying |
| NoSQL injection attack possible | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential NoSQL injection via string-based query concatenation | complying |
| Potential SQL injection in Doctrine's QueryBuilder | complying |
| Potential SQL injection in sqlite3 via string-based query concatenation | complying |
| Potential SQL injection through JDBC via string-based query concatenation | complying |
| Potential SQL injection using sqflite execute sink | complying |
| Potential SQL injection via Drupal database functionality | complying |
| Potential SQL injection via dynamic raw query construction | complying |
| Potential SQL injection via dynamic raw query construction | complying |
| Potential SQL injection via dynamic raw query construction | complying |
| Potential SQL injection via Laravel function | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation | complying |
| Potential SQL injection via string-based query concatenation using AuraSQL framework functions | complying |
| Potential SQL injection via Yii function | complying |
| Potential SQL injection when bypassing Django ORM with extra() | complying |
| Potential SQL injection when bypassing Django ORM with RawSQL() | complying |
| Potential SQL injection when bypassing Doctrine ORM with raw query | complying |
Is protected against command injections attacks
| Control | Status |
|---|---|
| A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input. | complying |
| Possible command injection via Process.Start | complying |
| Possible command injection via Process.Start | complying |
| Possible command injection via shell script | complying |
| Possible command injection via user-controlled input to clojure.java.shell/sh | complying |
| Potential command injection via Command API | complying |
| Potential command injection via Process.run | complying |
| Use of vulnerable ingress-nginx controller | complying |
| Xpath injection attack could lead to information extraction | complying |
| Xpath injection attack could lead to information extraction | complying |
Is protected against SSRF attacks
| Control | Status |
|---|---|
| A timing attack might allow hackers to bruteforce passwords | complying |
| EC2 IAM roles vulnerable to SSRF attacks | complying |
| GCP Kubernetes engine clusters vulnerable to SSRF attacks | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| HTTP request might enable SSRF attack | complying |
| Potential file inclusion attack via reading file | complying |
| Potential file inclusion attack via reading file | complying |
| Potential file inclusion attack via reading file | complying |
| Potential user input in HTTP request may allow SSRF attack | complying |
| Potential user input in HTTP request may allow SSRF attack | complying |
| Simple DOS attack possible due to http.server misconfiguration | complying |
| User data used in Puppeteer methods can result in SSRF | complying |
| User data used in Puppeteer methods can result in SSRF | complying |
Prevents the exposure of sensitive data
| Control | Status |
|---|---|
| Currently there are no exposed secrets | complying |
Prevents XSS attacks
| Control | Status |
|---|---|
| Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilities | complying |
| Directly writing unsanitized input to http.ResponseWriter can lead to XSS | complying |
| Disabling JSON HTML Escaping in ActiveSupport may lead to XSS | complying |
| DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinks | complying |
| HttpServletResponse output can be used for XSS attacks | complying |
| Improper sanitization in dynamic attribute bindings can lead to XSS attacks | complying |
| Input validation disabled in controller | complying |
| Jinja2 template config can lead to XSS attacks | complying |
| Potential Cross Site Scripting (XSS) via window.location.href | complying |
| Potential XSS due to enabling bypassSecurityTrustUrl | complying |
| Potential XSS via MarkupStr(...) in Razor template may lead to XSS | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input can lead to XSS attacks | complying |
| Rendering unescaped input in EJS template can lead to XSS attacks | complying |
| Rendering unescaped input in handlebar/mustache template can lead to XSS attacks | complying |
| Rendering unescaped input in HTML template can lead to XSS attacks | complying |
| Unsanitized user input in jQuery DOM handling methods detected | complying |
| Unsanitized user input leads to cross-site scripting (XSS) | complying |
| Using dangerouslySetInnerHTML in React can lead to XSS attacks | complying |
| Using document write methods can lead to XSS attacks | complying |
| Using document write methods can lead to XSS attacks | complying |
| Using document write methods can lead to XSS attacks | complying |
| Using raw on potential user input can leads to XSS | complying |
| Using v-html in Vue templates can lead to XSS attacks | complying |
Requires MFA for cloud users
| Control | Status |
|---|---|
| Users are logging in securely | complying |
Threat detection is enabled
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Encrypts data at rest
| Control | Status |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | complying |
| API Gateway REST API caching is unencrypted | complying |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | complying |
| Docker image repository not encrypted at rest | complying |
| Elasticsearch domain is not encrypted at rest | complying |
| Ensure all data stored in the RDS is securely encrypted at rest | complying |
| KMS keys have key rotation enabled | complying |
| SNS topics are not encrypted at rest | complying |
| Virtual Machines have confidential computing enabled | complying |
Enforces encryption of data in transit
| Control | Status |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | complying |
| App does not validate SSL certificates properly | complying |
| App uses an outdated TLS protocol | complying |
| App uses an outdated TLS protocol | complying |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Network Security Rule allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Account allows plaintext HTTP connections | complying |
| Azure Storage Accounts does not enforce latest TLS version | complying |
| Cloud functions require HTTPS invocations | complying |
| Cloud SQL db not enforcing SSL | complying |
| Cloud SQL instance requires SSL connections | complying |
| Cookie missing HttpOnly flag | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| Deprecated SSL Protocol Usage Detected | complying |
| DNSSEC is disabled | complying |
| DNSSEC is enabled for all managed zones | complying |
| Elasticsearch domain might have outdated TLS version | complying |
| Express is not emitting security headers | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| HTTP Client misconfigured with SSL validation disabled | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure gRPC connection can lead to remote code execution | complying |
| Insecure HTTP Request detected | complying |
| Insecure TLS configuration detected | complying |
| Insecure usage of `requests` sends data over cleartext | complying |
| Insecure websocket connection sends data over cleartext | complying |
| Laravel cookies can be sent unencrypted | complying |
| Load balancer allows invalid HTTP headers | complying |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | complying |
| Load Balancers only accept HTTPS connections | complying |
| NodeJS talks to database without encryption | complying |
| NodeJS talks to database without encryption | complying |
| Outbound Ansible connections are not encrypted | complying |
| Outbound Ansible connections are not encrypted | complying |
| Server certificates are not verified during SSL/TLS connections | complying |
| Server hostnames not verified during SSL/TLS connections | complying |
| Signature validation for dnf packages is off | complying |
| SQS queue data is not encrypted | complying |
| SSL certificate verification turned off during requests | complying |
| SSL certificate verification turned off during requests | complying |
| Storage account does not enforce HTTPS-only traffic | complying |
| TLS Certificate Validation Disabled | complying |
| TLS Certificate Validation Disabled | complying |
| Turning off TLS verification enables man-in-the-middle attacks | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Using potentially unsafe FTP connections to move data | complying |
| Weak SSL/TLS protocols used | complying |
Uses up to date cryptography libraries
| Control | Status |
|---|---|
| Hashes should include an unpredictable salt | complying |
| Usage of deprecated or broken encryption detected | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Using deprecated cryptographic library | complying |
Applies the least privilege principle for cloud resource
| Control | Status |
|---|---|
| Access Approval is enabled for the project | complying |
| Access to BigQuery datasets are restricted | complying |
| API key restricts usage to certain APIs | complying |
| API key restricts usage to certain clients | complying |
| Cloud functions are not publicly accessible | complying |
| Cloud functions have strict access policies | complying |
| Compute instances have IP forwarding disabled | complying |
| Compute instances have OS Login enabled | complying |
| Compute instances have serial port access disabled | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| GKE clusters have the GKE Metadata Server enabled | complying |
| GKE clusters have the Kubernetes Dashboard disabled | complying |
| GKE node pools use dedicated service accounts | complying |
| KMS keys have strict access permissions | complying |
| Kubernetes master endpoint is not publicly available | complying |
| Kubernetes pods are isolated | complying |
| No instance uses the default service account | complying |
| No user has both the Service Account User and Service Account Admin role | complying |
| Project-wide SSH keys are blocked | complying |
| Service accounts have strict access permissions | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
| Storage buckets have uniform bucket-level access enabled | complying |
| Users are logging in securely | complying |
| VM instances have strict access permissions | complying |
MFA is enforced for cloud users
| Control | Status |
|---|---|
| Users are logging in securely | complying |
Prevents public access to cloud resources
| Control | Status |
|---|---|
| Access to BigQuery datasets are restricted | complying |
| AKS API server does not limit access by IP ranges | complying |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | complying |
| API Gateway endpoints do not require an API key or authorization | complying |
| AWS EKS Node groups have implicit SSH access from any IP | complying |
| Azure Cognitive Services allows unrestricted public network access | complying |
| Azure Cosmos DB is publicly reachable | complying |
| Azure Key Vault allows public network access | complying |
| Azure Storage Account allow public access | complying |
| Azure Storage blobs do not restrict public access for nested items | complying |
| BigQuery table is anonymously or publicly accessible | complying |
| Cloud functions are not publicly accessible | complying |
| Cloud functions have strict access policies | complying |
| Cloud Storage bucket does not enforce public access prevention | complying |
| Cloud Storage bucket does not enforce uniform bucket-level access | complying |
| Cloud Storage bucket is publicly accessible | complying |
| Compute instances do not have public IP addresses | complying |
| Dataproc cluster is anonymously or publicly accessible | complying |
| Default network exists in GCP project | complying |
| Firewall rule prevents Docker API access from anywhere | complying |
| Firewall rule prevents RDP access from anywhere | complying |
| Firewall rule prevents SSH access from anywhere | complying |
| Firewall rules allow RDP access from any public IP | complying |
| Firewall rules allow SSH from any public IP | complying |
| Firewall rules allow SSH from any public IP | complying |
| Firewall rules allow unrestricted RDP access | complying |
| Firewall rules allow unrestricted SSH access | complying |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | complying |
| Firewall rules restrict public ingress to port 11214 | complying |
| Firewall rules restrict public ingress to port 11215 | complying |
| Firewall rules restrict public ingress to port 135 | complying |
| Firewall rules restrict public ingress to port 137 | complying |
| Firewall rules restrict public ingress to port 138 | complying |
| Firewall rules restrict public ingress to port 139 | complying |
| Firewall rules restrict public ingress to port 1433 | complying |
| Firewall rules restrict public ingress to port 1434 | complying |
| Firewall rules restrict public ingress to port 23 | complying |
| Firewall rules restrict public ingress to port 2379 | complying |
| Firewall rules restrict public ingress to port 2383 | complying |
| Firewall rules restrict public ingress to port 2484 | complying |
| Firewall rules restrict public ingress to port 27017 | complying |
| Firewall rules restrict public ingress to port 27018 | complying |
| Firewall rules restrict public ingress to port 27019 | complying |
| Firewall rules restrict public ingress to port 3000 | complying |
| Firewall rules restrict public ingress to port 3020 | complying |
| Firewall rules restrict public ingress to port 3306 | complying |
| Firewall rules restrict public ingress to port 389 | complying |
| Firewall rules restrict public ingress to port 4505 | complying |
| Firewall rules restrict public ingress to port 4506 | complying |
| Firewall rules restrict public ingress to port 5500 | complying |
| Firewall rules restrict public ingress to port 5800 | complying |
| Firewall rules restrict public ingress to port 61621 | complying |
| Firewall rules restrict public ingress to port 636 | complying |
| Firewall rules restrict public ingress to port 7001 | complying |
| Firewall rules restrict public ingress to port 8000 | complying |
| Firewall rules restrict public ingress to port 9200 | complying |
| Firewall rules restrict public ingress to port 9300 | complying |
| Key Vault is publicly accessible | complying |
| KMS cryptographic key policy allows public access | complying |
| KMS keys have strict access permissions | complying |
| Kubernetes dashboard might be deployed | complying |
| Kubernetes master endpoint is not publicly available | complying |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | complying |
| No firewall rule allows access to port 1720 from the internet | complying |
| No firewall rule allows cPanel access from the internet | complying |
| No firewall rule allows etcd access from the internet | complying |
| No firewall rule allows MongoDB access from the internet | complying |
| No firewall rule allows NFS access from the internet | complying |
| No firewall rule allows Telnet access from the internet | complying |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | complying |
| Profiling endpoint automatically exposed on /debug/pprof | complying |
| Pub/Sub topic is anonymously or publicly accessible | complying |
| S3 bucket grants public access to all contents | complying |
| S3 Buckets should have block public access globally | complying |
| SQL instance root user has strict access permissions | complying |
| SQL instances do not have a public IP assigned | complying |
| SQL instances have strict access permission | complying |
| SQL Server is publicly reachable | complying |
| Storage Buckets have proper access rules | complying |
| Storage buckets have public access prevention enabled | complying |
| Vertex AI notebook instance has a public IP address | complying |
Enforces latest TLS version
| Control | Status |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | complying |
| Azure Storage Accounts does not enforce latest TLS version | complying |
| Elasticsearch domain might have outdated TLS version | complying |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | complying |
| Storage account does not enforce HTTPS-only traffic | complying |
Uses up to date cryptography libraries
| Control | Status |
|---|---|
| Hashes should include an unpredictable salt | complying |
| Usage of deprecated or broken encryption detected | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Use of broken or outdated encryption | complying |
| Using deprecated cryptographic library | complying |
Prevents container orchestration takeover
| Control | Status |
|---|---|
| AKS local admin account is still enabled | complying |
| Dangerous Impersonate permission given to ServiceAccount or node | complying |
Protects unauthorized runtime access
| Control | Status |
|---|---|
| Container processes can gain more privileges than its parent | complying |
| Container running as root can allow attacker to escalate attacks | complying |
| Default Kubernetes settings allow containers to eavesdrop on traffic. | complying |
| Default security context allows pods to access host system. | complying |
| Docker container configured to run as user with root privileges | complying |
| Docker container runs as default root user | complying |
| Filesystem for docker container should not be writeable | complying |
| Privileged container can allow attackers to escalate attacks | complying |
Aikido Malware Scanner is enabled
| Control | Status |
|---|---|
| Aikido Malware Scanner is enabled | complying |
Threat detection is enabled
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Connected code repositories
| Control | Status |
|---|---|
| Connect code repositories | complying |
Connected public facing domain
| Control | Status |
|---|---|
| Connect public facing domain | complying |
Does not have any issues outside of their SLA
| Control | Status |
|---|---|
| No issues outside of sla | complying |
Uses Lockfiles to pin code dependencies
| Control | Status |
|---|---|
| Use lockfiles in repos | complying |
Connected code repositories
| Control | Status |
|---|---|
| Connect code repositories | complying |
Threat detection is enabled
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
Configured SLAs to resolve issues
| Control | Status |
|---|---|
| Configure SLAs | complying |
Connected cloud environment
| Control | Status |
|---|---|
| Connect a cloud environment | complying |
Connected code repositories
| Control | Status |
|---|---|
| Connect code repositories | complying |
Connected public facing domain
| Control | Status |
|---|---|
| Connect public facing domain | complying |
Enabled security logging for cloud instances
| Control | Status |
|---|---|
| Alerting policies have a notification channel configured | complying |
| Amazon EKS Clusters should have control plane logging enabled | complying |
| Audit Configuration logging is enabled | complying |
| Logging and alerts are enabled for Project Ownership assignments | complying |
| Storage Permissions logging is enabled | complying |
| VPC Firewall has Rule logging enabled | complying |
Has no critical open source dependency issues
| Control | Status |
|---|---|
| There are critical open source dependency issues | complying |
Runtimes are up to date
| Control | Status |
|---|---|
| AWS MQBroker version is outdated | complying |
| GKE clusters use stable release channels with automatic upgrades | complying |
| GKE node pools have node auto-upgrade enabled | complying |
| No AKS cluster upgrade channel is chosen | complying |
Prevents the exposure of sensitive data
| Control | Status |
|---|---|
| Currently there are no exposed secrets | complying |
Tracks progress via an issue tracker
| Control | Status |
|---|---|
| Integration with issue tracker enabled | complying |
Has backups for stateful cloud resources
| Control | Status |
|---|---|
| Databases have automated backups enabled | complying |
| DynamoDB backups are off | complying |
