Volver a Seguridad y cumplimiento

CIS Controls v8

456 controles conformes de 456

Última sincronización :

El contador es el que produce nuestra plataforma de control continuo Aikido Security, y el detalle enumera los controles que declara satisfechos. Ambas cifras pueden diferir ligeramente.

Los nombres de las evaluaciones, los tipos y los controles son los de los marcos de referencia de origen, por lo que están en inglés.

Solicitar el informe de auditoría de seguridad

Enforces safe SSL protocol usage

ControlEstado
API Gateway stages are not using TLS 1.2 or higherconforme
App does not validate SSL certificates properlyconforme
App uses an outdated TLS protocolconforme
App uses an outdated TLS protocolconforme
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Cloud functions require HTTPS invocationsconforme
Cloud SQL db not enforcing SSLconforme
Cloud SQL instance requires SSL connectionsconforme
Cookie missing HttpOnly flagconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme
Elasticsearch domain might have outdated TLS versionconforme
Express is not emitting security headersconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
HTTP Client misconfigured with SSL validation disabledconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure HTTP Request detectedconforme
Insecure TLS configuration detectedconforme
Insecure usage of `requests` sends data over cleartextconforme
Insecure websocket connection sends data over cleartextconforme
Laravel cookies can be sent unencryptedconforme
Load balancer allows invalid HTTP headersconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Load Balancers only accept HTTPS connectionsconforme
NodeJS talks to database without encryptionconforme
NodeJS talks to database without encryptionconforme
Outbound Ansible connections are not encryptedconforme
Outbound Ansible connections are not encryptedconforme
Server certificates are not verified during SSL/TLS connectionsconforme
Server hostnames not verified during SSL/TLS connectionsconforme
Signature validation for dnf packages is offconforme
SQS queue data is not encryptedconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme
Storage account does not enforce HTTPS-only trafficconforme
TLS Certificate Validation Disabledconforme
TLS Certificate Validation Disabledconforme
Turning off TLS verification enables man-in-the-middle attacksconforme
Usage of deprecated or broken encryption detectedconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Using potentially unsafe FTP connections to move dataconforme
Using potentially unsafe FTP connections to move dataconforme
Weak SSL/TLS protocols usedconforme

Runtimes are up to date

ControlEstado
AWS MQBroker version is outdatedconforme
GKE clusters use stable release channels with automatic upgradesconforme
GKE node pools have node auto-upgrade enabledconforme
No AKS cluster upgrade channel is chosenconforme

Applies the least privilege principle for cloud resource

ControlEstado
Access Approval is enabled for the projectconforme
AKS local admin account is still enabledconforme
Compute instances have OS Login enabledconforme
Dangerous Impersonate permission given to ServiceAccount or nodeconforme
GKE clusters have the Kubernetes Dashboard disabledconforme
Kubernetes pods are isolatedconforme
No instance uses the default service accountconforme
No user has both the Service Account User and Service Account Admin roleconforme
Project-wide SSH keys are blockedconforme
Service accounts have strict access permissionsconforme
ServiceAccount or node can read all secretsconforme
VM instances have strict access permissionsconforme

Applies the least privilege principle for cloud users

ControlEstado
Firewall rules restrict public ingress to port 636conforme
Users are logging in securelyconforme
Users are only allowed to use corporate emailsconforme

Applies the least privilege principle to cloud resources

ControlEstado
Access to BigQuery datasets are restrictedconforme
AKS API server does not limit access by IP rangesconforme
Amazon EKS Clusters public endpoints should not allow traffic from any IPconforme
API Gateway endpoints do not require an API key or authorizationconforme
AWS EKS Node groups have implicit SSH access from any IPconforme
Azure Cognitive Services allows unrestricted public network accessconforme
Azure Cosmos DB is publicly reachableconforme
Azure Key Vault allows public network accessconforme
Azure Storage Account allow public accessconforme
Azure Storage blobs do not restrict public access for nested itemsconforme
BigQuery table is anonymously or publicly accessibleconforme
Cloud functions are not publicly accessibleconforme
Cloud functions have strict access policiesconforme
Cloud Storage bucket does not enforce public access preventionconforme
Cloud Storage bucket does not enforce uniform bucket-level accessconforme
Cloud Storage bucket is publicly accessibleconforme
Dataproc cluster is anonymously or publicly accessibleconforme
Default network exists in GCP projectconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules allow RDP access from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow unrestricted RDP accessconforme
Firewall rules allow unrestricted SSH accessconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Key Vault is publicly accessibleconforme
KMS cryptographic key policy allows public accessconforme
KMS keys have strict access permissionsconforme
Kubernetes dashboard might be deployedconforme
Kubernetes master endpoint is not publicly availableconforme
Profiling endpoint automatically exposed on /debug/pprofconforme
Pub/Sub topic is anonymously or publicly accessibleconforme
S3 bucket grants public access to all contentsconforme
S3 Buckets should have block public access globallyconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme
SQL Server is publicly reachableconforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme
Vertex AI notebook instance has a public IP addressconforme

Enabled security logging for cloud instances

ControlEstado
Cloud SQL instances have deletion protection enabledconforme
Deletion protection is disabled for RDS databaseconforme
VM instances have deletion protection enabledconforme

Enforces encryption of data in transit

ControlEstado
API Gateway stages are not using TLS 1.2 or higherconforme
App does not validate SSL certificates properlyconforme
App uses an outdated TLS protocolconforme
App uses an outdated TLS protocolconforme
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Cloud functions require HTTPS invocationsconforme
Cloud SQL db not enforcing SSLconforme
Cloud SQL instance requires SSL connectionsconforme
Cookie missing HttpOnly flagconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme
Domain SSL Certificate Expirationconforme
Elasticsearch domain might have outdated TLS versionconforme
Express is not emitting security headersconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
HSTS header has malformed contentconforme
HSTS header has malformed Max-Age directiveconforme
HSTS header is defined via meta tagconforme
HSTS header is disabledconforme
HSTS header is malformed directiveconforme
HSTS header is missingconforme
HTTP Client misconfigured with SSL validation disabledconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure HTTP Request detectedconforme
Insecure TLS configuration detectedconforme
Insecure usage of `requests` sends data over cleartextconforme
Insecure websocket connection sends data over cleartextconforme
Laravel cookies can be sent unencryptedconforme
Load balancer allows invalid HTTP headersconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Load Balancers only accept HTTPS connectionsconforme
Multiple HSTS headers are being setconforme
NodeJS talks to database without encryptionconforme
NodeJS talks to database without encryptionconforme
Outbound Ansible connections are not encryptedconforme
Outbound Ansible connections are not encryptedconforme
Server certificates are not verified during SSL/TLS connectionsconforme
Server hostnames not verified during SSL/TLS connectionsconforme
Signature validation for dnf packages is offconforme
SQS queue data is not encryptedconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme
Storage account does not enforce HTTPS-only trafficconforme
TLS Certificate Validation Disabledconforme
TLS Certificate Validation Disabledconforme
TLS not enforced with valid HSTS headerconforme
Turning off TLS verification enables man-in-the-middle attacksconforme
Usage of deprecated or broken encryption detectedconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Using potentially unsafe FTP connections to move dataconforme
Using potentially unsafe FTP connections to move dataconforme
Weak SSL/TLS protocols usedconforme

Encrypts data at rest

ControlEstado
Amazon EKS Clusters should have secrets encryption enabledconforme
API Gateway REST API caching is unencryptedconforme
AWS ElastiCache Redis cluster should have encryption at rest enabledconforme
Docker image repository not encrypted at restconforme
Elasticsearch domain is not encrypted at restconforme
Ensure all data stored in the RDS is securely encrypted at restconforme
KMS keys have key rotation enabledconforme
SNS topics are not encrypted at restconforme
SQS queue data is not encryptedconforme
Virtual Machines have confidential computing enabledconforme

Enabled security logging for cloud instances

ControlEstado
Amazon EKS Clusters should have control plane logging enabledconforme
Audit Configuration logging is enabledconforme
Logging and alerts are enabled for Project Ownership assignmentsconforme
Storage Permissions logging is enabledconforme
VPC Firewall has Rule logging enabledconforme

Threat detection is enabled

ControlEstado
Alerting policies have a notification channel configuredconforme

Enforces encryption of data in transit

ControlEstado
Access to BigQuery datasets are restrictedconforme
AKS API server does not limit access by IP rangesconforme
Amazon EKS Clusters public endpoints should not allow traffic from any IPconforme
Azure Cognitive Services allows unrestricted public network accessconforme
Compute instances do not have public IP addressesconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rules allow unrestricted RDP accessconforme
Firewall rules allow unrestricted SSH accessconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 11214conforme
Firewall rules restrict public ingress to port 11215conforme
Firewall rules restrict public ingress to port 135conforme
Firewall rules restrict public ingress to port 137conforme
Firewall rules restrict public ingress to port 138conforme
Firewall rules restrict public ingress to port 139conforme
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 3020conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 389conforme
Firewall rules restrict public ingress to port 4505conforme
Firewall rules restrict public ingress to port 4506conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 636conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 8000conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
Kubernetes master endpoint is not publicly availableconforme
No firewall rule allows access to Open Telemtry metrics endpoint from the internetconforme
No firewall rule allows access to port 1720 from the internetconforme
No firewall rule allows cPanel access from the internetconforme
No firewall rule allows etcd access from the internetconforme
No firewall rule allows MongoDB access from the internetconforme
No firewall rule allows NFS access from the internetconforme
No firewall rule allows Telnet access from the internetconforme
No firewall rule allows Tomcat Cluster Receiver access from the internetconforme
Vertex AI notebook instance has a public IP addressconforme

Prevents unauthorized public access to database

ControlEstado
BigQuery table is anonymously or publicly accessibleconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme

Prevents unauthorized public access to file storage

ControlEstado
Azure Storage Account allow public accessconforme
Azure Storage blobs do not restrict public access for nested itemsconforme
S3 bucket grants public access to all contentsconforme
S3 Buckets should have block public access globallyconforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme

Threat detection is enabled

ControlEstado
Alerting policies have a notification channel configuredconforme

Enforces encryption of data in transit

ControlEstado
Access to BigQuery datasets are restrictedconforme
AKS API server does not limit access by IP rangesconforme
Amazon EKS Clusters public endpoints should not allow traffic from any IPconforme
Azure Cognitive Services allows unrestricted public network accessconforme
Compute instances do not have public IP addressesconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rules allow unrestricted RDP accessconforme
Firewall rules allow unrestricted SSH accessconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 11214conforme
Firewall rules restrict public ingress to port 11215conforme
Firewall rules restrict public ingress to port 135conforme
Firewall rules restrict public ingress to port 137conforme
Firewall rules restrict public ingress to port 138conforme
Firewall rules restrict public ingress to port 139conforme
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 3020conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 389conforme
Firewall rules restrict public ingress to port 4505conforme
Firewall rules restrict public ingress to port 4506conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 636conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 8000conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
Kubernetes master endpoint is not publicly availableconforme
No firewall rule allows access to Open Telemtry metrics endpoint from the internetconforme
No firewall rule allows access to port 1720 from the internetconforme
No firewall rule allows cPanel access from the internetconforme
No firewall rule allows etcd access from the internetconforme
No firewall rule allows MongoDB access from the internetconforme
No firewall rule allows NFS access from the internetconforme
No firewall rule allows Telnet access from the internetconforme
No firewall rule allows Tomcat Cluster Receiver access from the internetconforme
Vertex AI notebook instance has a public IP addressconforme

Enforces HTTPS traffic to cloud instances

ControlEstado
Load Balancers only accept HTTPS connectionsconforme

Enforces latest TLS version

ControlEstado
API Gateway stages are not using TLS 1.2 or higherconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Elasticsearch domain might have outdated TLS versionconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Storage account does not enforce HTTPS-only trafficconforme

Uses DNSSEC extensions

ControlEstado
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme

Applies the least privilege principle for cloud resource

ControlEstado
Access Approval is enabled for the projectconforme
AKS local admin account is still enabledconforme
Compute instances have OS Login enabledconforme
Dangerous Impersonate permission given to ServiceAccount or nodeconforme
GKE clusters have the Kubernetes Dashboard disabledconforme
Kubernetes pods are isolatedconforme
No instance uses the default service accountconforme
No user has both the Service Account User and Service Account Admin roleconforme
Project-wide SSH keys are blockedconforme
Service accounts have strict access permissionsconforme
ServiceAccount or node can read all secretsconforme
VM instances have strict access permissionsconforme

Requires MFA for access to cloud resources

ControlEstado
Users are logging in securelyconforme

Requires MFA for access to cloud resources

ControlEstado
Users are logging in securelyconforme

Requires MFA for access to cloud resources

ControlEstado
Users are logging in securelyconforme

Configured SLAs to resolve issues

ControlEstado
Configure SLAsconforme

Enabled security logging for cloud instances

ControlEstado
Alerting policies have a notification channel configuredconforme
Amazon EKS Clusters should have control plane logging enabledconforme
Audit Configuration logging is enabledconforme
Logging and alerts are enabled for Project Ownership assignmentsconforme
Storage Permissions logging is enabledconforme
VPC Firewall has Rule logging enabledconforme

No malware issues

ControlEstado
No open malware issuesconforme

Prevents unwanted write operations to filesystems

ControlEstado
Container processes can gain more privileges than its parentconforme
Container running as root can allow attacker to escalate attacksconforme
Default Kubernetes settings allow containers to eavesdrop on traffic.conforme
Default security context allows pods to access host system.conforme
Docker container configured to run as user with root privilegesconforme
Docker container runs as default root userconforme
Filesystem for docker container should not be writeableconforme
Privileged container can allow attackers to escalate attacksconforme

Threat detection is enabled

ControlEstado
Alerting policies have a notification channel configuredconforme

Uses Lockfiles to pin code dependencies

ControlEstado
Use lockfiles in reposconforme

Has backups for stateful cloud resources

ControlEstado
Databases have automated backups enabledconforme
DynamoDB backups are offconforme

Enforces HTTPS traffic to cloud instances

ControlEstado
Cloud functions require HTTPS invocationsconforme
Load Balancers only accept HTTPS connectionsconforme

Prevents unauthorized public access to database

ControlEstado
BigQuery table is anonymously or publicly accessibleconforme
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
No firewall rule allows MongoDB access from the internetconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme

Prevents unauthorized public access to networks and instances

ControlEstado
AWS EKS Node groups have implicit SSH access from any IPconforme
Compute instances have OS Login enabledconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules allow RDP access from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow unrestricted SSH accessconforme
Project-wide SSH keys are blockedconforme

Enforces encryption of data in transit

ControlEstado
App does not validate SSL certificates properlyconforme
App uses an outdated TLS protocolconforme
App uses an outdated TLS protocolconforme
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Cloud functions require HTTPS invocationsconforme
Cloud SQL instance requires SSL connectionsconforme
Cookie missing HttpOnly flagconforme
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme
Express is not emitting security headersconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
HTTP Client misconfigured with SSL validation disabledconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure HTTP Request detectedconforme
Insecure TLS configuration detectedconforme
Insecure usage of `requests` sends data over cleartextconforme
Insecure websocket connection sends data over cleartextconforme
Laravel cookies can be sent unencryptedconforme
Load balancer allows invalid HTTP headersconforme
Load Balancers only accept HTTPS connectionsconforme
NodeJS talks to database without encryptionconforme
Outbound Ansible connections are not encryptedconforme
Outbound Ansible connections are not encryptedconforme
Server certificates are not verified during SSL/TLS connectionsconforme
Server hostnames not verified during SSL/TLS connectionsconforme
Signature validation for dnf packages is offconforme
SQS queue data is not encryptedconforme
TLS Certificate Validation Disabledconforme
TLS Certificate Validation Disabledconforme
Turning off TLS verification enables man-in-the-middle attacksconforme
Usage of deprecated or broken encryption detectedconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Using potentially unsafe FTP connections to move dataconforme
Using potentially unsafe FTP connections to move dataconforme
Weak SSL/TLS protocols usedconforme

Prevents unauthorized public access to networks and instances

ControlEstado
AWS EKS Node groups have implicit SSH access from any IPconforme
Compute instances have OS Login enabledconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules allow RDP access from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow unrestricted SSH accessconforme
Project-wide SSH keys are blockedconforme

Uses secure communications protocols

ControlEstado
API Gateway stages are not using TLS 1.2 or higherconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Cloud SQL db not enforcing SSLconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
Elasticsearch domain might have outdated TLS versionconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
NodeJS talks to database without encryptionconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme
Storage account does not enforce HTTPS-only trafficconforme

Enabled security logging for cloud instances

ControlEstado
Alerting policies have a notification channel configuredconforme
Amazon EKS Clusters should have control plane logging enabledconforme
Audit Configuration logging is enabledconforme
Logging and alerts are enabled for Project Ownership assignmentsconforme
Storage Permissions logging is enabledconforme
VPC Firewall has Rule logging enabledconforme

Tracks progress via an issue tracker

ControlEstado
Integration with issue tracker enabledconforme

Configured SLAs to resolve issues

ControlEstado
Configure SLAsconforme

No risky licenses in 3rd party dependencies

ControlEstado
No risky licenses in dependenciesconforme

no_issues_outside_of_sla

ControlEstado
No issues outside of slaconforme

Has separate production and test environments

ControlEstado
No cloud environment used for mixed purposes (eg production and staging)conforme

Configured monitoring for code repositories

ControlEstado
Configured monitoring for all code repositoriesconforme