Volver a Seguridad y cumplimiento
RGPD
175 controles conformes de 175
Última sincronización :
El contador es el que produce nuestra plataforma de control continuo Aikido Security, y el detalle enumera los controles que declara satisfechos. Ambas cifras pueden diferir ligeramente.
Los nombres de las evaluaciones, los tipos y los controles son los de los marcos de referencia de origen, por lo que están en inglés.
Solicitar el informe de auditoría de seguridad
Enforces Multi-Factor Authentication (MFA)
| Control | Estado |
|---|---|
| Users are logging in securely | conforme |
Proper Access Management for Resources
| Control | Estado |
|---|---|
| Access Approval is enabled for the project | conforme |
| AKS local admin account is still enabled | conforme |
| Compute instances have OS Login enabled | conforme |
| Dangerous Impersonate permission given to ServiceAccount or node | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| ServiceAccount or node can read all secrets | conforme |
| VM instances have strict access permissions | conforme |
Proper Access Management for Users
| Control | Estado |
|---|---|
| Users are only allowed to use corporate emails | conforme |
Proper Access Management to Resources
| Control | Estado |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| API Gateway endpoints do not require an API key or authorization | conforme |
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Azure Cosmos DB is publicly reachable | conforme |
| Azure Key Vault allows public network access | conforme |
| Azure Storage Account allow public access | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| BigQuery table is anonymously or publicly accessible | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Cloud Storage bucket does not enforce public access prevention | conforme |
| Cloud Storage bucket does not enforce uniform bucket-level access | conforme |
| Cloud Storage bucket is publicly accessible | conforme |
| Dataproc cluster is anonymously or publicly accessible | conforme |
| Default network exists in GCP project | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Key Vault is publicly accessible | conforme |
| KMS cryptographic key policy allows public access | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes dashboard might be deployed | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| Profiling endpoint automatically exposed on /debug/pprof | conforme |
| Pub/Sub topic is anonymously or publicly accessible | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| SQL Server is publicly reachable | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Encryption at Rest Enabled
| Control | Estado |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces HTTPS traffic to cloud instances
| Control | Estado |
|---|---|
| Cloud functions require HTTPS invocations | conforme |
| Load Balancers only accept HTTPS connections | conforme |
Runtimes are up to date
| Control | Estado |
|---|---|
| AWS MQBroker version is outdated | conforme |
| GKE clusters use stable release channels with automatic upgrades | conforme |
| GKE node pools have node auto-upgrade enabled | conforme |
| No AKS cluster upgrade channel is chosen | conforme |
| No Critical End-of-Life (EOL) Issues | conforme |
| No High End-of-Life (EOL) Issues | conforme |
Use of Cryptography Libraries
| Control | Estado |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Use of Cryptography: Enforces SSL
| Control | Estado |
|---|---|
| Cloud SQL db not enforcing SSL | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| NodeJS talks to database without encryption | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
Use of Cryptography: Enforces TLS
| Control | Estado |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Use of Cryptography: Secure Cookies
| Control | Estado |
|---|---|
| Cookie missing HttpOnly flag | conforme |
| Laravel cookies can be sent unencrypted | conforme |
Backups Enabled
| Control | Estado |
|---|---|
| Databases have automated backups enabled | conforme |
| DynamoDB backups are off | conforme |
Logging Enabled
| Control | Estado |
|---|---|
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Threat Detection Enabled
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Encryption at Rest Enabled
| Control | Estado |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces HTTPS traffic to cloud instances
| Control | Estado |
|---|---|
| Cloud functions require HTTPS invocations | conforme |
| Load Balancers only accept HTTPS connections | conforme |
Use of Cryptography Libraries
| Control | Estado |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Use of Cryptography: Enforces SSL
| Control | Estado |
|---|---|
| Cloud SQL db not enforcing SSL | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| NodeJS talks to database without encryption | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
Use of Cryptography: Enforces TLS
| Control | Estado |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Use of Cryptography: Secure Cookies
| Control | Estado |
|---|---|
| Cookie missing HttpOnly flag | conforme |
| Laravel cookies can be sent unencrypted | conforme |
