Volver a Seguridad y cumplimiento
SOC 2
523 controles conformes de 525
Última sincronización :
El contador es el que produce nuestra plataforma de control continuo Aikido Security, y el detalle enumera los controles que declara satisfechos. Ambas cifras pueden diferir ligeramente.
Los nombres de las evaluaciones, los tipos y los controles son los de los marcos de referencia de origen, por lo que están en inglés.
Solicitar el informe de auditoría de seguridad
Configured monitoring for code repositories
| Control | Estado |
|---|---|
| Configured monitoring for all code repositories | conforme |
Configured monitoring for container images
| Control | Estado |
|---|---|
| Configured monitoring for all container images | conforme |
Configured monitoring for domains
| Control | Estado |
|---|---|
| Configured monitoring for domains | conforme |
Does not have any severe open source dependency issues
| Control | Estado |
|---|---|
| No active critical open source dependency issues | conforme |
| No active high severity open source dependency issues | conforme |
Does not have any severe surface monitoring issues
| Control | Estado |
|---|---|
| No active critical surface monitoring issues | conforme |
| No active high severity surface monitoring issues | conforme |
Properly manages the identity of cloud users
| Control | Estado |
|---|---|
| Firewall rules restrict public ingress to port 636 | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Service accounts have strict access permissions | conforme |
| Users are logging in securely | conforme |
| Users are only allowed to use corporate emails | conforme |
Threat detection is enabled
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Applies the least privilege principle for cloud resource
| Control | Estado |
|---|---|
| Access Approval is enabled for the project | conforme |
| Compute instances have OS Login enabled | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| VM instances have strict access permissions | conforme |
Applies the least privilege principle to cloud resources
| Control | Estado |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
Enabled security logging for cloud instances
| Control | Estado |
|---|---|
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Requires MFA for cloud users
| Control | Estado |
|---|---|
| Users are logging in securely | conforme |
Threat detection is enabled
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Applies the least privilege principle for cloud resource
| Control | Estado |
|---|---|
| Access Approval is enabled for the project | conforme |
| Compute instances have OS Login enabled | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| VM instances have strict access permissions | conforme |
Does not have any severe infrastructure as code issues
| Control | Estado |
|---|---|
| No active critical infrastructure as code issues | conforme |
| No active high severity infrastructure as code issues | conforme |
Has deletion protection for cloud resources
| Control | Estado |
|---|---|
| Cloud SQL instances have deletion protection enabled | conforme |
| VM instances have deletion protection enabled | conforme |
Properly manages the identity of cloud users
| Control | Estado |
|---|---|
| Firewall rules restrict public ingress to port 636 | conforme |
| Users are logging in securely | conforme |
| Users are only allowed to use corporate emails | conforme |
Has separate production and test environments
| Control | Estado |
|---|---|
| No cloud environment used for mixed purposes (eg production and staging) | conforme |
Prevents unauthorized access via ssh
| Control | Estado |
|---|---|
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
Prevents unauthorized public access to database
| Control | Estado |
|---|---|
| BigQuery table is anonymously or publicly accessible | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
Prevents unauthorized public access to file storage
| Control | Estado |
|---|---|
| Azure Storage Account allow public access | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| Firewall rules restrict public ingress to port 3020 | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
Has secured load balancer access points
| Control | Estado |
|---|---|
| Users are logging in securely | conforme |
Has secured load balancer access points
| Control | Estado |
|---|---|
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Compute instances have OS Login enabled | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| Project-wide SSH keys are blocked | conforme |
Applies the least privilege principle to cloud resources
| Control | Estado |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
Encrypts data at rest
| Control | Estado |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces encryption of data in transit
| Control | Estado |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| App does not validate SSL certificates properly | conforme |
| App uses an outdated TLS protocol | conforme |
| App uses an outdated TLS protocol | conforme |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Cloud functions require HTTPS invocations | conforme |
| Cloud SQL db not enforcing SSL | conforme |
| Cloud SQL instance requires SSL connections | conforme |
| Cookie missing HttpOnly flag | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| DNSSEC is disabled | conforme |
| DNSSEC is enabled for all managed zones | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Express is not emitting security headers | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| HTTP Client misconfigured with SSL validation disabled | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure HTTP Request detected | conforme |
| Insecure TLS configuration detected | conforme |
| Insecure usage of `requests` sends data over cleartext | conforme |
| Insecure websocket connection sends data over cleartext | conforme |
| Laravel cookies can be sent unencrypted | conforme |
| Load balancer allows invalid HTTP headers | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| NodeJS talks to database without encryption | conforme |
| NodeJS talks to database without encryption | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Server certificates are not verified during SSL/TLS connections | conforme |
| Server hostnames not verified during SSL/TLS connections | conforme |
| Signature validation for dnf packages is off | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
| TLS Certificate Validation Disabled | conforme |
| TLS Certificate Validation Disabled | conforme |
| Turning off TLS verification enables man-in-the-middle attacks | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Weak SSL/TLS protocols used | conforme |
Has measures against SQL injection attacks
| Control | Estado |
|---|---|
| NoSQL injection attack possible | conforme |
| NoSQL injection attack possible | conforme |
| NoSQL injection attack possible | conforme |
| Potential NoSQL injection via string-based query concatenation | conforme |
| Potential NoSQL injection via string-based query concatenation | conforme |
| Potential NoSQL injection via string-based query concatenation | conforme |
| Potential NoSQL injection via string-based query concatenation | conforme |
| Potential SQL injection in Doctrine's QueryBuilder | conforme |
| Potential SQL injection in sqlite3 via string-based query concatenation | conforme |
| Potential SQL injection through JDBC via string-based query concatenation | conforme |
| Potential SQL injection using sqflite execute sink | conforme |
| Potential SQL injection via Drupal database functionality | conforme |
| Potential SQL injection via dynamic raw query construction | conforme |
| Potential SQL injection via dynamic raw query construction | conforme |
| Potential SQL injection via dynamic raw query construction | conforme |
| Potential SQL injection via Laravel function | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation | conforme |
| Potential SQL injection via string-based query concatenation using AuraSQL framework functions | conforme |
| Potential SQL injection via Yii function | conforme |
| Potential SQL injection when bypassing Django ORM with extra() | conforme |
| Potential SQL injection when bypassing Django ORM with RawSQL() | conforme |
| Potential SQL injection when bypassing Doctrine ORM with raw query | conforme |
Is protected against command injections attacks
| Control | Estado |
|---|---|
| A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input. | conforme |
| Possible command injection via Process.Start | conforme |
| Possible command injection via Process.Start | conforme |
| Possible command injection via shell script | conforme |
| Possible command injection via user-controlled input to clojure.java.shell/sh | conforme |
| Potential command injection via Command API | conforme |
| Potential command injection via Process.run | conforme |
| Use of vulnerable ingress-nginx controller | conforme |
| Xpath injection attack could lead to information extraction | conforme |
| Xpath injection attack could lead to information extraction | conforme |
Is protected against SSRF attacks
| Control | Estado |
|---|---|
| A timing attack might allow hackers to bruteforce passwords | conforme |
| EC2 IAM roles vulnerable to SSRF attacks | conforme |
| GCP Kubernetes engine clusters vulnerable to SSRF attacks | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| HTTP request might enable SSRF attack | conforme |
| Potential file inclusion attack via reading file | conforme |
| Potential file inclusion attack via reading file | conforme |
| Potential file inclusion attack via reading file | conforme |
| Potential user input in HTTP request may allow SSRF attack | conforme |
| Potential user input in HTTP request may allow SSRF attack | conforme |
| Simple DOS attack possible due to http.server misconfiguration | conforme |
| User data used in Puppeteer methods can result in SSRF | conforme |
| User data used in Puppeteer methods can result in SSRF | conforme |
Prevents the exposure of sensitive data
| Control | Estado |
|---|---|
| Currently there are no exposed secrets | conforme |
Prevents XSS attacks
| Control | Estado |
|---|---|
| Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilities | conforme |
| Directly writing unsanitized input to http.ResponseWriter can lead to XSS | conforme |
| Disabling JSON HTML Escaping in ActiveSupport may lead to XSS | conforme |
| DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinks | conforme |
| HttpServletResponse output can be used for XSS attacks | conforme |
| Improper sanitization in dynamic attribute bindings can lead to XSS attacks | conforme |
| Input validation disabled in controller | conforme |
| Jinja2 template config can lead to XSS attacks | conforme |
| Potential Cross Site Scripting (XSS) via window.location.href | conforme |
| Potential XSS due to enabling bypassSecurityTrustUrl | conforme |
| Potential XSS via MarkupStr(...) in Razor template may lead to XSS | conforme |
| Rendering unescaped input can lead to XSS attacks | conforme |
| Rendering unescaped input can lead to XSS attacks | conforme |
| Rendering unescaped input can lead to XSS attacks | conforme |
| Rendering unescaped input can lead to XSS attacks | conforme |
| Rendering unescaped input can lead to XSS attacks | conforme |
| Rendering unescaped input can lead to XSS attacks | conforme |
| Rendering unescaped input in EJS template can lead to XSS attacks | conforme |
| Rendering unescaped input in handlebar/mustache template can lead to XSS attacks | conforme |
| Rendering unescaped input in HTML template can lead to XSS attacks | conforme |
| Unsanitized user input in jQuery DOM handling methods detected | conforme |
| Unsanitized user input leads to cross-site scripting (XSS) | conforme |
| Using dangerouslySetInnerHTML in React can lead to XSS attacks | conforme |
| Using document write methods can lead to XSS attacks | conforme |
| Using document write methods can lead to XSS attacks | conforme |
| Using document write methods can lead to XSS attacks | conforme |
| Using raw on potential user input can leads to XSS | conforme |
| Using v-html in Vue templates can lead to XSS attacks | conforme |
Requires MFA for cloud users
| Control | Estado |
|---|---|
| Users are logging in securely | conforme |
Threat detection is enabled
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Encrypts data at rest
| Control | Estado |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces encryption of data in transit
| Control | Estado |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| App does not validate SSL certificates properly | conforme |
| App uses an outdated TLS protocol | conforme |
| App uses an outdated TLS protocol | conforme |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Cloud functions require HTTPS invocations | conforme |
| Cloud SQL db not enforcing SSL | conforme |
| Cloud SQL instance requires SSL connections | conforme |
| Cookie missing HttpOnly flag | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| DNSSEC is disabled | conforme |
| DNSSEC is enabled for all managed zones | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Express is not emitting security headers | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| HTTP Client misconfigured with SSL validation disabled | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure HTTP Request detected | conforme |
| Insecure TLS configuration detected | conforme |
| Insecure usage of `requests` sends data over cleartext | conforme |
| Insecure websocket connection sends data over cleartext | conforme |
| Laravel cookies can be sent unencrypted | conforme |
| Load balancer allows invalid HTTP headers | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| NodeJS talks to database without encryption | conforme |
| NodeJS talks to database without encryption | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Server certificates are not verified during SSL/TLS connections | conforme |
| Server hostnames not verified during SSL/TLS connections | conforme |
| Signature validation for dnf packages is off | conforme |
| SQS queue data is not encrypted | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
| TLS Certificate Validation Disabled | conforme |
| TLS Certificate Validation Disabled | conforme |
| Turning off TLS verification enables man-in-the-middle attacks | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Weak SSL/TLS protocols used | conforme |
Uses up to date cryptography libraries
| Control | Estado |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Applies the least privilege principle for cloud resource
| Control | Estado |
|---|---|
| Access Approval is enabled for the project | conforme |
| Access to BigQuery datasets are restricted | conforme |
| API key restricts usage to certain APIs | conforme |
| API key restricts usage to certain clients | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Compute instances have IP forwarding disabled | conforme |
| Compute instances have OS Login enabled | conforme |
| Compute instances have serial port access disabled | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| GKE clusters have the GKE Metadata Server enabled | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| GKE node pools use dedicated service accounts | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
| Storage buckets have uniform bucket-level access enabled | conforme |
| Users are logging in securely | conforme |
| VM instances have strict access permissions | conforme |
MFA is enforced for cloud users
| Control | Estado |
|---|---|
| Users are logging in securely | conforme |
Prevents public access to cloud resources
| Control | Estado |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| API Gateway endpoints do not require an API key or authorization | conforme |
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Azure Cosmos DB is publicly reachable | conforme |
| Azure Key Vault allows public network access | conforme |
| Azure Storage Account allow public access | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| BigQuery table is anonymously or publicly accessible | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Cloud Storage bucket does not enforce public access prevention | conforme |
| Cloud Storage bucket does not enforce uniform bucket-level access | conforme |
| Cloud Storage bucket is publicly accessible | conforme |
| Compute instances do not have public IP addresses | conforme |
| Dataproc cluster is anonymously or publicly accessible | conforme |
| Default network exists in GCP project | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 11214 | conforme |
| Firewall rules restrict public ingress to port 11215 | conforme |
| Firewall rules restrict public ingress to port 135 | conforme |
| Firewall rules restrict public ingress to port 137 | conforme |
| Firewall rules restrict public ingress to port 138 | conforme |
| Firewall rules restrict public ingress to port 139 | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 3020 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 389 | conforme |
| Firewall rules restrict public ingress to port 4505 | conforme |
| Firewall rules restrict public ingress to port 4506 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 8000 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| Key Vault is publicly accessible | conforme |
| KMS cryptographic key policy allows public access | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes dashboard might be deployed | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | conforme |
| No firewall rule allows access to port 1720 from the internet | conforme |
| No firewall rule allows cPanel access from the internet | conforme |
| No firewall rule allows etcd access from the internet | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| No firewall rule allows NFS access from the internet | conforme |
| No firewall rule allows Telnet access from the internet | conforme |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | conforme |
| Profiling endpoint automatically exposed on /debug/pprof | conforme |
| Pub/Sub topic is anonymously or publicly accessible | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| SQL Server is publicly reachable | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Enforces latest TLS version
| Control | Estado |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Uses up to date cryptography libraries
| Control | Estado |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Prevents container orchestration takeover
| Control | Estado |
|---|---|
| AKS local admin account is still enabled | conforme |
| Dangerous Impersonate permission given to ServiceAccount or node | conforme |
Protects unauthorized runtime access
| Control | Estado |
|---|---|
| Container processes can gain more privileges than its parent | conforme |
| Container running as root can allow attacker to escalate attacks | conforme |
| Default Kubernetes settings allow containers to eavesdrop on traffic. | conforme |
| Default security context allows pods to access host system. | conforme |
| Docker container configured to run as user with root privileges | conforme |
| Docker container runs as default root user | conforme |
| Filesystem for docker container should not be writeable | conforme |
| Privileged container can allow attackers to escalate attacks | conforme |
Aikido Malware Scanner is enabled
| Control | Estado |
|---|---|
| Aikido Malware Scanner is enabled | conforme |
Threat detection is enabled
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Connected code repositories
| Control | Estado |
|---|---|
| Connect code repositories | conforme |
Connected public facing domain
| Control | Estado |
|---|---|
| Connect public facing domain | conforme |
Does not have any issues outside of their SLA
| Control | Estado |
|---|---|
| No issues outside of sla | conforme |
Uses Lockfiles to pin code dependencies
| Control | Estado |
|---|---|
| Use lockfiles in repos | conforme |
Connected code repositories
| Control | Estado |
|---|---|
| Connect code repositories | conforme |
Threat detection is enabled
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Configured SLAs to resolve issues
| Control | Estado |
|---|---|
| Configure SLAs | conforme |
Connected cloud environment
| Control | Estado |
|---|---|
| Connect a cloud environment | conforme |
Connected code repositories
| Control | Estado |
|---|---|
| Connect code repositories | conforme |
Connected public facing domain
| Control | Estado |
|---|---|
| Connect public facing domain | conforme |
Enabled security logging for cloud instances
| Control | Estado |
|---|---|
| Alerting policies have a notification channel configured | conforme |
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Has no critical open source dependency issues
| Control | Estado |
|---|---|
| There are critical open source dependency issues | conforme |
Runtimes are up to date
| Control | Estado |
|---|---|
| AWS MQBroker version is outdated | conforme |
| GKE clusters use stable release channels with automatic upgrades | conforme |
| GKE node pools have node auto-upgrade enabled | conforme |
| No AKS cluster upgrade channel is chosen | conforme |
Prevents the exposure of sensitive data
| Control | Estado |
|---|---|
| Currently there are no exposed secrets | conforme |
Tracks progress via an issue tracker
| Control | Estado |
|---|---|
| Integration with issue tracker enabled | conforme |
Has backups for stateful cloud resources
| Control | Estado |
|---|---|
| Databases have automated backups enabled | conforme |
| DynamoDB backups are off | conforme |
