Retour à Sécurité et conformité
CIS Controls v8
456 contrôles conformes sur 456
Dernière synchronisation :
Le compteur est celui produit par notre plateforme de contrôle continu Aikido Security, et le détail liste les contrôles qu’elle rapporte comme satisfaits. Les deux chiffres peuvent différer légèrement.
Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.
Demander le rapport d’audit de sécurité
Applies the least privilege principle for cloud resource
| Contrôle | Statut |
|---|---|
| Access Approval is enabled for the project | conforme |
| AKS local admin account is still enabled | conforme |
| Compute instances have OS Login enabled | conforme |
| Dangerous Impersonate permission given to ServiceAccount or node | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| ServiceAccount or node can read all secrets | conforme |
| VM instances have strict access permissions | conforme |
Applies the least privilege principle for cloud users
| Contrôle | Statut |
|---|---|
| Firewall rules restrict public ingress to port 636 | conforme |
| Users are logging in securely | conforme |
| Users are only allowed to use corporate emails | conforme |
Applies the least privilege principle to cloud resources
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| API Gateway endpoints do not require an API key or authorization | conforme |
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Azure Cosmos DB is publicly reachable | conforme |
| Azure Key Vault allows public network access | conforme |
| Azure Storage Account allow public access | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| BigQuery table is anonymously or publicly accessible | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Cloud Storage bucket does not enforce public access prevention | conforme |
| Cloud Storage bucket does not enforce uniform bucket-level access | conforme |
| Cloud Storage bucket is publicly accessible | conforme |
| Dataproc cluster is anonymously or publicly accessible | conforme |
| Default network exists in GCP project | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Key Vault is publicly accessible | conforme |
| KMS cryptographic key policy allows public access | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes dashboard might be deployed | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| Profiling endpoint automatically exposed on /debug/pprof | conforme |
| Pub/Sub topic is anonymously or publicly accessible | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| SQL Server is publicly reachable | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Enabled security logging for cloud instances
| Contrôle | Statut |
|---|---|
| Cloud SQL instances have deletion protection enabled | conforme |
| Deletion protection is disabled for RDS database | conforme |
| VM instances have deletion protection enabled | conforme |
Enforces encryption of data in transit
| Contrôle | Statut |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| App does not validate SSL certificates properly | conforme |
| App uses an outdated TLS protocol | conforme |
| App uses an outdated TLS protocol | conforme |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Cloud functions require HTTPS invocations | conforme |
| Cloud SQL db not enforcing SSL | conforme |
| Cloud SQL instance requires SSL connections | conforme |
| Cookie missing HttpOnly flag | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| DNSSEC is disabled | conforme |
| DNSSEC is enabled for all managed zones | conforme |
| Domain SSL Certificate Expiration | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Express is not emitting security headers | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| HSTS header has malformed content | conforme |
| HSTS header has malformed Max-Age directive | conforme |
| HSTS header is defined via meta tag | conforme |
| HSTS header is disabled | conforme |
| HSTS header is malformed directive | conforme |
| HSTS header is missing | conforme |
| HTTP Client misconfigured with SSL validation disabled | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure HTTP Request detected | conforme |
| Insecure TLS configuration detected | conforme |
| Insecure usage of `requests` sends data over cleartext | conforme |
| Insecure websocket connection sends data over cleartext | conforme |
| Laravel cookies can be sent unencrypted | conforme |
| Load balancer allows invalid HTTP headers | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| Multiple HSTS headers are being set | conforme |
| NodeJS talks to database without encryption | conforme |
| NodeJS talks to database without encryption | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Server certificates are not verified during SSL/TLS connections | conforme |
| Server hostnames not verified during SSL/TLS connections | conforme |
| Signature validation for dnf packages is off | conforme |
| SQS queue data is not encrypted | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
| TLS Certificate Validation Disabled | conforme |
| TLS Certificate Validation Disabled | conforme |
| TLS not enforced with valid HSTS header | conforme |
| Turning off TLS verification enables man-in-the-middle attacks | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Weak SSL/TLS protocols used | conforme |
Encrypts data at rest
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enabled security logging for cloud instances
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Threat detection is enabled
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Enforces encryption of data in transit
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Compute instances do not have public IP addresses | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 11214 | conforme |
| Firewall rules restrict public ingress to port 11215 | conforme |
| Firewall rules restrict public ingress to port 135 | conforme |
| Firewall rules restrict public ingress to port 137 | conforme |
| Firewall rules restrict public ingress to port 138 | conforme |
| Firewall rules restrict public ingress to port 139 | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 3020 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 389 | conforme |
| Firewall rules restrict public ingress to port 4505 | conforme |
| Firewall rules restrict public ingress to port 4506 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 8000 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | conforme |
| No firewall rule allows access to port 1720 from the internet | conforme |
| No firewall rule allows cPanel access from the internet | conforme |
| No firewall rule allows etcd access from the internet | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| No firewall rule allows NFS access from the internet | conforme |
| No firewall rule allows Telnet access from the internet | conforme |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Prevents unauthorized public access to database
| Contrôle | Statut |
|---|---|
| BigQuery table is anonymously or publicly accessible | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
Prevents unauthorized public access to file storage
| Contrôle | Statut |
|---|---|
| Azure Storage Account allow public access | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
Threat detection is enabled
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Enforces encryption of data in transit
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Compute instances do not have public IP addresses | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 11214 | conforme |
| Firewall rules restrict public ingress to port 11215 | conforme |
| Firewall rules restrict public ingress to port 135 | conforme |
| Firewall rules restrict public ingress to port 137 | conforme |
| Firewall rules restrict public ingress to port 138 | conforme |
| Firewall rules restrict public ingress to port 139 | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 3020 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 389 | conforme |
| Firewall rules restrict public ingress to port 4505 | conforme |
| Firewall rules restrict public ingress to port 4506 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 8000 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | conforme |
| No firewall rule allows access to port 1720 from the internet | conforme |
| No firewall rule allows cPanel access from the internet | conforme |
| No firewall rule allows etcd access from the internet | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| No firewall rule allows NFS access from the internet | conforme |
| No firewall rule allows Telnet access from the internet | conforme |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Enforces HTTPS traffic to cloud instances
| Contrôle | Statut |
|---|---|
| Load Balancers only accept HTTPS connections | conforme |
Enforces latest TLS version
| Contrôle | Statut |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Uses DNSSEC extensions
| Contrôle | Statut |
|---|---|
| DNSSEC is disabled | conforme |
| DNSSEC is enabled for all managed zones | conforme |
Applies the least privilege principle for cloud resource
| Contrôle | Statut |
|---|---|
| Access Approval is enabled for the project | conforme |
| AKS local admin account is still enabled | conforme |
| Compute instances have OS Login enabled | conforme |
| Dangerous Impersonate permission given to ServiceAccount or node | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| ServiceAccount or node can read all secrets | conforme |
| VM instances have strict access permissions | conforme |
Requires MFA for access to cloud resources
| Contrôle | Statut |
|---|---|
| Users are logging in securely | conforme |
Requires MFA for access to cloud resources
| Contrôle | Statut |
|---|---|
| Users are logging in securely | conforme |
Requires MFA for access to cloud resources
| Contrôle | Statut |
|---|---|
| Users are logging in securely | conforme |
Configured SLAs to resolve issues
| Contrôle | Statut |
|---|---|
| Configure SLAs | conforme |
Enabled security logging for cloud instances
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
No malware issues
| Contrôle | Statut |
|---|---|
| No open malware issues | conforme |
Prevents unwanted write operations to filesystems
| Contrôle | Statut |
|---|---|
| Container processes can gain more privileges than its parent | conforme |
| Container running as root can allow attacker to escalate attacks | conforme |
| Default Kubernetes settings allow containers to eavesdrop on traffic. | conforme |
| Default security context allows pods to access host system. | conforme |
| Docker container configured to run as user with root privileges | conforme |
| Docker container runs as default root user | conforme |
| Filesystem for docker container should not be writeable | conforme |
| Privileged container can allow attackers to escalate attacks | conforme |
Threat detection is enabled
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Uses Lockfiles to pin code dependencies
| Contrôle | Statut |
|---|---|
| Use lockfiles in repos | conforme |
Has backups for stateful cloud resources
| Contrôle | Statut |
|---|---|
| Databases have automated backups enabled | conforme |
| DynamoDB backups are off | conforme |
Enforces HTTPS traffic to cloud instances
| Contrôle | Statut |
|---|---|
| Cloud functions require HTTPS invocations | conforme |
| Load Balancers only accept HTTPS connections | conforme |
Prevents unauthorized public access to database
| Contrôle | Statut |
|---|---|
| BigQuery table is anonymously or publicly accessible | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
Prevents unauthorized public access to networks and instances
| Contrôle | Statut |
|---|---|
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Compute instances have OS Login enabled | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Project-wide SSH keys are blocked | conforme |
Enforces encryption of data in transit
| Contrôle | Statut |
|---|---|
| App does not validate SSL certificates properly | conforme |
| App uses an outdated TLS protocol | conforme |
| App uses an outdated TLS protocol | conforme |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Cloud functions require HTTPS invocations | conforme |
| Cloud SQL instance requires SSL connections | conforme |
| Cookie missing HttpOnly flag | conforme |
| DNSSEC is disabled | conforme |
| DNSSEC is enabled for all managed zones | conforme |
| Express is not emitting security headers | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| HTTP Client misconfigured with SSL validation disabled | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure HTTP Request detected | conforme |
| Insecure TLS configuration detected | conforme |
| Insecure usage of `requests` sends data over cleartext | conforme |
| Insecure websocket connection sends data over cleartext | conforme |
| Laravel cookies can be sent unencrypted | conforme |
| Load balancer allows invalid HTTP headers | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| NodeJS talks to database without encryption | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Server certificates are not verified during SSL/TLS connections | conforme |
| Server hostnames not verified during SSL/TLS connections | conforme |
| Signature validation for dnf packages is off | conforme |
| SQS queue data is not encrypted | conforme |
| TLS Certificate Validation Disabled | conforme |
| TLS Certificate Validation Disabled | conforme |
| Turning off TLS verification enables man-in-the-middle attacks | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Weak SSL/TLS protocols used | conforme |
Prevents unauthorized public access to networks and instances
| Contrôle | Statut |
|---|---|
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Compute instances have OS Login enabled | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Project-wide SSH keys are blocked | conforme |
Uses secure communications protocols
| Contrôle | Statut |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Cloud SQL db not enforcing SSL | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| NodeJS talks to database without encryption | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Enabled security logging for cloud instances
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Tracks progress via an issue tracker
| Contrôle | Statut |
|---|---|
| Integration with issue tracker enabled | conforme |
Configured SLAs to resolve issues
| Contrôle | Statut |
|---|---|
| Configure SLAs | conforme |
No risky licenses in 3rd party dependencies
| Contrôle | Statut |
|---|---|
| No risky licenses in dependencies | conforme |
no_issues_outside_of_sla
| Contrôle | Statut |
|---|---|
| No issues outside of sla | conforme |
Has separate production and test environments
| Contrôle | Statut |
|---|---|
| No cloud environment used for mixed purposes (eg production and staging) | conforme |
Configured monitoring for code repositories
| Contrôle | Statut |
|---|---|
| Configured monitoring for all code repositories | conforme |
