Retour à Sécurité et conformité
DORA
141 contrôles conformes sur 141
Dernière synchronisation :
Le compteur est le décompte des contrôles que notre plateforme de contrôle continu Aikido Security rapporte comme satisfaits, sur l’ensemble de ceux qu’elle évalue pour ce référentiel. Ils sont tous listés ci-dessous, un à un.
Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.
Demander le rapport d’audit de sécurité
Has deletion protection for cloud resources
| Contrôle | Statut |
|---|---|
| Cloud SQL instances have deletion protection enabled | conforme |
| Deletion protection is disabled for RDS database | conforme |
| VM instances have deletion protection enabled | conforme |
Uses load balancers
| Contrôle | Statut |
|---|---|
| Load Balancers only accept HTTPS connections | conforme |
Configured monitoring for domains
| Contrôle | Statut |
|---|---|
| Connected public facing domains | conforme |
Has connected cloud environments
| Contrôle | Statut |
|---|---|
| Cloud environments are connected | conforme |
Has connected code repositories
| Contrôle | Statut |
|---|---|
| Code repositories are connected | conforme |
Has connected container repositories
| Contrôle | Statut |
|---|---|
| Container repositories are connected | conforme |
Cloud Infrastructure Configuration
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Azure Cognitive Services Network ACLs do not have IP rules configured | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Data Protection and Encryption
| Contrôle | Statut |
|---|---|
| API Gateway endpoints do not require an API key or authorization | conforme |
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Azure Cosmos DB is publicly reachable | conforme |
| Azure Key Vault allows public network access | conforme |
| BigQuery table is anonymously or publicly accessible | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Cloud Storage bucket does not enforce public access prevention | conforme |
| Cloud Storage bucket does not enforce uniform bucket-level access | conforme |
| Cloud Storage bucket is publicly accessible | conforme |
| Dataproc cluster is anonymously or publicly accessible | conforme |
| Default network exists in GCP project | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Key Vault is publicly accessible | conforme |
| KMS cryptographic key policy allows public access | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes dashboard might be deployed | conforme |
| Profiling endpoint automatically exposed on /debug/pprof | conforme |
| Pub/Sub topic is anonymously or publicly accessible | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| SQL Server is publicly reachable | conforme |
Encryption at Rest Enabled
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces HTTPS traffic to cloud instances
| Contrôle | Statut |
|---|---|
| Cloud functions require HTTPS invocations | conforme |
| Load Balancers only accept HTTPS connections | conforme |
Identity and Access Management (IAM)
| Contrôle | Statut |
|---|---|
| Users are logging in securely | conforme |
Network Security
| Contrôle | Statut |
|---|---|
| Compute instances do not have public IP addresses | conforme |
| Firewall rules restrict public ingress to port 11214 | conforme |
| Firewall rules restrict public ingress to port 11215 | conforme |
| Firewall rules restrict public ingress to port 135 | conforme |
| Firewall rules restrict public ingress to port 137 | conforme |
| Firewall rules restrict public ingress to port 138 | conforme |
| Firewall rules restrict public ingress to port 139 | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 389 | conforme |
| Firewall rules restrict public ingress to port 4505 | conforme |
| Firewall rules restrict public ingress to port 4506 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 8000 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | conforme |
| No firewall rule allows access to port 1720 from the internet | conforme |
| No firewall rule allows cPanel access from the internet | conforme |
| No firewall rule allows etcd access from the internet | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| No firewall rule allows NFS access from the internet | conforme |
| No firewall rule allows Telnet access from the internet | conforme |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | conforme |
Storage and Backup Security
| Contrôle | Statut |
|---|---|
| Azure Storage Account allow public access | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| Firewall rules restrict public ingress to port 3020 | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
| Storage buckets have uniform bucket-level access enabled | conforme |
Use of Cryptography: Enforces SSL
| Contrôle | Statut |
|---|---|
| Cloud SQL db not enforcing SSL | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| NodeJS talks to database without encryption | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
Use of Cryptography: Enforces TLS
| Contrôle | Statut |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Use of Cryptography: Secure Cookies
| Contrôle | Statut |
|---|---|
| Cookie missing HttpOnly flag | conforme |
| Laravel cookies can be sent unencrypted | conforme |
Cloud Resource Logging Enabled
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Does not have any issues outside of their SLA
| Contrôle | Statut |
|---|---|
| Configure SLAs | conforme |
| No critical issues outside of SLA | conforme |
| No high severity issues outside of SLA | conforme |
| No low severity issues outside of SLA | conforme |
| No medium severity issues outside of SLA | conforme |
Has email notifications set up
| Contrôle | Statut |
|---|---|
| Email notifications are enabled | conforme |
Has enabled security notifications
| Contrôle | Statut |
|---|---|
| Security notifications are enabled | conforme |
Has backups for stateful cloud resources
| Contrôle | Statut |
|---|---|
| Databases have automated backups enabled | conforme |
Is GDPR Compliant
| Contrôle | Statut |
|---|---|
| GDPR Compliance | conforme |
Does not have any issues outside of their SLA
| Contrôle | Statut |
|---|---|
| Configure SLAs | conforme |
| No critical issues outside of SLA | conforme |
| No high severity issues outside of SLA | conforme |
| No low severity issues outside of SLA | conforme |
| No medium severity issues outside of SLA | conforme |
Has email notifications set up
| Contrôle | Statut |
|---|---|
| Email notifications are enabled | conforme |
Has enabled security notifications
| Contrôle | Statut |
|---|---|
| Security notifications are enabled | conforme |
Configured monitoring for code repositories
| Contrôle | Statut |
|---|---|
| Configured monitoring for all code repositories | conforme |
Configured monitoring for container images
| Contrôle | Statut |
|---|---|
| Configured monitoring for all container images | conforme |
