Retour à Sécurité et conformité

DORA

141 contrôles conformes sur 141

Dernière synchronisation :

Le compteur est le décompte des contrôles que notre plateforme de contrôle continu Aikido Security rapporte comme satisfaits, sur l’ensemble de ceux qu’elle évalue pour ce référentiel. Ils sont tous listés ci-dessous, un à un.

Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.

Demander le rapport d’audit de sécurité

Has deletion protection for cloud resources

ContrôleStatut
Cloud SQL instances have deletion protection enabledconforme
Deletion protection is disabled for RDS databaseconforme
VM instances have deletion protection enabledconforme

Uses load balancers

ContrôleStatut
Load Balancers only accept HTTPS connectionsconforme

Configured monitoring for domains

ContrôleStatut
Connected public facing domainsconforme

Has connected cloud environments

ContrôleStatut
Cloud environments are connectedconforme

Has connected code repositories

ContrôleStatut
Code repositories are connectedconforme

Has connected container repositories

ContrôleStatut
Container repositories are connectedconforme

Cloud Infrastructure Configuration

ContrôleStatut
Access to BigQuery datasets are restrictedconforme
AKS API server does not limit access by IP rangesconforme
Amazon EKS Clusters public endpoints should not allow traffic from any IPconforme
Azure Cognitive Services allows unrestricted public network accessconforme
Azure Cognitive Services Network ACLs do not have IP rules configuredconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rules allow unrestricted RDP accessconforme
Firewall rules allow unrestricted SSH accessconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Kubernetes master endpoint is not publicly availableconforme
Vertex AI notebook instance has a public IP addressconforme

Data Protection and Encryption

ContrôleStatut
API Gateway endpoints do not require an API key or authorizationconforme
AWS EKS Node groups have implicit SSH access from any IPconforme
Azure Cosmos DB is publicly reachableconforme
Azure Key Vault allows public network accessconforme
BigQuery table is anonymously or publicly accessibleconforme
Cloud functions are not publicly accessibleconforme
Cloud functions have strict access policiesconforme
Cloud Storage bucket does not enforce public access preventionconforme
Cloud Storage bucket does not enforce uniform bucket-level accessconforme
Cloud Storage bucket is publicly accessibleconforme
Dataproc cluster is anonymously or publicly accessibleconforme
Default network exists in GCP projectconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules allow RDP access from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Firewall rules allow SSH from any public IPconforme
Key Vault is publicly accessibleconforme
KMS cryptographic key policy allows public accessconforme
KMS keys have strict access permissionsconforme
Kubernetes dashboard might be deployedconforme
Profiling endpoint automatically exposed on /debug/pprofconforme
Pub/Sub topic is anonymously or publicly accessibleconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme
SQL Server is publicly reachableconforme

Encryption at Rest Enabled

ContrôleStatut
Amazon EKS Clusters should have secrets encryption enabledconforme
API Gateway REST API caching is unencryptedconforme
AWS ElastiCache Redis cluster should have encryption at rest enabledconforme
Docker image repository not encrypted at restconforme
Elasticsearch domain is not encrypted at restconforme
Ensure all data stored in the RDS is securely encrypted at restconforme
KMS keys have key rotation enabledconforme
SNS topics are not encrypted at restconforme
SQS queue data is not encryptedconforme
Virtual Machines have confidential computing enabledconforme

Enforces HTTPS traffic to cloud instances

ContrôleStatut
Cloud functions require HTTPS invocationsconforme
Load Balancers only accept HTTPS connectionsconforme

Identity and Access Management (IAM)

ContrôleStatut
Users are logging in securelyconforme

Network Security

ContrôleStatut
Compute instances do not have public IP addressesconforme
Firewall rules restrict public ingress to port 11214conforme
Firewall rules restrict public ingress to port 11215conforme
Firewall rules restrict public ingress to port 135conforme
Firewall rules restrict public ingress to port 137conforme
Firewall rules restrict public ingress to port 138conforme
Firewall rules restrict public ingress to port 139conforme
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 389conforme
Firewall rules restrict public ingress to port 4505conforme
Firewall rules restrict public ingress to port 4506conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 636conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 8000conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
No firewall rule allows access to Open Telemtry metrics endpoint from the internetconforme
No firewall rule allows access to port 1720 from the internetconforme
No firewall rule allows cPanel access from the internetconforme
No firewall rule allows etcd access from the internetconforme
No firewall rule allows MongoDB access from the internetconforme
No firewall rule allows NFS access from the internetconforme
No firewall rule allows Telnet access from the internetconforme
No firewall rule allows Tomcat Cluster Receiver access from the internetconforme

Storage and Backup Security

ContrôleStatut
Azure Storage Account allow public accessconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Azure Storage blobs do not restrict public access for nested itemsconforme
Firewall rules restrict public ingress to port 3020conforme
S3 bucket grants public access to all contentsconforme
S3 Buckets should have block public access globallyconforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme
Storage buckets have uniform bucket-level access enabledconforme

Use of Cryptography: Enforces SSL

ContrôleStatut
Cloud SQL db not enforcing SSLconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
NodeJS talks to database without encryptionconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme

Use of Cryptography: Enforces TLS

ContrôleStatut
API Gateway stages are not using TLS 1.2 or higherconforme
Elasticsearch domain might have outdated TLS versionconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Storage account does not enforce HTTPS-only trafficconforme

Use of Cryptography: Secure Cookies

ContrôleStatut
Cookie missing HttpOnly flagconforme
Laravel cookies can be sent unencryptedconforme

Cloud Resource Logging Enabled

ContrôleStatut
Alerting policies have a notification channel configuredconforme
Amazon EKS Clusters should have control plane logging enabledconforme
Audit Configuration logging is enabledconforme
Logging and alerts are enabled for Project Ownership assignmentsconforme
Storage Permissions logging is enabledconforme
VPC Firewall has Rule logging enabledconforme

Does not have any issues outside of their SLA

ContrôleStatut
Configure SLAsconforme
No critical issues outside of SLAconforme
No high severity issues outside of SLAconforme
No low severity issues outside of SLAconforme
No medium severity issues outside of SLAconforme

Has email notifications set up

ContrôleStatut
Email notifications are enabledconforme

Has enabled security notifications

ContrôleStatut
Security notifications are enabledconforme

Has backups for stateful cloud resources

ContrôleStatut
Databases have automated backups enabledconforme

Is GDPR Compliant

ContrôleStatut
GDPR Complianceconforme

Does not have any issues outside of their SLA

ContrôleStatut
Configure SLAsconforme
No critical issues outside of SLAconforme
No high severity issues outside of SLAconforme
No low severity issues outside of SLAconforme
No medium severity issues outside of SLAconforme

Has email notifications set up

ContrôleStatut
Email notifications are enabledconforme

Has enabled security notifications

ContrôleStatut
Security notifications are enabledconforme

Configured monitoring for code repositories

ContrôleStatut
Configured monitoring for all code repositoriesconforme

Configured monitoring for container images

ContrôleStatut
Configured monitoring for all container imagesconforme