Retour à Sécurité et conformité

ISO 27001:2022

455 contrôles conformes sur 455

Dernière synchronisation :

Le compteur est celui produit par notre plateforme de contrôle continu Aikido Security, et le détail liste les contrôles qu’elle rapporte comme satisfaits. Les deux chiffres peuvent différer légèrement.

Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.

Demander le rapport d’audit de sécurité

Applies the least privilege principle for cloud resource

ContrôleStatut
Access Approval is enabled for the projectconforme
Compute instances have OS Login enabledconforme
GKE clusters have the Kubernetes Dashboard disabledconforme
Kubernetes pods are isolatedconforme
No instance uses the default service accountconforme
No user has both the Service Account User and Service Account Admin roleconforme
Project-wide SSH keys are blockedconforme
Service accounts have strict access permissionsconforme
VM instances have strict access permissionsconforme

Applies the least privilege principle for cloud users

ContrôleStatut
Firewall rules restrict public ingress to port 636conforme
Users are logging in securelyconforme
Users are only allowed to use corporate emailsconforme

Applies the least privilege principle to cloud resources

ContrôleStatut
Access to BigQuery datasets are restrictedconforme
Cloud functions are not publicly accessibleconforme
Cloud functions have strict access policiesconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
KMS keys have strict access permissionsconforme
Kubernetes master endpoint is not publicly availableconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme

Prevents the exposure of sensitive data

ContrôleStatut
Currently there are no exposed secretsconforme

Has backups for stateful cloud resources

ContrôleStatut
Databases have automated backups enabledconforme

Uses load balancers correctly

ContrôleStatut
Load Balancers only accept HTTPS connectionsconforme

Tracks progress via an issue tracker

ContrôleStatut
Integration with issue tracker enabledconforme

Enabled security logging for cloud instances

ContrôleStatut
Audit Configuration logging is enabledconforme
Logging and alerts are enabled for Project Ownership assignmentsconforme
Storage Permissions logging is enabledconforme
VPC Firewall has Rule logging enabledconforme

Has enabled threat detection

ContrôleStatut
Alerting policies have a notification channel configuredconforme

Runs cloud instances on up-to-date versions

ContrôleStatut
GKE clusters use stable release channels with automatic upgradesconforme
GKE node pools have node auto-upgrade enabledconforme

Uses Lockfiles to pin code dependencies

ContrôleStatut
Usage of lockfiles in code repositoriesconforme

Encrypts data at rest

ContrôleStatut
Amazon EKS Clusters should have secrets encryption enabledconforme
API Gateway REST API caching is unencryptedconforme
AWS ElastiCache Redis cluster should have encryption at rest enabledconforme
Docker image repository not encrypted at restconforme
Elasticsearch domain is not encrypted at restconforme
Ensure all data stored in the RDS is securely encrypted at restconforme
KMS keys have key rotation enabledconforme
SNS topics are not encrypted at restconforme
SQS queue data is not encryptedconforme
Virtual Machines have confidential computing enabledconforme

Enforces encryption of data in transit

ContrôleStatut
API Gateway stages are not using TLS 1.2 or higherconforme
App does not validate SSL certificates properlyconforme
App uses an outdated TLS protocolconforme
App uses an outdated TLS protocolconforme
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Cloud functions require HTTPS invocationsconforme
Cloud SQL db not enforcing SSLconforme
Cloud SQL instance requires SSL connectionsconforme
Cookie missing HttpOnly flagconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme
Elasticsearch domain might have outdated TLS versionconforme
Express is not emitting security headersconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
HTTP Client misconfigured with SSL validation disabledconforme
Insecure HTTP Request detectedconforme
Insecure TLS configuration detectedconforme
Insecure usage of `requests` sends data over cleartextconforme
Insecure websocket connection sends data over cleartextconforme
Laravel cookies can be sent unencryptedconforme
Load balancer allows invalid HTTP headersconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Load Balancers only accept HTTPS connectionsconforme
NodeJS talks to database without encryptionconforme
NodeJS talks to database without encryptionconforme
Outbound Ansible connections are not encryptedconforme
Outbound Ansible connections are not encryptedconforme
Server certificates are not verified during SSL/TLS connectionsconforme
Server hostnames not verified during SSL/TLS connectionsconforme
Signature validation for dnf packages is offconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme
Storage account does not enforce HTTPS-only trafficconforme
TLS Certificate Validation Disabledconforme
TLS Certificate Validation Disabledconforme
Turning off TLS verification enables man-in-the-middle attacksconforme
Usage of deprecated or broken encryption detectedconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Using potentially unsafe FTP connections to move dataconforme
Using potentially unsafe FTP connections to move dataconforme
Weak SSL/TLS protocols usedconforme

Has measures against SQL injection attacks

ContrôleStatut
NoSQL injection attack possibleconforme
NoSQL injection attack possibleconforme
NoSQL injection attack possibleconforme
Potential NoSQL injection via string-based query concatenationconforme
Potential NoSQL injection via string-based query concatenationconforme
Potential NoSQL injection via string-based query concatenationconforme
Potential NoSQL injection via string-based query concatenationconforme
Potential SQL injection in Doctrine's QueryBuilderconforme
Potential SQL injection in sqlite3 via string-based query concatenationconforme
Potential SQL injection through JDBC via string-based query concatenationconforme
Potential SQL injection using sqflite execute sinkconforme
Potential SQL injection via Drupal database functionalityconforme
Potential SQL injection via dynamic raw query constructionconforme
Potential SQL injection via dynamic raw query constructionconforme
Potential SQL injection via dynamic raw query constructionconforme
Potential SQL injection via Laravel functionconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenationconforme
Potential SQL injection via string-based query concatenation using AuraSQL framework functionsconforme
Potential SQL injection via Yii functionconforme
Potential SQL injection when bypassing Django ORM with extra()conforme
Potential SQL injection when bypassing Django ORM with RawSQL()conforme
Potential SQL injection when bypassing Doctrine ORM with raw queryconforme

Is protected against SSRF attacks

ContrôleStatut
A timing attack might allow hackers to bruteforce passwordsconforme
EC2 IAM roles vulnerable to SSRF attacksconforme
GCP Kubernetes engine clusters vulnerable to SSRF attacksconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
HTTP request might enable SSRF attackconforme
Potential file inclusion attack via reading fileconforme
Potential file inclusion attack via reading fileconforme
Potential user input in HTTP request may allow SSRF attackconforme
Potential user input in HTTP request may allow SSRF attackconforme
Simple DOS attack possible due to http.server misconfigurationconforme
User data used in Puppeteer methods can result in SSRFconforme
User data used in Puppeteer methods can result in SSRFconforme

Prevents remote code execution

ContrôleStatut
A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input.conforme
Arbitrary Code Execution via Unsafe Clojure Deserializationconforme
Enabling NodeJS in Electron can lead to remote code executionconforme
Enabling NodeJS in Electron can lead to remote code executionconforme
Flask app debug mode may allow remote code executionconforme
Handling potential user-controlled inputs into java.lang.Runtime calls can lead to command injection.conforme
Insecure Deserialization in torch.load() leading to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
LDAP query injection may lead to data exposureconforme
LDAP query injection may lead to data exposureconforme
LDAP query injection may lead to data exposureconforme
Object deserialization can lead to remote code executionconforme
Object deserialization can lead to remote code executionconforme
Object deserialization can lead to remote code executionconforme
Object deserialization can lead to remote code executionconforme
POSIX function called with arguments that trigger Buffer Overflowconforme
Possible command injection via exec()-type functionsconforme
Possible command injection via Process.Startconforme
Possible command injection via Process.Startconforme
Possible command injection via shell scriptconforme
Possible command injection via user-controlled input to clojure.java.shell/shconforme
Potential command injection via Command APIconforme
Potential command injection via Process.runconforme
Potential file inclusion attack via reading fileconforme
Remote Code Execution possible via eval()-type functionsconforme
Remote Code Execution possible via eval()-type functionsconforme
Remote Code Execution possible via eval()-type functionsconforme
Ruby reflection via constantize may lead to remote code executionconforme
Ruby reflection via send may lead to RCEconforme
Unsafe eval usage can lead to remote code executionconforme
Unsafe eval usage can lead to remote code executionconforme
Unsafe eval usage can lead to remote code executionconforme
Unsafe eval usage can lead to remote code executionconforme
Unsafe exec usage can lead to remote code executionconforme
Unsafe exec usage can lead to remote code executionconforme
Unsafe exec usage can lead to remote code executionconforme
Unsafe subprocess usage can lead to remote code executionconforme
Unsafe yaml load can lead to remote code executionconforme
Unsafe yaml load can lead to remote code executionconforme
Unsafe yaml load can lead to remote code executionconforme
Usage of HttpInvokerServiceExporter can lead to remote code executionconforme
Use of vulnerable ingress-nginx controllerconforme
Use of vulnerable ingress-nginx controllerconforme
Using backticks in PHP can lead to remote code executionconforme
Using Marshal can lead to remote code executionconforme
Using Pickle can lead to remote code executionconforme
Using unserialize can lead to remote code executionconforme
XXE attack can lead to remote code executionconforme

Prevents XSS attacks

ContrôleStatut
Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilitiesconforme
Directly writing unsanitized input to http.ResponseWriter can lead to XSSconforme
Disabling JSON HTML Escaping in ActiveSupport may lead to XSSconforme
DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinksconforme
HttpServletResponse output can be used for XSS attacksconforme
Improper sanitization in dynamic attribute bindings can lead to XSS attacksconforme
Input validation disabled in controllerconforme
Jinja2 template config can lead to XSS attacksconforme
Potential Cross Site Scripting (XSS) via window.location.hrefconforme
Potential XSS due to enabling bypassSecurityTrustUrlconforme
Potential XSS via MarkupStr(...) in Razor template may lead to XSSconforme
Rendering unescaped input can lead to XSS attacksconforme
Rendering unescaped input can lead to XSS attacksconforme
Rendering unescaped input can lead to XSS attacksconforme
Rendering unescaped input can lead to XSS attacksconforme
Rendering unescaped input can lead to XSS attacksconforme
Rendering unescaped input can lead to XSS attacksconforme
Rendering unescaped input in EJS template can lead to XSS attacksconforme
Rendering unescaped input in handlebar/mustache template can lead to XSS attacksconforme
Rendering unescaped input in HTML template can lead to XSS attacksconforme
Unsanitized user input in jQuery DOM handling methods detectedconforme
Unsanitized user input leads to cross-site scripting (XSS)conforme
Using dangerouslySetInnerHTML in React can lead to XSS attacksconforme
Using document write methods can lead to XSS attacksconforme
Using document write methods can lead to XSS attacksconforme
Using document write methods can lead to XSS attacksconforme
Using raw on potential user input can leads to XSSconforme
Using v-html in Vue templates can lead to XSS attacksconforme

Securely stores files

ContrôleStatut
Firewall rules restrict public ingress to port 3020conforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme
Storage buckets have uniform bucket-level access enabledconforme

Properly manages the identity of cloud users

ContrôleStatut
Firewall rules restrict public ingress to port 636conforme
No user has both the Service Account User and Service Account Admin roleconforme
Service accounts have strict access permissionsconforme
Users are logging in securelyconforme
Users are only allowed to use corporate emailsconforme

Has proper access controls for cloud resources

ContrôleStatut
Access Approval is enabled for the projectconforme
API key restricts usage to certain APIsconforme
API key restricts usage to certain clientsconforme
Compute instances have OS Login enabledconforme
Compute instances have serial port access disabledconforme
GKE clusters have the Kubernetes Dashboard disabledconforme
Kubernetes pods are isolatedconforme
No instance uses the default service accountconforme
No user has both the Service Account User and Service Account Admin roleconforme
Project-wide SSH keys are blockedconforme
Service accounts have strict access permissionsconforme
Storage buckets have uniform bucket-level access enabledconforme
VM instances have strict access permissionsconforme

Prevents public access to cloud resources

ContrôleStatut
Access to BigQuery datasets are restrictedconforme
Cloud functions are not publicly accessibleconforme
Cloud functions have strict access policiesconforme
Compute instances do not have public IP addressesconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 11214conforme
Firewall rules restrict public ingress to port 11215conforme
Firewall rules restrict public ingress to port 135conforme
Firewall rules restrict public ingress to port 137conforme
Firewall rules restrict public ingress to port 138conforme
Firewall rules restrict public ingress to port 139conforme
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 3020conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 389conforme
Firewall rules restrict public ingress to port 4505conforme
Firewall rules restrict public ingress to port 4506conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 636conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 8000conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
KMS keys have strict access permissionsconforme
Kubernetes master endpoint is not publicly availableconforme
No firewall rule allows access to Open Telemtry metrics endpoint from the internetconforme
No firewall rule allows access to port 1720 from the internetconforme
No firewall rule allows cPanel access from the internetconforme
No firewall rule allows etcd access from the internetconforme
No firewall rule allows MongoDB access from the internetconforme
No firewall rule allows NFS access from the internetconforme
No firewall rule allows Telnet access from the internetconforme
No firewall rule allows Tomcat Cluster Receiver access from the internetconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme

Enabled security logging for cloud instances

ContrôleStatut
Alerting policies have a notification channel configuredconforme
Audit Configuration logging is enabledconforme
Logging and alerts are enabled for Project Ownership assignmentsconforme
Storage Permissions logging is enabledconforme
VPC Firewall has Rule logging enabledconforme

Does not have any issues outside of their SLA

ContrôleStatut
No critical issues outside of SLAconforme
No high severity issues outside of SLAconforme
No low severity issues outside of SLAconforme
No medium severity issues outside of SLAconforme

Has connected a cloud environment

ContrôleStatut
Has connected cloud environmentconforme

Has enabled threat detection

ContrôleStatut
Alerting policies have a notification channel configuredconforme

Receives security alerts in real time

ContrôleStatut
Security notifications are enabledconforme

Prevents ssh access to cloud resources from anywhere

ContrôleStatut
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme

Prevents unauthorized network access

ContrôleStatut
Access to BigQuery datasets are restrictedconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Kubernetes master endpoint is not publicly availableconforme

Has checks in place for enforcing permissions

ContrôleStatut
Access Approval is enabled for the projectconforme
Compute instances have OS Login enabledconforme
GKE clusters have the Kubernetes Dashboard disabledconforme
Kubernetes pods are isolatedconforme
No instance uses the default service accountconforme
No user has both the Service Account User and Service Account Admin roleconforme
Project-wide SSH keys are blockedconforme
Service accounts have strict access permissionsconforme
VM instances have strict access permissionsconforme

Has enabled threat detection

ContrôleStatut
Alerting policies have a notification channel configuredconforme

Prevents unwanted write operations to filesystems

ContrôleStatut
Container processes can gain more privileges than its parentconforme
Container running as root can allow attacker to escalate attacksconforme
Default Kubernetes settings allow containers to eavesdrop on traffic.conforme
Default security context allows pods to access host system.conforme
Docker container configured to run as user with root privilegesconforme
Docker container runs as default root userconforme
Filesystem for docker container should not be writeableconforme
Privileged container can allow attackers to escalate attacksconforme

Uses Lockfiles to pin code dependencies

ContrôleStatut
Usage of lockfiles in code repositoriesconforme

Prevents public access to cloud resources

ContrôleStatut
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
No firewall rule allows MongoDB access from the internetconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme

Enforces encryption of data in transit

ContrôleStatut
Cloud functions require HTTPS invocationsconforme
Cloud SQL instance requires SSL connectionsconforme
DNSSEC is enabled for all managed zonesconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
Load Balancers only accept HTTPS connectionsconforme

Requires MFA for cloud users

ContrôleStatut
Users are logging in securelyconforme

Does not have any issues outside of their SLA

ContrôleStatut
No critical SAST issues outside of SLAconforme
No high severity SAST issues outside of SLAconforme
No low severity SAST issues outside of SLAconforme
No medium severity SAST issues outside of SLAconforme

Has connected a cloud environment

ContrôleStatut
A cloud environment is connectedconforme

Has connected a code repository

ContrôleStatut
Code repositories are connectedconforme

Uses a CI integration

ContrôleStatut
The Aikido CI integration is enabledconforme

Has separate production and test environments

ContrôleStatut
No cloud environment used for mixed purposes (eg production and staging)conforme

Enforces safe SSL protocol usage

ContrôleStatut
Amazon EKS Clusters should have secrets encryption enabledconforme
API Gateway REST API caching is unencryptedconforme
API Gateway stages are not using TLS 1.2 or higherconforme
App does not validate SSL certificates properlyconforme
App uses an outdated TLS protocolconforme
App uses an outdated TLS protocolconforme
AWS ElastiCache Redis cluster should have encryption at rest enabledconforme
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Cloud functions require HTTPS invocationsconforme
Cloud SQL db not enforcing SSLconforme
Cloud SQL instance requires SSL connectionsconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme
Docker image repository not encrypted at restconforme
Elasticsearch domain is not encrypted at restconforme
Elasticsearch domain might have outdated TLS versionconforme
Ensure all data stored in the RDS is securely encrypted at restconforme
Express is not emitting security headersconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
HTTP Client misconfigured with SSL validation disabledconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure HTTP Request detectedconforme
Insecure TLS configuration detectedconforme
Insecure usage of `requests` sends data over cleartextconforme
Insecure websocket connection sends data over cleartextconforme
KMS keys have key rotation enabledconforme
Load balancer allows invalid HTTP headersconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Load Balancers only accept HTTPS connectionsconforme
NodeJS talks to database without encryptionconforme
NodeJS talks to database without encryptionconforme
Outbound Ansible connections are not encryptedconforme
Outbound Ansible connections are not encryptedconforme
Server certificates are not verified during SSL/TLS connectionsconforme
Server hostnames not verified during SSL/TLS connectionsconforme
Signature validation for dnf packages is offconforme
SNS topics are not encrypted at restconforme
SQS queue data is not encryptedconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme
Storage account does not enforce HTTPS-only trafficconforme
TLS Certificate Validation Disabledconforme
TLS Certificate Validation Disabledconforme
Turning off TLS verification enables man-in-the-middle attacksconforme
Using potentially unsafe FTP connections to move dataconforme
Using potentially unsafe FTP connections to move dataconforme
Virtual Machines have confidential computing enabledconforme
Weak SSL/TLS protocols usedconforme

Uses secure cookies

ContrôleStatut
Cookie missing HttpOnly flagconforme
Laravel cookies can be sent unencryptedconforme

Uses up-to-date cryptographic libraries

ContrôleStatut
Hashes should include an unpredictable saltconforme
Usage of deprecated or broken encryption detectedconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Using deprecated cryptographic libraryconforme

Enforces secure access for cloud users

ContrôleStatut
Cloud SQL instances have deletion protection enabledconforme
VM instances have deletion protection enabledconforme

Has proper access controls for cloud resources

ContrôleStatut
No user has both the Service Account User and Service Account Admin roleconforme
Service accounts have strict access permissionsconforme

Prevents the exposure of sensitive data

ContrôleStatut
Currently there are no exposed secretsconforme

Requires MFA for cloud users

ContrôleStatut
Users are logging in securelyconforme