Retour à Sécurité et conformité

NIS2

148 contrôles conformes sur 148

Dernière synchronisation :

Le compteur est celui produit par notre plateforme de contrôle continu Aikido Security, et le détail liste les contrôles qu’elle rapporte comme satisfaits. Les deux chiffres peuvent différer légèrement.

Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.

Demander le rapport d’audit de sécurité

Applies the least privilege principle for cloud resource

ContrôleStatut
Access Approval is enabled for the projectconforme
Compute instances have OS Login enabledconforme
GKE clusters have the Kubernetes Dashboard disabledconforme
Kubernetes pods are isolatedconforme
No instance uses the default service accountconforme
No user has both the Service Account User and Service Account Admin roleconforme
Project-wide SSH keys are blockedconforme
Service accounts have strict access permissionsconforme
VM instances have strict access permissionsconforme

Applies the least privilege principle for cloud users

ContrôleStatut
Firewall rules restrict public ingress to port 636conforme
Users are logging in securelyconforme
Users are only allowed to use corporate emailsconforme

Applies the least privilege principle to cloud resources

ContrôleStatut
Access to BigQuery datasets are restrictedconforme
Cloud functions are not publicly accessibleconforme
Cloud functions have strict access policiesconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rule prevents RDP access from anywhereconforme
Firewall rule prevents SSH access from anywhereconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
KMS keys have strict access permissionsconforme
Kubernetes master endpoint is not publicly availableconforme
SQL instance root user has strict access permissionsconforme
SQL instances do not have a public IP assignedconforme
SQL instances have strict access permissionconforme
Storage Buckets have proper access rulesconforme
Storage buckets have public access prevention enabledconforme

Has backups for stateful cloud resources

ContrôleStatut
Databases have automated backups enabledconforme

Configured SLAs to resolve issues

ContrôleStatut
Configure SLAsconforme

Tracks progress via an issue tracker

ContrôleStatut
Integration with issue tracker enabledconforme

Configured monitoring for code repositories

ContrôleStatut
Configured monitoring for all code repositoriesconforme

Configured monitoring for container images

ContrôleStatut
Configured monitoring for cloud environmentconforme

Configured monitoring for public facing domains

ContrôleStatut
Configured monitoring for public facing domainsconforme

Has configured exposure for repositories

ContrôleStatut
Has configured exposure for resourcesconforme

Has measurements against unauthorized network access

ContrôleStatut
Access to BigQuery datasets are restrictedconforme
Firewall rule prevents Docker API access from anywhereconforme
Firewall rules do not allow unrestricted ingress to all ports and protocolsconforme
Firewall rules restrict public ingress to port 23conforme
Firewall rules restrict public ingress to port 2379conforme
Firewall rules restrict public ingress to port 3000conforme
Firewall rules restrict public ingress to port 5500conforme
Firewall rules restrict public ingress to port 5800conforme
Kubernetes master endpoint is not publicly availableconforme

Has separate production and test environments

ContrôleStatut
No cloud environment used for mixed purposes (eg production and staging)conforme

Uses firewalls

ContrôleStatut
Firewall rules restrict public ingress to port 11214conforme
Firewall rules restrict public ingress to port 11215conforme
Firewall rules restrict public ingress to port 135conforme
Firewall rules restrict public ingress to port 137conforme
Firewall rules restrict public ingress to port 138conforme
Firewall rules restrict public ingress to port 139conforme
Firewall rules restrict public ingress to port 1433conforme
Firewall rules restrict public ingress to port 1434conforme
Firewall rules restrict public ingress to port 2383conforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 27017conforme
Firewall rules restrict public ingress to port 27018conforme
Firewall rules restrict public ingress to port 27019conforme
Firewall rules restrict public ingress to port 3020conforme
Firewall rules restrict public ingress to port 3306conforme
Firewall rules restrict public ingress to port 389conforme
Firewall rules restrict public ingress to port 4505conforme
Firewall rules restrict public ingress to port 4506conforme
Firewall rules restrict public ingress to port 61621conforme
Firewall rules restrict public ingress to port 636conforme
Firewall rules restrict public ingress to port 7001conforme
Firewall rules restrict public ingress to port 8000conforme
Firewall rules restrict public ingress to port 9200conforme
Firewall rules restrict public ingress to port 9300conforme
No firewall rule allows access to Open Telemtry metrics endpoint from the internetconforme
No firewall rule allows access to port 1720 from the internetconforme
No firewall rule allows cPanel access from the internetconforme
No firewall rule allows etcd access from the internetconforme
No firewall rule allows MongoDB access from the internetconforme
No firewall rule allows NFS access from the internetconforme
No firewall rule allows Telnet access from the internetconforme
No firewall rule allows Tomcat Cluster Receiver access from the internetconforme

No issues outside of sla

ContrôleStatut
No issues outside of slaconforme

Uses Lockfiles to pin code dependencies

ContrôleStatut
Use lockfiles in reposconforme

Enforces safe SSL protocol usage

ContrôleStatut
Amazon EKS Clusters should have secrets encryption enabledconforme
API Gateway REST API caching is unencryptedconforme
API Gateway stages are not using TLS 1.2 or higherconforme
App does not validate SSL certificates properlyconforme
App uses an outdated TLS protocolconforme
App uses an outdated TLS protocolconforme
AWS ElastiCache Redis cluster should have encryption at rest enabledconforme
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Network Security Rule allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Account allows plaintext HTTP connectionsconforme
Azure Storage Accounts does not enforce latest TLS versionconforme
Cloud functions require HTTPS invocationsconforme
Cloud SQL db not enforcing SSLconforme
Cloud SQL instance requires SSL connectionsconforme
Deprecated SSL Protocol Usage Detectedconforme
Deprecated SSL Protocol Usage Detectedconforme
DNSSEC is disabledconforme
DNSSEC is enabled for all managed zonesconforme
Docker image repository not encrypted at restconforme
Elasticsearch domain is not encrypted at restconforme
Elasticsearch domain might have outdated TLS versionconforme
Ensure all data stored in the RDS is securely encrypted at restconforme
Express is not emitting security headersconforme
Firewall rules restrict public ingress to port 2484conforme
Firewall rules restrict public ingress to port 636conforme
HTTP Client misconfigured with SSL validation disabledconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure gRPC connection can lead to remote code executionconforme
Insecure HTTP Request detectedconforme
Insecure TLS configuration detectedconforme
Insecure usage of `requests` sends data over cleartextconforme
Insecure websocket connection sends data over cleartextconforme
KMS keys have key rotation enabledconforme
Load balancer allows invalid HTTP headersconforme
Load balancer allows unencrypted or encrypted traffic with outdated TLS policyconforme
Load Balancers only accept HTTPS connectionsconforme
NodeJS talks to database without encryptionconforme
NodeJS talks to database without encryptionconforme
Outbound Ansible connections are not encryptedconforme
Outbound Ansible connections are not encryptedconforme
Server certificates are not verified during SSL/TLS connectionsconforme
Server hostnames not verified during SSL/TLS connectionsconforme
Signature validation for dnf packages is offconforme
SNS topics are not encrypted at restconforme
SQS queue data is not encryptedconforme
SSL certificate verification turned off during requestsconforme
SSL certificate verification turned off during requestsconforme
Storage account does not enforce HTTPS-only trafficconforme
TLS Certificate Validation Disabledconforme
TLS Certificate Validation Disabledconforme
Turning off TLS verification enables man-in-the-middle attacksconforme
Using potentially unsafe FTP connections to move dataconforme
Using potentially unsafe FTP connections to move dataconforme
Virtual Machines have confidential computing enabledconforme
Weak SSL/TLS protocols usedconforme

Uses secure cookies

ContrôleStatut
Cookie missing HttpOnly flagconforme
Laravel cookies can be sent unencryptedconforme

Uses up-to-date cryptographic libraries

ContrôleStatut
Hashes should include an unpredictable saltconforme
Usage of deprecated or broken encryption detectedconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Use of broken or outdated encryptionconforme
Using deprecated cryptographic libraryconforme

Requires MFA for cloud users

ContrôleStatut
Users are logging in securelyconforme