Retour à Sécurité et conformité
NIS2
148 contrôles conformes sur 148
Dernière synchronisation :
Le compteur est celui produit par notre plateforme de contrôle continu Aikido Security, et le détail liste les contrôles qu’elle rapporte comme satisfaits. Les deux chiffres peuvent différer légèrement.
Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.
Demander le rapport d’audit de sécurité
Applies the least privilege principle for cloud resource
| Contrôle | Statut |
|---|---|
| Access Approval is enabled for the project | conforme |
| Compute instances have OS Login enabled | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| VM instances have strict access permissions | conforme |
Applies the least privilege principle for cloud users
| Contrôle | Statut |
|---|---|
| Firewall rules restrict public ingress to port 636 | conforme |
| Users are logging in securely | conforme |
| Users are only allowed to use corporate emails | conforme |
Applies the least privilege principle to cloud resources
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
Has backups for stateful cloud resources
| Contrôle | Statut |
|---|---|
| Databases have automated backups enabled | conforme |
Configured SLAs to resolve issues
| Contrôle | Statut |
|---|---|
| Configure SLAs | conforme |
Tracks progress via an issue tracker
| Contrôle | Statut |
|---|---|
| Integration with issue tracker enabled | conforme |
Configured monitoring for code repositories
| Contrôle | Statut |
|---|---|
| Configured monitoring for all code repositories | conforme |
Configured monitoring for container images
| Contrôle | Statut |
|---|---|
| Configured monitoring for cloud environment | conforme |
Configured monitoring for public facing domains
| Contrôle | Statut |
|---|---|
| Configured monitoring for public facing domains | conforme |
Has configured exposure for repositories
| Contrôle | Statut |
|---|---|
| Has configured exposure for resources | conforme |
Has measurements against unauthorized network access
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
Has separate production and test environments
| Contrôle | Statut |
|---|---|
| No cloud environment used for mixed purposes (eg production and staging) | conforme |
Uses firewalls
| Contrôle | Statut |
|---|---|
| Firewall rules restrict public ingress to port 11214 | conforme |
| Firewall rules restrict public ingress to port 11215 | conforme |
| Firewall rules restrict public ingress to port 135 | conforme |
| Firewall rules restrict public ingress to port 137 | conforme |
| Firewall rules restrict public ingress to port 138 | conforme |
| Firewall rules restrict public ingress to port 139 | conforme |
| Firewall rules restrict public ingress to port 1433 | conforme |
| Firewall rules restrict public ingress to port 1434 | conforme |
| Firewall rules restrict public ingress to port 2383 | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 27017 | conforme |
| Firewall rules restrict public ingress to port 27018 | conforme |
| Firewall rules restrict public ingress to port 27019 | conforme |
| Firewall rules restrict public ingress to port 3020 | conforme |
| Firewall rules restrict public ingress to port 3306 | conforme |
| Firewall rules restrict public ingress to port 389 | conforme |
| Firewall rules restrict public ingress to port 4505 | conforme |
| Firewall rules restrict public ingress to port 4506 | conforme |
| Firewall rules restrict public ingress to port 61621 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| Firewall rules restrict public ingress to port 7001 | conforme |
| Firewall rules restrict public ingress to port 8000 | conforme |
| Firewall rules restrict public ingress to port 9200 | conforme |
| Firewall rules restrict public ingress to port 9300 | conforme |
| No firewall rule allows access to Open Telemtry metrics endpoint from the internet | conforme |
| No firewall rule allows access to port 1720 from the internet | conforme |
| No firewall rule allows cPanel access from the internet | conforme |
| No firewall rule allows etcd access from the internet | conforme |
| No firewall rule allows MongoDB access from the internet | conforme |
| No firewall rule allows NFS access from the internet | conforme |
| No firewall rule allows Telnet access from the internet | conforme |
| No firewall rule allows Tomcat Cluster Receiver access from the internet | conforme |
No issues outside of sla
| Contrôle | Statut |
|---|---|
| No issues outside of sla | conforme |
Uses Lockfiles to pin code dependencies
| Contrôle | Statut |
|---|---|
| Use lockfiles in repos | conforme |
Enforces safe SSL protocol usage
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| App does not validate SSL certificates properly | conforme |
| App uses an outdated TLS protocol | conforme |
| App uses an outdated TLS protocol | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTH | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Network Security Rule allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Account allows plaintext HTTP connections | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Cloud functions require HTTPS invocations | conforme |
| Cloud SQL db not enforcing SSL | conforme |
| Cloud SQL instance requires SSL connections | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| DNSSEC is disabled | conforme |
| DNSSEC is enabled for all managed zones | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| Express is not emitting security headers | conforme |
| Firewall rules restrict public ingress to port 2484 | conforme |
| Firewall rules restrict public ingress to port 636 | conforme |
| HTTP Client misconfigured with SSL validation disabled | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure gRPC connection can lead to remote code execution | conforme |
| Insecure HTTP Request detected | conforme |
| Insecure TLS configuration detected | conforme |
| Insecure usage of `requests` sends data over cleartext | conforme |
| Insecure websocket connection sends data over cleartext | conforme |
| KMS keys have key rotation enabled | conforme |
| Load balancer allows invalid HTTP headers | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Load Balancers only accept HTTPS connections | conforme |
| NodeJS talks to database without encryption | conforme |
| NodeJS talks to database without encryption | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Outbound Ansible connections are not encrypted | conforme |
| Server certificates are not verified during SSL/TLS connections | conforme |
| Server hostnames not verified during SSL/TLS connections | conforme |
| Signature validation for dnf packages is off | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
| TLS Certificate Validation Disabled | conforme |
| TLS Certificate Validation Disabled | conforme |
| Turning off TLS verification enables man-in-the-middle attacks | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Using potentially unsafe FTP connections to move data | conforme |
| Virtual Machines have confidential computing enabled | conforme |
| Weak SSL/TLS protocols used | conforme |
Uses secure cookies
| Contrôle | Statut |
|---|---|
| Cookie missing HttpOnly flag | conforme |
| Laravel cookies can be sent unencrypted | conforme |
Uses up-to-date cryptographic libraries
| Contrôle | Statut |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Requires MFA for cloud users
| Contrôle | Statut |
|---|---|
| Users are logging in securely | conforme |
