Retour à Sécurité et conformité
RGPD
175 contrôles conformes sur 175
Dernière synchronisation :
Le compteur est celui produit par notre plateforme de contrôle continu Aikido Security, et le détail liste les contrôles qu’elle rapporte comme satisfaits. Les deux chiffres peuvent différer légèrement.
Les intitulés d’évaluations, de types et de contrôles sont ceux des référentiels d’origine, et sont donc en anglais.
Demander le rapport d’audit de sécurité
Enforces Multi-Factor Authentication (MFA)
| Contrôle | Statut |
|---|---|
| Users are logging in securely | conforme |
Proper Access Management for Resources
| Contrôle | Statut |
|---|---|
| Access Approval is enabled for the project | conforme |
| AKS local admin account is still enabled | conforme |
| Compute instances have OS Login enabled | conforme |
| Dangerous Impersonate permission given to ServiceAccount or node | conforme |
| GKE clusters have the Kubernetes Dashboard disabled | conforme |
| Kubernetes pods are isolated | conforme |
| No instance uses the default service account | conforme |
| No user has both the Service Account User and Service Account Admin role | conforme |
| Project-wide SSH keys are blocked | conforme |
| Service accounts have strict access permissions | conforme |
| ServiceAccount or node can read all secrets | conforme |
| VM instances have strict access permissions | conforme |
Proper Access Management for Users
| Contrôle | Statut |
|---|---|
| Users are only allowed to use corporate emails | conforme |
Proper Access Management to Resources
| Contrôle | Statut |
|---|---|
| Access to BigQuery datasets are restricted | conforme |
| AKS API server does not limit access by IP ranges | conforme |
| Amazon EKS Clusters public endpoints should not allow traffic from any IP | conforme |
| API Gateway endpoints do not require an API key or authorization | conforme |
| AWS EKS Node groups have implicit SSH access from any IP | conforme |
| Azure Cognitive Services allows unrestricted public network access | conforme |
| Azure Cosmos DB is publicly reachable | conforme |
| Azure Key Vault allows public network access | conforme |
| Azure Storage Account allow public access | conforme |
| Azure Storage blobs do not restrict public access for nested items | conforme |
| BigQuery table is anonymously or publicly accessible | conforme |
| Cloud functions are not publicly accessible | conforme |
| Cloud functions have strict access policies | conforme |
| Cloud Storage bucket does not enforce public access prevention | conforme |
| Cloud Storage bucket does not enforce uniform bucket-level access | conforme |
| Cloud Storage bucket is publicly accessible | conforme |
| Dataproc cluster is anonymously or publicly accessible | conforme |
| Default network exists in GCP project | conforme |
| Firewall rule prevents Docker API access from anywhere | conforme |
| Firewall rule prevents RDP access from anywhere | conforme |
| Firewall rule prevents SSH access from anywhere | conforme |
| Firewall rules allow RDP access from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow SSH from any public IP | conforme |
| Firewall rules allow unrestricted RDP access | conforme |
| Firewall rules allow unrestricted SSH access | conforme |
| Firewall rules do not allow unrestricted ingress to all ports and protocols | conforme |
| Firewall rules restrict public ingress to port 23 | conforme |
| Firewall rules restrict public ingress to port 2379 | conforme |
| Firewall rules restrict public ingress to port 3000 | conforme |
| Firewall rules restrict public ingress to port 5500 | conforme |
| Firewall rules restrict public ingress to port 5800 | conforme |
| Key Vault is publicly accessible | conforme |
| KMS cryptographic key policy allows public access | conforme |
| KMS keys have strict access permissions | conforme |
| Kubernetes dashboard might be deployed | conforme |
| Kubernetes master endpoint is not publicly available | conforme |
| Profiling endpoint automatically exposed on /debug/pprof | conforme |
| Pub/Sub topic is anonymously or publicly accessible | conforme |
| S3 bucket grants public access to all contents | conforme |
| S3 Buckets should have block public access globally | conforme |
| SQL instance root user has strict access permissions | conforme |
| SQL instances do not have a public IP assigned | conforme |
| SQL instances have strict access permission | conforme |
| SQL Server is publicly reachable | conforme |
| Storage Buckets have proper access rules | conforme |
| Storage buckets have public access prevention enabled | conforme |
| Vertex AI notebook instance has a public IP address | conforme |
Encryption at Rest Enabled
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces HTTPS traffic to cloud instances
| Contrôle | Statut |
|---|---|
| Cloud functions require HTTPS invocations | conforme |
| Load Balancers only accept HTTPS connections | conforme |
Runtimes are up to date
| Contrôle | Statut |
|---|---|
| AWS MQBroker version is outdated | conforme |
| GKE clusters use stable release channels with automatic upgrades | conforme |
| GKE node pools have node auto-upgrade enabled | conforme |
| No AKS cluster upgrade channel is chosen | conforme |
| No Critical End-of-Life (EOL) Issues | conforme |
| No High End-of-Life (EOL) Issues | conforme |
Use of Cryptography Libraries
| Contrôle | Statut |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Use of Cryptography: Enforces SSL
| Contrôle | Statut |
|---|---|
| Cloud SQL db not enforcing SSL | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| NodeJS talks to database without encryption | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
Use of Cryptography: Enforces TLS
| Contrôle | Statut |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Use of Cryptography: Secure Cookies
| Contrôle | Statut |
|---|---|
| Cookie missing HttpOnly flag | conforme |
| Laravel cookies can be sent unencrypted | conforme |
Backups Enabled
| Contrôle | Statut |
|---|---|
| Databases have automated backups enabled | conforme |
| DynamoDB backups are off | conforme |
Logging Enabled
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have control plane logging enabled | conforme |
| Audit Configuration logging is enabled | conforme |
| Logging and alerts are enabled for Project Ownership assignments | conforme |
| Storage Permissions logging is enabled | conforme |
| VPC Firewall has Rule logging enabled | conforme |
Threat Detection Enabled
| Contrôle | Statut |
|---|---|
| Alerting policies have a notification channel configured | conforme |
Encryption at Rest Enabled
| Contrôle | Statut |
|---|---|
| Amazon EKS Clusters should have secrets encryption enabled | conforme |
| API Gateway REST API caching is unencrypted | conforme |
| AWS ElastiCache Redis cluster should have encryption at rest enabled | conforme |
| Docker image repository not encrypted at rest | conforme |
| Elasticsearch domain is not encrypted at rest | conforme |
| Ensure all data stored in the RDS is securely encrypted at rest | conforme |
| KMS keys have key rotation enabled | conforme |
| SNS topics are not encrypted at rest | conforme |
| SQS queue data is not encrypted | conforme |
| Virtual Machines have confidential computing enabled | conforme |
Enforces HTTPS traffic to cloud instances
| Contrôle | Statut |
|---|---|
| Cloud functions require HTTPS invocations | conforme |
| Load Balancers only accept HTTPS connections | conforme |
Use of Cryptography Libraries
| Contrôle | Statut |
|---|---|
| Hashes should include an unpredictable salt | conforme |
| Usage of deprecated or broken encryption detected | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Use of broken or outdated encryption | conforme |
| Using deprecated cryptographic library | conforme |
Use of Cryptography: Enforces SSL
| Contrôle | Statut |
|---|---|
| Cloud SQL db not enforcing SSL | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| Deprecated SSL Protocol Usage Detected | conforme |
| NodeJS talks to database without encryption | conforme |
| SSL certificate verification turned off during requests | conforme |
| SSL certificate verification turned off during requests | conforme |
Use of Cryptography: Enforces TLS
| Contrôle | Statut |
|---|---|
| API Gateway stages are not using TLS 1.2 or higher | conforme |
| Azure Storage Accounts does not enforce latest TLS version | conforme |
| Elasticsearch domain might have outdated TLS version | conforme |
| Load balancer allows unencrypted or encrypted traffic with outdated TLS policy | conforme |
| Storage account does not enforce HTTPS-only traffic | conforme |
Use of Cryptography: Secure Cookies
| Contrôle | Statut |
|---|---|
| Cookie missing HttpOnly flag | conforme |
| Laravel cookies can be sent unencrypted | conforme |
