1---2name: infrastructure-compliance-auditor3description: Cross-cutting infrastructure security audit skill that checks cloud infrastructure, DNS, TLS, endpoints, access control, network security, containers, CI/CD pipelines, secrets management, logging, and physical security against ALL major compliance frameworks. Use for infrastructure audit, cloud security audit, infrastructure compliance, DNS security audit, TLS audit, endpoint security, access control audit, network security assessment, infrastructure security, cloud compliance, Vanta alternative, compliance automation, security posture assessment, hardware security keys, YubiKey compliance.4license: MIT + Commons Clause5---6# Infrastructure Compliance Auditor
7
8Cross-cutting infrastructure security audit across ALL compliance frameworks. Replaces manual Vanta-style checks with deterministic, repeatable, evidence-generating infrastructure audits covering cloud, DNS, TLS, endpoints, access control, network, containers, CI/CD, secrets, logging, and physical security.
9
10---
11
12## Table of Contents
13
14- [Trigger Phrases](#trigger-phrases)
15- [Quick Start](#quick-start)
16- [Tools](#tools)
17- [Audit Domains](#audit-domains)
18 - [1. Cloud Infrastructure Security](#1-cloud-infrastructure-security)
19 - [2. DNS Security](#2-dns-security)
20 - [3. TLS/SSL Security](#3-tlsssl-security)
21 - [4. Endpoint Security](#4-endpoint-security)
22 - [5. Access Control and Authentication](#5-access-control-and-authentication)
23 - [6. Network Security](#6-network-security)
24 - [7. Container and Kubernetes Security](#7-container-and-kubernetes-security)
25 - [8. CI/CD Pipeline Security](#8-cicd-pipeline-security)
26 - [9. Secrets Management](#9-secrets-management)
27 - [10. Logging and Monitoring](#10-logging-and-monitoring)
28 - [11. Physical Security](#11-physical-security)
29 - [12. Compliance Framework Mapping](#12-compliance-framework-mapping)
30- [Workflows](#workflows)
31- [Reference Guides](#reference-guides)
32- [Validation Checkpoints](#validation-checkpoints)
33- [Scoring Methodology](#scoring-methodology)
34
35---
36
37## Trigger Phrases
38
39Use this skill when you hear:
40- "infrastructure audit"
41- "cloud security audit"
42- "infrastructure compliance"
43- "DNS security audit"
44- "TLS audit"
45- "endpoint security"
46- "access control audit"
47- "network security assessment"
48- "infrastructure security"
49- "cloud compliance"
50- "Vanta alternative"
51- "compliance automation"
52- "security posture assessment"
53- "hardware security keys"
54- "YubiKey compliance"
55
56---
57
58## Quick Start
59
60### Run Full Infrastructure Audit
61
62```bash
63python scripts/infra_audit_runner.py --config infrastructure.json --output audit_report.json
64```
65
66### Audit DNS Security for a Domain
67
68```bash
69python scripts/dns_security_checker.py --domain example.com --output dns_report.json
70```
71
72### Audit Access Controls
73
74```bash
75python scripts/access_control_auditor.py --config access_controls.json --output access_report.json
76```
77
78### Generate Compliance-Mapped Report
79
80```bash
81python scripts/infra_audit_runner.py --config infrastructure.json --frameworks soc2,iso27001,hipaa --format markdown --output compliance_report.md
82```
83
84---
85
86## Tools
87
88| Tool | Purpose | Input |
89|------|---------|-------|
90| `infra_audit_runner.py` | Full infrastructure audit across all 11 domains | JSON config describing infrastructure |
91| `dns_security_checker.py` | DNS-specific security audit (SPF, DKIM, DMARC, DNSSEC, CAA, MTA-STS) | Domain name |
92| `access_control_auditor.py` | Access control, MFA, SSO, PAM, RBAC audit | JSON config describing access controls |
93
94---
95
96## Audit Domains
97
98### 1. Cloud Infrastructure Security
99
100#### AWS Security Audit Checklist
101
102**IAM Policies and Roles**
103
104| Check ID | Control | Severity | Frameworks |
105|----------|---------|----------|------------|
106| AWS-IAM-001 | Root account has MFA enabled (hardware MFA preferred) | Critical | SOC 2 CC6.1, ISO 27001 A.9.2.1, PCI-DSS 8.3, NIST CSF PR.AC-1, HIPAA 164.312(d), FedRAMP AC-2 |
107| AWS-IAM-002 | Root account has no access keys | Critical | SOC 2 CC6.1, ISO 27001 A.9.2.3, PCI-DSS 2.1, NIST CSF PR.AC-4 |
108| AWS-IAM-003 | No IAM policies with `"Effect": "Allow", "Action": "*", "Resource": "*"` | Critical | SOC 2 CC6.3, ISO 27001 A.9.4.1, PCI-DSS 7.1, NIST CSF PR.AC-4 |
109| AWS-IAM-004 | All IAM users have MFA enabled | High | SOC 2 CC6.1, ISO 27001 A.9.4.2, PCI-DSS 8.3, HIPAA 164.312(d) |
110| AWS-IAM-005 | IAM password policy enforces minimum 14 characters | Medium | SOC 2 CC6.1, ISO 27001 A.9.4.3, PCI-DSS 8.2.3, NIST CSF PR.AC-1 |
111| AWS-IAM-006 | IAM roles use external ID for cross-account access | Medium | SOC 2 CC6.3, ISO 27001 A.9.2.1 |
112| AWS-IAM-007 | Unused IAM credentials (>90 days) are disabled | Medium | SOC 2 CC6.2, ISO 27001 A.9.2.6, PCI-DSS 8.1.4 |
113| AWS-IAM-008 | IAM Access Analyzer is enabled in all regions | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.5 |
114| AWS-IAM-009 | No inline IAM policies (use managed policies) | Low | ISO 27001 A.9.2.2 |
115| AWS-IAM-010 | IAM policy conditions restrict by source IP or VPC where possible | Low | SOC 2 CC6.6, NIST CSF PR.AC-3 |
116
117**S3 Bucket Security**
118
119| Check ID | Control | Severity | Frameworks |
120|----------|---------|----------|------------|
121| AWS-S3-001 | S3 Block Public Access enabled at account level | Critical | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.3, HIPAA 164.312(e)(1), GDPR Art.32 |
122| AWS-S3-002 | No S3 buckets with public ACLs or policies | Critical | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.3, HIPAA 164.312(e)(1) |
123| AWS-S3-003 | Server-side encryption enabled (SSE-S3 minimum, SSE-KMS preferred) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 3.4, HIPAA 164.312(a)(2)(iv), GDPR Art.32 |
124| AWS-S3-004 | Versioning enabled on critical data buckets | Medium | SOC 2 CC6.7, ISO 27001 A.12.3.1 |
125| AWS-S3-005 | Access logging enabled for all buckets | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1, PCI-DSS 10.2 |
126| AWS-S3-006 | Lifecycle policies configured for log retention | Low | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
127| AWS-S3-007 | MFA Delete enabled for critical buckets | Medium | SOC 2 CC6.7, ISO 27001 A.12.3.1 |
128| AWS-S3-008 | S3 Object Lock enabled for compliance data (WORM) | Medium | SEC Rule 17a-4, HIPAA 164.312(c)(1) |
129
130**VPC Configuration**
131
132| Check ID | Control | Severity | Frameworks |
133|----------|---------|----------|------------|
134| AWS-VPC-001 | VPC Flow Logs enabled for all VPCs | High | SOC 2 CC7.2, ISO 27001 A.12.4.1, PCI-DSS 10.2, NIST CSF DE.CM-1 |
135| AWS-VPC-002 | Default security group restricts all inbound/outbound | High | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.2 |
136| AWS-VPC-003 | No security groups allow 0.0.0.0/0 on SSH (22) or RDP (3389) | Critical | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.3, NIST CSF PR.AC-5 |
137| AWS-VPC-004 | Private subnets used for databases and application tiers | High | SOC 2 CC6.6, ISO 27001 A.13.1.3, PCI-DSS 1.3 |
138| AWS-VPC-005 | NACLs configured as additional defense layer | Medium | SOC 2 CC6.6, PCI-DSS 1.2 |
139| AWS-VPC-006 | VPC endpoints used for AWS service access (avoid public internet) | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
140| AWS-VPC-007 | Transit Gateway or VPC Peering uses non-overlapping CIDRs | Low | ISO 27001 A.13.1.1 |
141
142**RDS Security**
143
144| Check ID | Control | Severity | Frameworks |
145|----------|---------|----------|------------|
146| AWS-RDS-001 | Encryption at rest enabled (KMS) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 3.4, HIPAA 164.312(a)(2)(iv) |
147| AWS-RDS-002 | SSL/TLS connections enforced (`rds.force_ssl = 1`) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 4.1 |
148| AWS-RDS-003 | Automated backups enabled with minimum 7-day retention | Medium | SOC 2 CC6.7, ISO 27001 A.12.3.1, HIPAA 164.308(a)(7)(ii)(A) |
149| AWS-RDS-004 | Multi-AZ deployment for production databases | Medium | SOC 2 A1.2, ISO 27001 A.17.1.1 |
150| AWS-RDS-005 | Database instances not publicly accessible | Critical | SOC 2 CC6.6, PCI-DSS 1.3 |
151| AWS-RDS-006 | Enhanced monitoring enabled | Low | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
152| AWS-RDS-007 | Deletion protection enabled for production instances | Medium | SOC 2 CC6.7 |
153
154**CloudTrail and Monitoring**
155
156| Check ID | Control | Severity | Frameworks |
157|----------|---------|----------|------------|
158| AWS-CT-001 | CloudTrail enabled in all regions | Critical | SOC 2 CC7.2, ISO 27001 A.12.4.1, PCI-DSS 10.1, HIPAA 164.312(b), NIST CSF DE.CM-1, FedRAMP AU-2 |
159| AWS-CT-002 | CloudTrail log file validation enabled | High | SOC 2 CC7.2, ISO 27001 A.12.4.3, PCI-DSS 10.5 |
160| AWS-CT-003 | CloudTrail logs delivered to S3 with encryption | High | SOC 2 CC7.2, ISO 27001 A.12.4.1, PCI-DSS 10.5 |
161| AWS-CT-004 | CloudTrail integrated with CloudWatch Logs | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
162| AWS-CT-005 | GuardDuty enabled in all regions | High | SOC 2 CC7.2, NIST CSF DE.CM-1 |
163| AWS-CT-006 | Security Hub enabled with CIS AWS Foundations Benchmark | Medium | SOC 2 CC7.2, NIST CSF DE.CM-1 |
164| AWS-CT-007 | AWS Config enabled with required rules | High | SOC 2 CC7.2, ISO 27001 A.12.4.1, NIST CSF DE.CM-1, FedRAMP CM-8 |
165
166**KMS and Encryption**
167
168| Check ID | Control | Severity | Frameworks |
169|----------|---------|----------|------------|
170| AWS-KMS-001 | Customer-managed KMS keys used for sensitive data | High | SOC 2 CC6.7, ISO 27001 A.10.1.2, PCI-DSS 3.5 |
171| AWS-KMS-002 | KMS key rotation enabled (annual automatic rotation) | Medium | SOC 2 CC6.7, ISO 27001 A.10.1.2, PCI-DSS 3.6.4 |
172| AWS-KMS-003 | KMS key policies follow least privilege | Medium | SOC 2 CC6.3, ISO 27001 A.10.1.2 |
173| AWS-KMS-004 | KMS keys have alias and description for identification | Low | ISO 27001 A.10.1.2 |
174
175**Lambda and Serverless Security**
176
177| Check ID | Control | Severity | Frameworks |
178|----------|---------|----------|------------|
179| AWS-LAM-001 | Lambda functions use IAM roles with least privilege | High | SOC 2 CC6.3, ISO 27001 A.9.4.1 |
180| AWS-LAM-002 | Lambda functions do not store secrets in environment variables (use Secrets Manager) | High | SOC 2 CC6.7, PCI-DSS 3.4 |
181| AWS-LAM-003 | Lambda functions deployed in VPC when accessing private resources | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
182| AWS-LAM-004 | Lambda function code is signed | Medium | SOC 2 CC7.1 |
183| AWS-LAM-005 | Dead letter queues configured for async invocations | Low | SOC 2 A1.2 |
184
185**EKS/ECS Container Security**
186
187| Check ID | Control | Severity | Frameworks |
188|----------|---------|----------|------------|
189| AWS-EKS-001 | EKS cluster endpoint not publicly accessible (or restricted by CIDR) | High | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
190| AWS-EKS-002 | EKS control plane logging enabled (api, audit, authenticator) | High | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
191| AWS-EKS-003 | EKS managed node groups use latest AMI | Medium | SOC 2 CC7.1 |
192| AWS-EKS-004 | ECS tasks use awsvpc networking mode | Medium | SOC 2 CC6.6 |
193| AWS-EKS-005 | ECR image scanning enabled on push | High | SOC 2 CC7.1, NIST CSF PR.IP-12 |
194
195#### Azure Security Audit Checklist
196
197**Azure AD / Entra ID**
198
199| Check ID | Control | Severity | Frameworks |
200|----------|---------|----------|------------|
201| AZ-AD-001 | Global Administrator accounts have MFA enforced | Critical | SOC 2 CC6.1, ISO 27001 A.9.2.1, PCI-DSS 8.3 |
202| AZ-AD-002 | Maximum 5 Global Administrator accounts | High | SOC 2 CC6.1, ISO 27001 A.9.2.3 |
203| AZ-AD-003 | Conditional Access Policies configured | High | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
204| AZ-AD-004 | Security Defaults enabled (if no Conditional Access) | High | SOC 2 CC6.1 |
205| AZ-AD-005 | Privileged Identity Management (PIM) enabled for admin roles | High | SOC 2 CC6.1, ISO 27001 A.9.2.3 |
206| AZ-AD-006 | Guest user access restricted | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.2 |
207| AZ-AD-007 | Sign-in risk policy configured (requires P2) | Medium | SOC 2 CC6.1 |
208
209**Azure Network Security**
210
211| Check ID | Control | Severity | Frameworks |
212|----------|---------|----------|------------|
213| AZ-NET-001 | NSG rules follow least privilege (no allow-all inbound) | High | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.2 |
214| AZ-NET-002 | Azure Firewall or third-party NVA deployed | Medium | SOC 2 CC6.6, PCI-DSS 1.1 |
215| AZ-NET-003 | DDoS Protection Standard enabled for public IPs | Medium | SOC 2 A1.2, ISO 27001 A.13.1.1 |
216| AZ-NET-004 | Private endpoints used for PaaS services | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
217| AZ-NET-005 | Network Watcher enabled in all regions | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
218
219**Azure Key Vault**
220
221| Check ID | Control | Severity | Frameworks |
222|----------|---------|----------|------------|
223| AZ-KV-001 | Key Vault uses RBAC (not legacy access policies) | High | SOC 2 CC6.3, ISO 27001 A.10.1.2 |
224| AZ-KV-002 | Soft delete and purge protection enabled | High | SOC 2 CC6.7, ISO 27001 A.10.1.2 |
225| AZ-KV-003 | Key Vault diagnostic logging enabled | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
226| AZ-KV-004 | Key rotation policy configured | Medium | SOC 2 CC6.7, PCI-DSS 3.6.4 |
227| AZ-KV-005 | Key Vault firewall enabled (restrict to VNet/IP) | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
228
229**Azure Monitoring**
230
231| Check ID | Control | Severity | Frameworks |
232|----------|---------|----------|------------|
233| AZ-MON-001 | Azure Monitor activity log alerts configured | High | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
234| AZ-MON-002 | Microsoft Sentinel (SIEM) deployed | Medium | SOC 2 CC7.2, NIST CSF DE.AE-2 |
235| AZ-MON-003 | Diagnostic settings enabled for all resources | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
236| AZ-MON-004 | Azure Policy assignments enforcing compliance | High | SOC 2 CC7.1, ISO 27001 A.18.2.2 |
237| AZ-MON-005 | Microsoft Defender for Cloud enabled (all plans) | High | SOC 2 CC7.2, NIST CSF DE.CM-1 |
238
239**Azure Storage Security**
240
241| Check ID | Control | Severity | Frameworks |
242|----------|---------|----------|------------|
243| AZ-ST-001 | Storage accounts require HTTPS transfer | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 4.1 |
244| AZ-ST-002 | Storage account public access disabled | Critical | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
245| AZ-ST-003 | Storage accounts use customer-managed keys | Medium | SOC 2 CC6.7, PCI-DSS 3.5 |
246| AZ-ST-004 | Shared Access Signatures (SAS) use short expiry | Medium | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
247
248**AKS Security**
249
250| Check ID | Control | Severity | Frameworks |
251|----------|---------|----------|------------|
252| AZ-AKS-001 | AKS uses managed identity (not service principal) | High | SOC 2 CC6.1, ISO 27001 A.9.4.1 |
253| AZ-AKS-002 | Azure Policy for AKS enabled | Medium | SOC 2 CC7.1 |
254| AZ-AKS-003 | AKS API server authorized IP ranges configured | High | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
255| AZ-AKS-004 | AKS uses Azure CNI (not kubenet) for network policies | Medium | SOC 2 CC6.6 |
256
257#### GCP Security Audit Checklist
258
259**GCP IAM and Service Accounts**
260
261| Check ID | Control | Severity | Frameworks |
262|----------|---------|----------|------------|
263| GCP-IAM-001 | Organization-level IAM policies use groups, not individual users | High | SOC 2 CC6.1, ISO 27001 A.9.2.2 |
264| GCP-IAM-002 | Service accounts do not have Owner/Editor roles | Critical | SOC 2 CC6.3, ISO 27001 A.9.4.1 |
265| GCP-IAM-003 | User-managed service account keys rotate every 90 days | High | SOC 2 CC6.1, PCI-DSS 3.6.4 |
266| GCP-IAM-004 | Domain-restricted sharing enabled via Organization Policy | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.2 |
267| GCP-IAM-005 | Workload Identity used for GKE (no service account keys) | High | SOC 2 CC6.1, ISO 27001 A.9.4.1 |
268
269**GCP VPC and Network**
270
271| Check ID | Control | Severity | Frameworks |
272|----------|---------|----------|------------|
273| GCP-VPC-001 | VPC Service Controls configured for sensitive projects | High | SOC 2 CC6.6, ISO 27001 A.13.1.3 |
274| GCP-VPC-002 | Cloud Armor WAF rules protect public-facing services | High | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
275| GCP-VPC-003 | VPC Flow Logs enabled for all subnets | High | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
276| GCP-VPC-004 | Private Google Access enabled for private subnets | Medium | SOC 2 CC6.6 |
277| GCP-VPC-005 | Firewall rules do not allow 0.0.0.0/0 on SSH/RDP | Critical | SOC 2 CC6.6, PCI-DSS 1.3 |
278
279**GCP Security Services**
280
281| Check ID | Control | Severity | Frameworks |
282|----------|---------|----------|------------|
283| GCP-SEC-001 | Security Command Center (SCC) enabled (Premium) | High | SOC 2 CC7.2, NIST CSF DE.CM-1 |
284| GCP-SEC-002 | Cloud KMS keys have rotation scheduled | Medium | SOC 2 CC6.7, PCI-DSS 3.6.4 |
285| GCP-SEC-003 | Cloud Audit Logs enabled for all services | High | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
286| GCP-SEC-004 | Binary Authorization enabled for GKE | Medium | SOC 2 CC7.1 |
287| GCP-SEC-005 | Organization Policy Service enforces constraints | High | SOC 2 CC7.1, ISO 27001 A.18.2.2 |
288
289**GKE Security**
290
291| Check ID | Control | Severity | Frameworks |
292|----------|---------|----------|------------|
293| GCP-GKE-001 | GKE uses private cluster (no public endpoint) or authorized networks | High | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
294| GCP-GKE-002 | GKE Shielded Nodes enabled | Medium | SOC 2 CC6.7 |
295| GCP-GKE-003 | GKE node auto-upgrade enabled | Medium | SOC 2 CC7.1, NIST CSF PR.IP-12 |
296| GCP-GKE-004 | GKE workload identity enabled (no node service account keys) | High | SOC 2 CC6.1 |
297| GCP-GKE-005 | Container-Optimized OS used for nodes | Medium | SOC 2 CC7.1 |
298
299---
300
301### 2. DNS Security
302
303#### Email Authentication Chain
304
305SPF, DKIM, and DMARC form a layered email authentication system. ALL three must be configured correctly for effective protection against spoofing and phishing.
306
307**SPF (Sender Policy Framework)**
308
309| Check ID | Control | Severity | Frameworks |
310|----------|---------|----------|------------|
311| DNS-SPF-001 | SPF record exists for primary domain | High | SOC 2 CC6.6, ISO 27001 A.13.2.1, NIST CSF PR.AC-3 |
312| DNS-SPF-002 | SPF record uses `-all` (hard fail) not `~all` (soft fail) | High | SOC 2 CC6.6, ISO 27001 A.13.2.1 |
313| DNS-SPF-003 | SPF record has fewer than 10 DNS lookups (RFC 7208 limit) | Medium | SOC 2 CC6.6 |
314| DNS-SPF-004 | SPF record does not use `+all` (permits all senders) | Critical | SOC 2 CC6.6, ISO 27001 A.13.2.1 |
315| DNS-SPF-005 | Non-sending domains have `v=spf1 -all` to prevent spoofing | Medium | ISO 27001 A.13.2.1 |
316| DNS-SPF-006 | SPF record avoids deprecated PTR mechanism | Low | RFC 7208 |
317| DNS-SPF-007 | SPF flattening used if approaching lookup limit | Low | Best practice |
318
319SPF syntax reference:
320```
321v=spf1 include:_spf.google.com include:sendgrid.net ip4:203.0.113.0/24 -all
322```
323
324**Key rules:**
325- Maximum 10 DNS lookups (include, a, mx, ptr, exists, redirect each count as 1)
326- `ip4` and `ip6` mechanisms do NOT count toward the 10-lookup limit
327- Nested includes count toward the limit
328- Record must be a single TXT record (no multiple SPF records)
329- Maximum 255 characters per DNS string (use string concatenation for longer records)
330
331**DKIM (DomainKeys Identified Mail)**
332
333| Check ID | Control | Severity | Frameworks |
334|----------|---------|----------|------------|
335| DNS-DKIM-001 | DKIM record exists for all sending domains | High | SOC 2 CC6.6, ISO 27001 A.13.2.1 |
336| DNS-DKIM-002 | DKIM key is minimum 2048-bit RSA | High | SOC 2 CC6.7, ISO 27001 A.10.1.1 |
337| DNS-DKIM-003 | DKIM keys rotate every 6-12 months | Medium | SOC 2 CC6.7, ISO 27001 A.10.1.2 |
338| DNS-DKIM-004 | Multiple DKIM selectors for different sending services | Low | Best practice |
339| DNS-DKIM-005 | DKIM testing mode (`t=y`) removed for production domains | Medium | SOC 2 CC6.6 |
340
341DKIM record format:
342```
343selector._domainkey.example.com IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
344```
345
346**DMARC (Domain-based Message Authentication, Reporting, and Conformance)**
347
348| Check ID | Control | Severity | Frameworks |
349|----------|---------|----------|------------|
350| DNS-DMARC-001 | DMARC record exists at `_dmarc.example.com` | High | SOC 2 CC6.6, ISO 27001 A.13.2.1, NIST CSF PR.AC-3 |
351| DNS-DMARC-002 | DMARC policy is `p=reject` (maximum enforcement) | High | SOC 2 CC6.6, ISO 27001 A.13.2.1 |
352| DNS-DMARC-003 | DMARC `rua` (aggregate reporting) tag configured | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
353| DNS-DMARC-004 | DMARC `ruf` (forensic reporting) tag configured | Low | SOC 2 CC7.2 |
354| DNS-DMARC-005 | DMARC subdomain policy `sp=reject` configured | Medium | ISO 27001 A.13.2.1 |
355| DNS-DMARC-006 | DMARC alignment modes — `adkim=s` and `aspf=s` (strict) preferred | Medium | SOC 2 CC6.6 |
356| DNS-DMARC-007 | DMARC `pct=100` (applies to all messages) | Medium | SOC 2 CC6.6 |
357
358DMARC record format:
359```
360_dmarc.example.com IN TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; rua=mailto:dmarc-agg@example.com; ruf=mailto:dmarc-forensic@example.com; pct=100"
361```
362
363**DMARC rollout strategy** (avoid disrupting legitimate email):
3641. `p=none; rua=mailto:...` — Monitor for 2-4 weeks
3652. `p=quarantine; pct=10` — Quarantine 10% of failing messages
3663. `p=quarantine; pct=50` — Increase gradually
3674. `p=quarantine; pct=100` — Full quarantine
3685. `p=reject; pct=100` — Full enforcement
369
370**DNSSEC**
371
372| Check ID | Control | Severity | Frameworks |
373|----------|---------|----------|------------|
374| DNS-SEC-001 | DNSSEC signing enabled for domain | High | SOC 2 CC6.6, ISO 27001 A.13.1.1, NIST CSF PR.DS-2 |
375| DNS-SEC-002 | DS record published in parent zone | High | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
376| DNS-SEC-003 | DNSSEC algorithm is ECDSAP256SHA256 (13) or newer | Medium | SOC 2 CC6.7 |
377| DNS-SEC-004 | DNSSEC key rotation schedule documented | Medium | SOC 2 CC6.7, ISO 27001 A.10.1.2 |
378
379**CAA (Certificate Authority Authorization)**
380
381| Check ID | Control | Severity | Frameworks |
382|----------|---------|----------|------------|
383| DNS-CAA-001 | CAA record exists restricting certificate issuance | High | SOC 2 CC6.7, ISO 27001 A.10.1.2 |
384| DNS-CAA-002 | CAA `iodef` tag configured for certificate issuance notifications | Medium | SOC 2 CC7.2 |
385| DNS-CAA-003 | Only authorized CAs listed in CAA record | High | SOC 2 CC6.7 |
386
387CAA record format:
388```
389example.com IN CAA 0 issue "letsencrypt.org"
390example.com IN CAA 0 issue "digicert.com"
391example.com IN CAA 0 issuewild "letsencrypt.org"
392example.com IN CAA 0 iodef "mailto:security@example.com"
393```
394
395**MTA-STS and TLS-RPT**
396
397| Check ID | Control | Severity | Frameworks |
398|----------|---------|----------|------------|
399| DNS-MTA-001 | MTA-STS policy published at `/.well-known/mta-sts.txt` | Medium | ISO 27001 A.13.2.1 |
400| DNS-MTA-002 | MTA-STS DNS record `_mta-sts.example.com` exists | Medium | ISO 27001 A.13.2.1 |
401| DNS-MTA-003 | MTA-STS mode is `enforce` (not `testing` or `none`) | Medium | ISO 27001 A.13.2.1 |
402| DNS-MTA-004 | TLS-RPT record `_smtp._tls.example.com` configured | Low | ISO 27001 A.12.4.1 |
403
404MTA-STS policy (at `https://mta-sts.example.com/.well-known/mta-sts.txt`):
405```
406version: STSv1
407mode: enforce
408mx: mail.example.com
409mx: *.example.com
410max_age: 604800
411```
412
413**Domain Security**
414
415| Check ID | Control | Severity | Frameworks |
416|----------|---------|----------|------------|
417| DNS-DOM-001 | Registrar lock enabled (clientTransferProhibited) | High | SOC 2 CC6.7, ISO 27001 A.13.1.1 |
418| DNS-DOM-002 | WHOIS privacy enabled | Low | GDPR Art.5 |
419| DNS-DOM-003 | 2FA enabled on domain registrar account | Critical | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
420| DNS-DOM-004 | Domain expiration monitored (>60 days before expiry) | Medium | SOC 2 A1.2 |
421| DNS-DOM-005 | Subdomain inventory maintained (prevent subdomain takeover) | High | SOC 2 CC6.6, ISO 27001 A.13.1.1 |
422| DNS-DOM-006 | Dangling DNS records (CNAME to deprovisioned services) monitored | High | SOC 2 CC6.6 |
423| DNS-DOM-007 | DNS monitoring alerts configured for unauthorized changes | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
424
425---
426
427### 3. TLS/SSL Security
428
429#### Certificate Management
430
431| Check ID | Control | Severity | Frameworks |
432|----------|---------|----------|------------|
433| TLS-CERT-001 | Certificates issued by trusted CA (not self-signed for public services) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 4.1 |
434| TLS-CERT-002 | Automated certificate renewal via ACME (Let's Encrypt, ZeroSSL) | Medium | SOC 2 CC6.7 |
435| TLS-CERT-003 | Certificate expiration monitored (alert at 30, 14, 7 days) | High | SOC 2 A1.2, ISO 27001 A.10.1.2 |
436| TLS-CERT-004 | Certificate Transparency (CT) log monitoring enabled | Medium | SOC 2 CC7.2 |
437| TLS-CERT-005 | No wildcard certificates for high-security domains | Medium | SOC 2 CC6.7, PCI-DSS 4.1 |
438| TLS-CERT-006 | Certificate validity period 90 days maximum (Let's Encrypt standard) | Low | Best practice |
439| TLS-CERT-007 | OCSP stapling enabled | Medium | SOC 2 CC6.7 |
440| TLS-CERT-008 | Certificate pinning only for mobile apps (not web — risk of bricking) | Info | Best practice |
441
442#### Protocol and Cipher Configuration
443
444| Check ID | Control | Severity | Frameworks |
445|----------|---------|----------|------------|
446| TLS-PROTO-001 | TLS 1.2 minimum (TLS 1.0 and 1.1 disabled) | Critical | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 4.1, NIST CSF PR.DS-2, HIPAA 164.312(e)(1) |
447| TLS-PROTO-002 | TLS 1.3 preferred where supported | Medium | SOC 2 CC6.7, NIST CSF PR.DS-2 |
448| TLS-PROTO-003 | SSL 2.0 and 3.0 disabled | Critical | PCI-DSS 4.1, NIST CSF PR.DS-2 |
449| TLS-CIPHER-001 | Forward secrecy enabled (ECDHE or DHE key exchange) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 4.1 |
450| TLS-CIPHER-002 | AEAD cipher suites only (GCM, ChaCha20-Poly1305) | High | SOC 2 CC6.7, PCI-DSS 4.1 |
451| TLS-CIPHER-003 | No RC4, 3DES, DES, NULL, or EXPORT ciphers | Critical | PCI-DSS 4.1, NIST CSF PR.DS-2 |
452| TLS-CIPHER-004 | No CBC mode ciphers (BEAST/POODLE vulnerability) | High | PCI-DSS 4.1 |
453| TLS-CIPHER-005 | RSA key exchange disabled (no forward secrecy) | Medium | SOC 2 CC6.7 |
454
455**Recommended TLS 1.2 cipher suites (in order):**
456```
457TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
458TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
459TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
460TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
461TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
462TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
463```
464
465**TLS 1.3 cipher suites (always use all three):**
466```
467TLS_AES_256_GCM_SHA384
468TLS_CHACHA20_POLY1305_SHA256
469TLS_AES_128_GCM_SHA256
470```
471
472#### HTTP Security Headers
473
474| Check ID | Control | Severity | Frameworks |
475|----------|---------|----------|------------|
476| TLS-HSTS-001 | HSTS enabled with `max-age` >= 31536000 (1 year) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 4.1, NIST CSF PR.DS-2 |
477| TLS-HSTS-002 | HSTS `includeSubDomains` directive set | High | SOC 2 CC6.7 |
478| TLS-HSTS-003 | HSTS preload submitted to hstspreload.org | Medium | SOC 2 CC6.7 |
479| TLS-HSTS-004 | HTTP to HTTPS redirect configured (301 permanent) | High | SOC 2 CC6.7, PCI-DSS 4.1 |
480
481#### Internal TLS
482
483| Check ID | Control | Severity | Frameworks |
484|----------|---------|----------|------------|
485| TLS-INT-001 | mTLS configured for service-to-service communication | High | SOC 2 CC6.7, ISO 27001 A.13.1.1, PCI-DSS 4.1 (if CDE) |
486| TLS-INT-002 | Internal PKI with short-lived certificates (24h-7d) | Medium | SOC 2 CC6.7, ISO 27001 A.10.1.2 |
487| TLS-INT-003 | Service mesh (Istio/Linkerd) manages mTLS transparently | Medium | SOC 2 CC6.7 |
488| TLS-INT-004 | Database connections use TLS | High | SOC 2 CC6.7, PCI-DSS 4.1, HIPAA 164.312(e)(1) |
489
490---
491
492### 4. Endpoint Security
493
494#### Mobile Device Management (MDM)
495
496| Check ID | Control | Severity | Frameworks |
497|----------|---------|----------|------------|
498| EP-MDM-001 | MDM solution deployed (Jamf, Intune, Kandji) | High | SOC 2 CC6.7, ISO 27001 A.6.2.1, HIPAA 164.310(d)(1), NIST CSF PR.AC-3 |
499| EP-MDM-002 | All corporate devices enrolled in MDM | High | SOC 2 CC6.7, ISO 27001 A.6.2.1 |
500| EP-MDM-003 | MDM compliance policies enforced (auto-remediate non-compliant devices) | Medium | SOC 2 CC6.7 |
501| EP-MDM-004 | MDM reports integrated into security dashboard | Low | SOC 2 CC7.2 |
502
503#### Disk Encryption
504
505| Check ID | Control | Severity | Frameworks |
506|----------|---------|----------|------------|
507| EP-ENC-001 | Full disk encryption enabled on all endpoints (FileVault/BitLocker/LUKS) | Critical | SOC 2 CC6.7, ISO 27001 A.10.1.1, PCI-DSS 3.4, HIPAA 164.312(a)(2)(iv), GDPR Art.32, NIST CSF PR.DS-1 |
508| EP-ENC-002 | Encryption recovery keys escrowed in MDM or central key management | High | SOC 2 CC6.7, ISO 27001 A.10.1.2 |
509| EP-ENC-003 | Encryption status verified on every endpoint via MDM | Medium | SOC 2 CC6.7 |
510| EP-ENC-004 | Mobile devices have device encryption enabled | High | SOC 2 CC6.7, HIPAA 164.312(a)(2)(iv) |
511
512#### Antivirus and EDR
513
514| Check ID | Control | Severity | Frameworks |
515|----------|---------|----------|------------|
516| EP-AV-001 | EDR solution deployed on all endpoints (CrowdStrike, SentinelOne, Defender for Endpoint) | High | SOC 2 CC6.8, ISO 27001 A.12.2.1, PCI-DSS 5.1, HIPAA 164.308(a)(5)(ii)(B), NIST CSF DE.CM-4 |
517| EP-AV-002 | Real-time protection enabled and cannot be disabled by users | High | SOC 2 CC6.8, PCI-DSS 5.1 |
518| EP-AV-003 | Definitions updated automatically (maximum 24h staleness) | Medium | SOC 2 CC6.8, PCI-DSS 5.2 |
519| EP-AV-004 | EDR telemetry centralized for threat hunting | Medium | SOC 2 CC7.2, NIST CSF DE.AE-2 |
520| EP-AV-005 | Automatic quarantine/isolation for critical threats | Medium | SOC 2 CC6.8, NIST CSF RS.MI-1 |
521
522#### OS Patch Management
523
524| Check ID | Control | Severity | Frameworks |
525|----------|---------|----------|------------|
526| EP-PATCH-001 | Critical patches applied within 24 hours | Critical | SOC 2 CC7.1, ISO 27001 A.12.6.1, PCI-DSS 6.2, NIST CSF PR.IP-12 |
527| EP-PATCH-002 | High patches applied within 72 hours | High | SOC 2 CC7.1, ISO 27001 A.12.6.1, PCI-DSS 6.2 |
528| EP-PATCH-003 | Medium patches applied within 7 days | Medium | SOC 2 CC7.1, ISO 27001 A.12.6.1 |
529| EP-PATCH-004 | Low patches applied within 30 days | Low | SOC 2 CC7.1, ISO 27001 A.12.6.1 |
530| EP-PATCH-005 | Patch compliance reported weekly | Medium | SOC 2 CC7.1, ISO 27001 A.12.6.1 |
531| EP-PATCH-006 | Emergency patch process documented and tested | Medium | SOC 2 CC7.1, NIST CSF RS.MI-3 |
532
533#### Additional Endpoint Controls
534
535| Check ID | Control | Severity | Frameworks |
536|----------|---------|----------|------------|
537| EP-LOCK-001 | Screen lock after 5 minutes of inactivity | Medium | SOC 2 CC6.1, ISO 27001 A.11.2.8, PCI-DSS 8.1.8, HIPAA 164.310(b) |
538| EP-USB-001 | USB storage devices blocked or controlled via MDM | Medium | SOC 2 CC6.7, ISO 27001 A.8.3.1, PCI-DSS 9.7 |
539| EP-BRW-001 | Browser extension allow-listing enforced | Medium | SOC 2 CC6.8, ISO 27001 A.12.2.1 |
540| EP-BRW-002 | Safe browsing / web filtering enabled | Low | SOC 2 CC6.8, ISO 27001 A.13.1.1 |
541| EP-WIPE-001 | Remote wipe capability verified for all corporate devices | High | SOC 2 CC6.7, ISO 27001 A.6.2.1, HIPAA 164.310(d)(2)(iii) |
542| EP-BYOD-001 | BYOD policy documented and enforced via MDM container | Medium | SOC 2 CC6.7, ISO 27001 A.6.2.1, GDPR Art.32 |
543| EP-FW-001 | Host-based firewall enabled on all endpoints | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.4 |
544
545---
546
547### 5. Access Control and Authentication
548
549#### Identity Provider (IdP) Configuration
550
551| Check ID | Control | Severity | Frameworks |
552|----------|---------|----------|------------|
553| AC-IDP-001 | Centralized IdP deployed (Okta, Azure AD/Entra ID, Google Workspace) | High | SOC 2 CC6.1, ISO 27001 A.9.2.1, PCI-DSS 8.1, HIPAA 164.312(d), NIST CSF PR.AC-1, FedRAMP AC-2 |
554| AC-IDP-002 | All applications integrated with IdP via SSO | High | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
555| AC-IDP-003 | IdP has admin MFA enforced (hardware key required for admin) | Critical | SOC 2 CC6.1, ISO 27001 A.9.4.2, PCI-DSS 8.3 |
556| AC-IDP-004 | IdP audit logs exported to SIEM | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
557
558#### Single Sign-On (SSO)
559
560| Check ID | Control | Severity | Frameworks |
561|----------|---------|----------|------------|
562| AC-SSO-001 | SSO implemented via SAML 2.0 or OIDC (no password-based SSO) | High | SOC 2 CC6.1, ISO 27001 A.9.4.2, NIST CSF PR.AC-1 |
563| AC-SSO-002 | SSO session timeout configured (maximum 8 hours) | Medium | SOC 2 CC6.1, ISO 27001 A.9.4.2, PCI-DSS 8.1.8 |
564| AC-SSO-003 | SSO enforced (local authentication disabled where possible) | High | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
565| AC-SSO-004 | SCIM provisioning enabled for automated user lifecycle | High | SOC 2 CC6.2, ISO 27001 A.9.2.1, NIST CSF PR.AC-1 |
566| AC-SSO-005 | Deprovisioning triggers immediate SSO session revocation | High | SOC 2 CC6.2, ISO 27001 A.9.2.6 |
567
568#### Multi-Factor Authentication (MFA)
569
570| Check ID | Control | Severity | Frameworks |
571|----------|---------|----------|------------|
572| AC-MFA-001 | MFA enforced for ALL user accounts (no exceptions) | Critical | SOC 2 CC6.1, ISO 27001 A.9.4.2, PCI-DSS 8.3, HIPAA 164.312(d), NIST CSF PR.AC-7, GDPR Art.32, NIS2 Art.21, DORA Art.9, FedRAMP IA-2 |
573| AC-MFA-002 | Phishing-resistant MFA (FIDO2/WebAuthn) required for privileged accounts | Critical | SOC 2 CC6.1, ISO 27001 A.9.4.2, NIST CSF PR.AC-7, FedRAMP IA-2(6) |
574| AC-MFA-003 | SMS-based MFA prohibited (SIM swap vulnerability) | High | SOC 2 CC6.1, NIST CSF PR.AC-7 |
575| AC-MFA-004 | TOTP (time-based one-time password) accepted as minimum MFA | Medium | SOC 2 CC6.1 |
576| AC-MFA-005 | Hardware security keys (YubiKey 5 Series, Bio Series) deployed for all admins | High | SOC 2 CC6.1, ISO 27001 A.9.4.2, NIST CSF PR.AC-7 |
577| AC-MFA-006 | MFA recovery process documented (not bypass, requires identity verification) | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.4 |
578| AC-MFA-007 | MFA enrollment status reported (100% coverage target) | Medium | SOC 2 CC6.1 |
579
580**Hardware Security Key (YubiKey) Implementation:**
581
582Enrollment process:
5831. User registers primary YubiKey to IdP (Okta, Azure AD, Google Workspace)
5842. User registers backup YubiKey (stored in secure location)
5853. IdP policy updated to require FIDO2/WebAuthn for user
5864. TOTP/push fallback disabled for privileged accounts
587
588YubiKey policy requirements:
589- Each user has minimum 2 registered keys (primary + backup)
590- Backup key stored in secure, documented location
591- PIN configured on YubiKey (FIDO2 user verification)
592- Touch required for every authentication
593- Bio Series (fingerprint) preferred for shared workstations
594- Inventory of all issued keys maintained
595- Lost key process: immediate revocation, identity reverification, new key issuance
596
597IdP-specific configuration:
598- **Okta:** Enroll YubiKey via FIDO2 (WebAuthn) factor, set Authentication Policy to require phishing-resistant MFA
599- **Azure AD/Entra ID:** Configure FIDO2 security key in Authentication Methods, create Conditional Access policy requiring authentication strength "Phishing-resistant MFA"
600- **Google Workspace:** Enroll security key in 2-Step Verification, enable Advanced Protection Program for admins
601
602#### Privileged Access Management (PAM)
603
604| Check ID | Control | Severity | Frameworks |
605|----------|---------|----------|------------|
606| AC-PAM-001 | Just-in-time (JIT) access implemented for privileged roles | High | SOC 2 CC6.1, ISO 27001 A.9.2.3, PCI-DSS 7.1, NIST CSF PR.AC-4 |
607| AC-PAM-002 | Privileged access requests require approval workflow | High | SOC 2 CC6.1, ISO 27001 A.9.2.3 |
608| AC-PAM-003 | Privileged session time-limited (maximum 4 hours, re-approval needed) | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.3 |
609| AC-PAM-004 | Privileged sessions recorded (screen recording or command logging) | High | SOC 2 CC7.2, ISO 27001 A.12.4.1, PCI-DSS 10.2 |
610| AC-PAM-005 | Break-glass procedure documented and tested quarterly | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.3, NIST CSF PR.AC-4 |
611| AC-PAM-006 | Privileged account inventory maintained and reviewed quarterly | High | SOC 2 CC6.2, ISO 27001 A.9.2.5, PCI-DSS 7.1 |
612| AC-PAM-007 | Standing privileged access eliminated (no permanent admin accounts) | High | SOC 2 CC6.1, ISO 27001 A.9.2.3, NIST CSF PR.AC-4 |
613
614#### Role-Based Access Control (RBAC)
615
616| Check ID | Control | Severity | Frameworks |
617|----------|---------|----------|------------|
618| AC-RBAC-001 | RBAC model documented with role definitions and permissions | High | SOC 2 CC6.3, ISO 27001 A.9.2.2, PCI-DSS 7.1, HIPAA 164.312(a)(1), NIST CSF PR.AC-4 |
619| AC-RBAC-002 | Role assignments reviewed quarterly (access recertification) | High | SOC 2 CC6.2, ISO 27001 A.9.2.5, PCI-DSS 7.1.1 |
620| AC-RBAC-003 | Separation of duties enforced (no single user has conflicting roles) | High | SOC 2 CC6.3, ISO 27001 A.6.1.2, PCI-DSS 6.4.2 |
621| AC-RBAC-004 | Default deny — users get minimum necessary permissions | High | SOC 2 CC6.3, ISO 27001 A.9.4.1 |
622| AC-RBAC-005 | Role changes logged and auditable | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
623
624#### Service Account and API Key Governance
625
626| Check ID | Control | Severity | Frameworks |
627|----------|---------|----------|------------|
628| AC-SVC-001 | No shared credentials for service accounts | Critical | SOC 2 CC6.1, ISO 27001 A.9.2.4, PCI-DSS 8.5 |
629| AC-SVC-002 | Service account permissions follow least privilege | High | SOC 2 CC6.3, ISO 27001 A.9.4.1 |
630| AC-SVC-003 | Service account credentials rotate every 90 days maximum | High | SOC 2 CC6.1, ISO 27001 A.9.2.4, PCI-DSS 8.2.4 |
631| AC-SVC-004 | Service account inventory maintained with owner assignment | High | SOC 2 CC6.2, ISO 27001 A.9.2.5 |
632| AC-SVC-005 | API keys scoped to minimum required permissions | High | SOC 2 CC6.3, ISO 27001 A.9.4.1 |
633| AC-SVC-006 | API keys have expiration dates (maximum 1 year) | Medium | SOC 2 CC6.1, ISO 27001 A.9.2.4 |
634| AC-SVC-007 | API key usage monitored and anomalous access alerted | Medium | SOC 2 CC7.2, ISO 27001 A.12.4.1 |
635
636#### SSH Key Management
637
638| Check ID | Control | Severity | Frameworks |
639|----------|---------|----------|------------|
640| AC-SSH-001 | ED25519 keys required (or RSA >= 4096 bit) | High | SOC 2 CC6.7, ISO 27001 A.10.1.1 |
641| AC-SSH-002 | SSH certificate-based authentication for infrastructure | Medium | SOC 2 CC6.7, ISO 27001 A.9.4.2 |
642| AC-SSH-003 | SSH key passphrase required | Medium | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
643| AC-SSH-004 | SSH key inventory maintained with owner assignment | Medium | SOC 2 CC6.2, ISO 27001 A.9.2.5 |
644| AC-SSH-005 | SSH keys rotate annually at minimum | Medium | SOC 2 CC6.1, PCI-DSS 3.6.4 |
645| AC-SSH-006 | Root SSH login disabled | High | SOC 2 CC6.1, ISO 27001 A.9.4.2, PCI-DSS 2.1 |
646| AC-SSH-007 | SSH password authentication disabled (key-only) | High | SOC 2 CC6.1, ISO 27001 A.9.4.2 |
647
648#### Zero Trust Architecture
649
650| Check ID | Control | Severity | Frameworks |
651|----------|---------|----------|------------|
652| AC-ZT-001 | Identity-based access (verify user, device, and context) | High | SOC 2 CC6.1, ISO 27001 A.9.4.2, NIST CSF PR.AC-4 |
653| AC-ZT-002 | Device posture checked before granting access | High | SOC 2 CC6.1, ISO 27001 A.6.2.1 |
654| AC-ZT-003 | Network location is not trusted (no implicit trust for internal network) | High | SOC 2 CC6.6, ISO 27001 A.13.1.1, NIST CSF PR.AC-5 |
655| AC-ZT-004 | Continuous verification (re-authenticate for sensitive operations) | Medium | SOC 2 CC6.1, NIST CSF PR.AC-7 |
656| AC-ZT-005 | Microsegmentation between services | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.3, PCI-DSS 1.2 |
657
658---
659
660### 6. Network Security
661
662#### Firewall Configuration
663
664| Check ID | Control | Severity | Frameworks |
665|----------|---------|----------|------------|
666| NET-FW-001 | Default deny policy (deny all, allow by exception) | Critical | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.2, NIST CSF PR.AC-5 |
667| NET-FW-002 | Egress filtering enabled (restrict outbound traffic) | High | SOC 2 CC6.6, ISO 27001 A.13.1.1, PCI-DSS 1.3 |
668| NET-FW-003 | Firewall rules reviewed quarterly | Medium | SOC 2 CC6.6, PCI-DSS 1.1.7 |
669| NET-FW-004 | Firewall rule documentation (business justification for each rule) | Medium | SOC 2 CC6.6, PCI-DSS 1.1.6 |
670| NET-FW-005 | No "any/any" rules in firewall ruleset | Critical | SOC 2 CC6.6, PCI-DSS 1.2 |
671| NET-FW-006 | Firewall change management process documented | Medium | SOC 2 CC6.6, PCI-DSS 1.1.1 |
672
673#### Network Segmentation
674
675| Check ID | Control | Severity | Frameworks |
676|----------|---------|----------|------------|
677| NET-SEG-001 | Network segmentation isolates sensitive environments (production, staging, dev) | High | SOC 2 CC6.6, ISO 27001 A.13.1.3, PCI-DSS 1.2, HIPAA 164.312(e)(1) |
678| NET-SEG-002 | Cardholder Data Environment (CDE) segmented from general network | Critical | PCI-DSS 1.3 |
679| NET-SEG-003 | Database tier isolated from public-facing tier | High | SOC 2 CC6.6, ISO 27001 A.13.1.3, PCI-DSS 1.3 |
680| NET-SEG-004 | Microsegmentation for East-West traffic | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.3, NIST CSF PR.AC-5 |
681| NET-SEG-005 | Management network separated from production | High | SOC 2 CC6.6, PCI-DSS 1.2 |
682| NET-SEG-006 | Guest WiFi isolated from corporate network | Medium | SOC 2 CC6.6, ISO 27001 A.13.1.3 |
683
684#### Web Application Firewall (WAF)
685
686| Check ID | Control | Severity | Frameworks |
687|----------|---------|----------|------------|
688| NET-WAF-001 | WAF d
689
690…(truncated)