Skip to content

How Black Cat SSPM maps to DORA (SaaS Security)

Digital Operational Resilience Act — ICT risk management and third-party risk for financial entities in SaaS environments (Articles 5-6, 8-14, 17-19, 24-30)

DORA-5 — ICT Risk Management Framework

Sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system (Articles 5-6)

DORA-5.1 — Governance and board oversight

The management body defines, approves, oversees and is accountable for the ICT risk management framework (Article 5(2))

DORA-6.1 — Documented ICT risk management framework

The ICT risk management framework is documented in a comprehensive manner, covering strategies, policies, protocols and tools (Article 6(1)-(2))

DORA-6.2 — Roles, responsibilities and control function

Clear ICT roles and responsibilities with an independent ICT risk control function (Article 6(4))

DORA-6.3 — Post-incident and periodic framework review

Review the ICT risk management framework after major ICT incidents and following supervisory instructions (Article 6(5))

DORA-6.4 — Internal audit of the ICT framework

The ICT risk management framework is subject to internal audit by auditors with sufficient ICT knowledge (Article 6(6))

DORA-6.5 — ICT risk tolerance and strategy

Digital operational resilience strategy setting ICT risk tolerance in line with the entity's risk appetite (Article 6(8))

DORA-8 — Identification

Identify, classify and document ICT-supported business functions, assets and dependencies (Article 8)

DORA-8.1 — ICT asset inventory

Identify and maintain an inventory of all ICT assets, accounts and applications supporting business functions (Article 8(1)/(4))

  • Stale Browser (90+ Days Inactive) (chrome_enterprise)
  • Unmanaged Browser (30+ Days Inactive) (chrome_enterprise)
  • Orphaned Extension With Zero Installs (chrome_enterprise)
  • Browser Flagged as Needing Attention (chrome_enterprise)
  • CMDB Stale Records (servicenow)

DORA-8.2 — ICT-supported business functions

Identify and classify the business functions, roles and dependencies that ICT assets support (Article 8(1))

DORA-8.3 — Legacy and end-of-life ICT systems

Identify ICT systems that are outdated, unsupported or approaching end of life (Article 8(7))

  • Sideloaded Extension Detected (chrome_enterprise)
  • Outdated Browser Version (chrome_enterprise)
  • Extension With Risky Permissions (chrome_enterprise)
  • Extension Not Hosted on Chrome Web Store (chrome_enterprise)
  • Computer OS Outdated (jamf)
  • Mobile Device OS Outdated (jamf)

DORA-9 — Protection and Prevention

ICT security policies, tools and controls that protect ICT systems and data (Article 9)

DORA-9.1 — Identity and access management policy

Documented policies governing identity and access management across ICT systems (Article 9(4)(c))

  • Browser Without Organizational Unit Assignment (chrome_enterprise)
  • Sentinel Policy Advisory Only (terraform_cloud)
  • Policy Set Overridable (terraform_cloud)
  • Policy Set Not Global (terraform_cloud)
  • Policy Set Empty (terraform_cloud)

DORA-9.2 — Access control and least privilege

Restrict access rights to the minimum required for each role, applying least privilege and separation of duties (Article 9(4)(c))

  • User Account Locked (akamai)
  • User Inactive (akamai)
  • User All Groups Access (akamai)
  • API Client Credentials Near Expiry (akamai)
  • API Client Inactive (akamai)
  • Custom Role With Admin Permissions (akamai)
  • Excessive Org Admins (anthropic)
  • Unscoped Admin (anthropic)
  • Managed User Review (anthropic)
  • Admin Redundancy Missing (anthropic)
  • Dormant Member (anthropic)
  • Stale API Key (anthropic)
  • Unscoped API Key (anthropic)
  • Inactive API Key Not Removed (anthropic)
  • API Key Created By Non-User (anthropic)
  • Stale Invite (anthropic)
  • Expired Invite Not Cleaned (anthropic)
  • Admin Invite Pending Review (anthropic)
  • Excessive Workspace Admins (anthropic)
  • Workspace Single Admin (anthropic)
  • API Key Expired Or Expiring (anthropic)
  • API Key No Expiration (anthropic)
  • Claude Code User Not In Workspace (anthropic)
  • Claude Code User Role Review (anthropic)
  • Claude Code Commits Without Pull Requests (anthropic)
  • Unscoped API Usage (anthropic)
  • Claude SSO Not Enforced (anthropic)
  • Claude SSO Provisioning Not Required (anthropic)
  • Claude No Active IP Allowlist (anthropic)
  • Claude Excessive Session Duration (anthropic)
  • Compliance Key Has Delete Scope (anthropic)
  • Deactivated Compliance Key Still Listed (anthropic)
  • Compliance Key Stale (anthropic)
  • Claude Admin Sprawl (anthropic)
  • Claude Empty Group (anthropic)
  • Claude Custom Role Broad Connector Access (anthropic)
  • Compliance Key No Expiry (anthropic)
  • Inactive User (atlassian)
  • Suspended User With Access (atlassian)
  • User Dual Admin Role (atlassian)
  • External User With Product Access (atlassian)
  • API Token Older Than 90 Days (atlassian)
  • User With Multiple API Tokens (atlassian)
  • SSO Not Configured (atlassian)
  • Session Duration Excessive (atlassian)
  • Jira Project Permissive Default Roles (atlassian)
  • API Token No Label (atlassian)
  • External Users Policy Disabled (atlassian)
  • Org Admin Product Access (atlassian)
  • User Account Closed (atlassian)
  • API Token Generic Label (atlassian)
  • Empty Group (atlassian)
  • Admin Without MFA (atlassian)
  • Product Access Admin (atlassian)
  • Root Access Key Exists (aws)
  • Unused Access Keys (aws)
  • Old Access Keys Not Rotated (aws)
  • Inactive IAM Users (aws)
  • Password Never Used (aws)
  • Overly Permissive IAM Policy (aws)
  • Weak Password Policy (aws)
  • Password Policy Expiration Too Long (aws)
  • SCP Not Attached to Root (aws)
  • SCP Allows All Actions (aws)
  • SCP Overly Broad Deny Exception (aws)
  • Owner Count Exceeded (azure)
  • Custom Admin Roles (azure)
  • Classic Administrators (azure)
  • Guest Privileged Role (azure)
  • Key Vault RBAC Not Enabled (azure)
  • SQL AD Admin Not Configured (azure)
  • App Service Managed Identity Disabled (azure)
  • App Service Auth Disabled (azure)
  • Excessive Admin Users (box)
  • Inactive User Account (box)
  • External Collaboration Not Restricted (box)
  • Platform Access Only Admin (box)
  • User Exempt from Login Verification (box)
  • User Account Deactivated But Not Removed (box)
  • Admin Exempt From Login Verification (box)
  • GPT With Unreviewed Third-Party Actions (chatgpt_enterprise)
  • Download Restrictions Not Set (chrome_enterprise)
  • Incognito Mode Allowed (chrome_enterprise)
  • Extension With Excessive Permissions (chrome_enterprise)
  • No Groups Defined (circleci)
  • Unrestricted Context (circleci)
  • User Checkout Key (circleci)
  • OIDC Not Configured (circleci)
  • Empty Group (circleci)
  • Large Group (circleci)
  • OIDC Default Audience (circleci)
  • External Account Member (cloudflare)
  • SSO Not Configured (cloudflare)
  • Super Admin Count Excessive (cloudflare)
  • Super Admin Redundancy Missing (cloudflare)
  • Super Admin Without MFA (cloudflare)
  • Pending Account Member (cloudflare)
  • Role-less Account Member (cloudflare)
  • API Token Without Expiry (cloudflare)
  • API Token Stale (cloudflare)
  • Application Without Policies (cloudflare_access)
  • Bypass Decision Policy (cloudflare_access)
  • Policy Allows Everyone (cloudflare_access)
  • No Purpose Justification (cloudflare_access)
  • Group Includes Everyone (cloudflare_access)
  • Group With Empty Include Rules (cloudflare_access)
  • Single Identity Provider (cloudflare_access)
  • Application Allows All IdPs (cloudflare_access)
  • Application No Auto-Redirect to IdP (cloudflare_access)
  • Policy Without Require Rules (cloudflare_access)
  • Group Without Require Rules (cloudflare_access)
  • Service Token Over One Year Old (cloudflare_access)
  • Seat Expiration Not Configured (cloudflare_access)
  • Dashboard Not Read-Only (cloudflare_access)
  • SSO Disabled (datadog)
  • SSO Not Enforced (datadog)
  • Admin Redundancy (datadog)
  • Excessive Admins (datadog)
  • External Admin (datadog)
  • Unverified User (datadog)
  • Disabled User Present (datadog)
  • External User Access (datadog)
  • Dashboard Permissions Open (datadog)
  • Dashboard Read-Only Without Role Restriction (datadog)
  • External Admin Service Account (datadog)
  • Service Account Admin Privileges (datadog)
  • Service Account Custom Role (datadog)
  • Application Key Write Scopes (datadog)
  • Application Key Has No Scopes (datadog)
  • External Service Account (datadog)
  • Admin User Not Verified (datadog)
  • Disabled Admin User (datadog)
  • Application Key Excessive Scopes (datadog)
  • API Key Critical Age (datadog)
  • Weak SSH Key (digitalocean)
  • Kubernetes SSO Not Enabled (digitalocean)
  • MFA Not Required for Admins (discord)
  • Low Verification Level (discord)
  • Member Verification Gate Disabled (discord)
  • Role Has Administrator Permission (discord)
  • Role Has Dangerous Permissions (discord)
  • Everyone Role Has Dangerous Permissions (discord)
  • Excessive Admin Roles (discord)
  • Role Can Mention Everyone (discord)
  • Permanent Invite (discord)
  • Unlimited Use Invite (discord)
  • Channel Everyone Overwrite (discord)
  • Overly Permissive Channel (discord)
  • Excessive Admins (discord)
  • Admin Role High Member Count (discord)
  • Bot-Managed Role With Admin (discord)
  • Weak Password Length (docusign)
  • Weak Password Strength (docusign)
  • No Password Expiration (docusign)
  • No Account Lockout (docusign)
  • Long Web Session Timeout (docusign)
  • Long Signing Session Timeout (docusign)
  • Long Mobile Session Timeout (docusign)
  • Excessive Admins (docusign)
  • Inactive User With Access (docusign)
  • Overly Broad Permission Profile (docusign)
  • User Without Group (docusign)
  • No SSO Configured (docusign)
  • Unclaimed Domain (docusign)
  • SSO Not Mandatory (docusign)
  • Empty Group (docusign)
  • Permission Profile Manages Users (docusign)
  • Unused Admin Permission Profile (docusign)
  • Disabled Admin Account (docusign)
  • Domain Not Linked to Identity Provider (docusign)
  • Password Security Questions Enabled (docusign)
  • Group Creation Unrestricted (dropbox)
  • Excessive Admin Users (dropbox)
  • Inactive Member Account (dropbox)
  • Stale Pending Invite (dropbox)
  • Email Not Verified (dropbox)
  • Admin Email Not Verified (dropbox)
  • User-Managed Group (dropbox)
  • Stale Mobile Session (dropbox)
  • High Pending Invitation Count (dropbox)
  • Suspended Members Present (dropbox)
  • Overly Permissive IAM Binding (gcp)
  • SA Impersonation Role Binding (gcp)
  • Excessive Project Owners (gcp)
  • Owner Role Group Assignment (gcp)
  • Privileged Service Account Binding (gcp)
  • Old Service Account Keys (gcp)
  • User Managed Service Account Keys (gcp)
  • Bucket Uniform Access Disabled (gcp)
  • SA Key Creation Not Disabled (gcp)
  • SA Key Upload Not Disabled (gcp)
  • Default SA Grant Not Disabled (gcp)
  • Service Account Key Expiry Not Enforced (gcp)
  • Unrestricted API Key (gcp)
  • Stale API Key (gcp)
  • KMS Separation of Duties Violation (gcp)
  • SA Separation of Duties Violation (gcp)
  • Org-Level Owner Binding (gcp)
  • Org-Level Editor Binding (gcp)
  • External Members at Org Level (gcp)
  • Instance Uses Default Service Account (gcp)
  • Cloud KMS Key Publicly Accessible (gcp)
  • Secret Manager Secret Publicly Accessible (gcp)
  • GKE Legacy ABAC Enabled (gcp)
  • GKE Workload Identity Disabled (gcp)
  • GKE Master Authorized Networks Disabled (gcp)
  • Unbounded Conditional Privileged Binding (gcp)
  • WIF Provider Trusts Public Issuer Without Attribute Condition (gcp)
  • WIF Provider Missing Attribute Condition (gcp)
  • Privileged Service Account Impersonable From Unconditioned WIF Pool (gcp)
  • Privileged Role Granted to Workload Identity Pool via Wildcard (gcp)
  • Org Default Permission Too Permissive (github)
  • Repo Branch Protection Disabled (github)
  • Stale Organization Member (github)
  • Repo Admins Bypass Branch Protection (github)
  • Repo Stale Reviews Not Dismissed (github)
  • Team Admin Permission (github)
  • OAuth App Broad Repository Access (github)
  • GitHub Actions Can Approve Pull Requests (github)
  • GitHub Actions Default Workflow Permissions Read-Write (github)
  • Org Members Can Fork Private Repos (github)
  • Org Members Can Create Public Repos (github)
  • Org Repository Creation Unrestricted (github)
  • Repo Branch Deletion Allowed (github)
  • Repo Force Pushes Allowed (github)
  • Repo Insufficient Required Reviews (github)
  • Too Few Organization Owners (github)
  • Too Many Organization Owners (github)
  • Fine-Grained PAT Stale (github)
  • Fine-Grained PAT Broad Access (github)
  • Copilot Allows Public Code Suggestions (github)
  • Copilot Seat Inactive (github)
  • Group Membership Unlocked (gitlab)
  • Project Merge Approvals Disabled (gitlab)
  • Project Branch Protection Disabled (gitlab)
  • Project Force Push Allowed (gitlab)
  • Project No Code Owner Approval (gitlab)
  • Deactivated Member Not Removed (gitlab)
  • Pending Invitation Not Accepted (gitlab)
  • Group Subgroup Creation Permissive (gitlab)
  • Blocked Member Not Removed (gitlab)
  • Email-Only User Access (google_ads)
  • Excessive Admin Users (google_ads)
  • Stale Pending Invitation (google_ads)
  • Stale User Access (google_ads)
  • Account With No Admin Users (google_ads)
  • Account With Single Admin User (google_ads)
  • Stale Standard User Access (google_ads)
  • Stale Admin Invitation (google_ads)
  • Self-Granted User Access (google_ads)
  • Stale Read-Only Invitation (google_ads)
  • Stale Email-Only User Access (google_ads)
  • Stale Admin Access (google_ads)
  • User Access Without Inviter (google_ads)
  • Stale Standard Access Invitation (google_ads)
  • SSO Disabled (grafana)
  • Basic Auth Enabled With SSO (grafana)
  • Single SSO Provider (grafana)
  • Excessive Admins (grafana)
  • Dormant User (grafana)
  • Admin Without Recent Activity (grafana)
  • Service Account Admin Role (grafana)
  • Non-Expiring Service Account Token (grafana)
  • Disabled Service Account With Tokens (grafana)
  • Expired Service Account Token (grafana)
  • Service Account Token Age Exceeds 180 Days (grafana)
  • Folder Without Custom ACL (grafana)
  • Excessive Cloud Admins (grafana_cloud)
  • Cloud Wildcard Access Policy (grafana_cloud)
  • Overly Permissive Access Policy (grafana_cloud)
  • Access Policy Without IP Restriction (grafana_cloud)
  • Single Cloud Admin (grafana_cloud)
  • Access Policy With No Scopes (grafana_cloud)
  • Access Policy With No Realm Binding (grafana_cloud)
  • Access Policy Combines Write and Delete Scopes (grafana_cloud)
  • Access Policy Uses Org-Wide Realm (grafana_cloud)
  • Recently Added Admin Member (grafana_cloud)
  • Write-Scoped Access Policy Without IP Restriction (grafana_cloud)
  • Organization Member Without Email (grafana_cloud)
  • Excessive Scope Count on Access Policy (grafana_cloud)
  • Token Bound to Unknown or Deleted Policy (grafana_cloud)
  • Token With Expiration Over 365 Days (grafana_cloud)
  • Token Not Rotated in 180 Days (grafana_cloud)
  • Resource Group Auto-Join With Write Access (huggingface)
  • Excessive Admins (incidentio)
  • Single Account Owner (incidentio)
  • User Without Base Role (incidentio)
  • User Has Custom Roles But No Base Role (incidentio)
  • User With Excessive Custom Roles (incidentio)
  • Dormant Account (lastpass)
  • Admin Dormant (lastpass)
  • Never Logged In Account (lastpass)
  • Admin Never Logged In (lastpass)
  • Disabled Account Not Removed (lastpass)
  • Excessive Shared Folder Admins (lastpass)
  • Shared Folder All Admin (lastpass)
  • Shared Folder No Read-Only Users (lastpass)
  • Shared Folder Single Admin (lastpass)
  • Shared Folder Excessive Users (lastpass)
  • User Not Assigned to Any Group (lastpass)
  • Disabled Account With Admin Privileges (lastpass)
  • Recently Created Admin Account (lastpass)
  • Guest User Permissions Not Restricted (m365)
  • Guest Invitation Not Restricted (m365)
  • Users Can Create Security Groups (m365)
  • Users Can Register Applications (m365)
  • User Consent to Apps Not Restricted (m365)
  • Guest Group Privileges Not Restricted (m365)
  • Admin Consent Requests Disabled (m365)
  • Users Can Create Tenants (m365)
  • M365 Group Creation Not Restricted (m365)
  • MSOL PowerShell Not Blocked (m365)
  • Self-Service Sign Up Enabled (m365)
  • Guest Access to Groups Not Restricted (m365)
  • Global Admin Redundancy Missing (m365)
  • Excessive Global Administrators (m365)
  • Global Admin Not Cloud-Only (m365)
  • External Users With Admin Role (m365)
  • Guest Users Present (m365)
  • Copilot License on Guest User (m365)
  • CA Block High Risk Users Missing (m365)
  • CA Block Risky Sign-ins Missing (m365)
  • CA Legacy Auth Not Blocked (m365)
  • CA Session Duration Not Set (m365)
  • CA Compliant Devices Not Required (m365)
  • CA Device Code Flow Not Blocked (m365)
  • Auth Methods Migration Incomplete (m365)
  • TAP Enabled for All Users (m365)
  • TAP Not One-Time Use (m365)
  • TAP Global Policy Enabled (m365)
  • TAP Maximum Lifetime Too Long (m365)
  • TAP Character Length Too Short (m365)
  • Password Expiration Policy Enabled (m365)
  • Password Lockout Threshold Too High (m365)
  • Lockout Duration Too Short (m365)
  • Custom Banned Passwords Not Enforced (m365)
  • Password Protection On-Prem Disabled (m365)
  • Password Protection Mode Audit Only (m365)
  • SP Using Password Credentials (m365)
  • SP Expired Password Credentials (m365)
  • SP Expired Certificate Credentials (m365)
  • SP Long-Lived Password Credentials (m365)
  • SP Long-Lived Certificate Credentials (m365)
  • SP Password Credentials Expiring Soon (m365)
  • SP Certificate Credentials Expiring Soon (m365)
  • App Using Password Credentials (m365)
  • App Long-Lived Password Credentials (m365)
  • App Long-Lived Certificate Credentials (m365)
  • App Expired Password Credentials (m365)
  • App Expired Certificate Credentials (m365)
  • App Password Credentials Expiring Soon (m365)
  • App Certificate Credentials Expiring Soon (m365)
  • OAuth App AI With Data Scopes (m365)
  • OWA Session Timeout Disabled (m365)
  • Shared Mailbox Sign-In Enabled (m365)
  • Users Can Install Outlook Add-ins (m365)
  • Direct File Access on Public Computers (m365)
  • WAC Viewing on Public Computers (m365)
  • Mobile Device Allows Non-Provisionable (m365)
  • ActiveSync Does Not Block Unmanaged Devices (m365)
  • Guest User Sprawl (notion)
  • Member Without Email (notion)
  • Bot Without Description (notion)
  • Excessive Workspace Members (notion)
  • Excessive Guest Ratio (notion)
  • Bot User Without Name (notion)
  • Dormant Accounts (okta)
  • Dormant Super Admins (okta)
  • Weak Password Policy (okta)
  • Weak Account Lockout (okta)
  • Session Idle Timeout Too Long (okta)
  • Session Lifetime Too Long (okta)
  • App Not Using Federated Auth (okta)
  • App With Individual User Assignments (okta)
  • OAuth App Broad Scopes (okta)
  • OAuth App Inactive With Grants (okta)
  • OAuth App AI With Broad Access (okta)
  • Access Policy Default Not Deny (okta)
  • Super Admin API Tokens (okta)
  • Super Admin Count Excessive (okta)
  • Super Admin Redundancy Missing (okta)
  • Admin API Token Usage (okta)
  • User Account Suspended (okta)
  • User Account Locked Out (okta)
  • Excessive Total Admin Accounts (okta)
  • Stale API Token (okta)
  • Old API Token (okta)
  • Suspended User Activity (1password)
  • Suspended User Not Removed (1password)
  • Dormant User (1password)
  • Failed Sign-in Attempt (1password)
  • Sign-in From Untrusted Location (1password)
  • Failed Sign-in From Untrusted Location (1password)
  • Service Account Token Created (1password)
  • Sign-in From Unknown Country (1password)
  • Failed Sign-in Without MFA (1password)
  • Sign-in With No Client Recorded (1password)
  • Sign-in With No IP Recorded (1password)
  • Failed Sign-in From Unknown Country (1password)
  • Resource Created (1password)
  • Suspended User With MFA Disabled (1password)
  • User With No Recorded Activity (1password)
  • Stale API Key (openai)
  • API Key Non-User Owner (openai)
  • Admin Key Sprawl (openai)
  • Stale Admin Key (openai)
  • Admin Key Non-User Owner (openai)
  • Excessive Organization Owners (openai)
  • Owner Redundancy Missing (openai)
  • Disabled User Not Removed (openai)
  • Excessive Service Accounts (openai)
  • Excessive Project API Keys (openai)
  • Project With Only Service Accounts (openai)
  • Orphaned Service Account (openai)
  • Stale Service Account (openai)
  • Empty Group (openai)
  • Group Not SCIM-Managed (openai)
  • Stale Expired Invite (openai)
  • Invite Grants Owner Role (openai)
  • Stale Pending Invite (openai)
  • Overpermissive Custom Role (openai)
  • Guardrail Without Provider Allowlist (openrouter)
  • Guardrail Without Model Allowlist (openrouter)
  • BYOK Credential Without Workspace Scope (openrouter)
  • SCIM Group Grants Admin Role (openrouter)
  • SCIM Group Mapped to Default Workspace (openrouter)
  • MFA Not Enabled (ovhcloud)
  • Only SMS MFA Enabled (ovhcloud)
  • No IP Restrictions (ovhcloud)
  • API Credential No Expiry (ovhcloud)
  • API Credential Never Used (ovhcloud)
  • API Credential Overly Permissive (ovhcloud)
  • Identity User Disabled Not Removed (ovhcloud)
  • Identity User No Group (ovhcloud)
  • Identity User MFA Not Enabled (ovhcloud)
  • IAM Policy Wildcard Actions (ovhcloud)
  • IAM Policy Wildcard Resources (ovhcloud)
  • Excessive OAuth2 Clients (ovhcloud)
  • Weak SSH Key Algorithm (ovhcloud)
  • SSH Key Size Too Small (ovhcloud)
  • API Credential OVH Support Access (ovhcloud)
  • IAM Policy Excessive Identities (ovhcloud)
  • Identity User Password Never Changed (ovhcloud)
  • Excessive Admins (pagerduty)
  • Single Account Owner (pagerduty)
  • Unassigned User (pagerduty)
  • User Pending Invitation (pagerduty)
  • Team Without Manager (pagerduty)
  • Service Not Assigned to Team (pagerduty)
  • Inactive Admin (salesforce)
  • Frozen Active User (salesforce)
  • User Never Logged In (salesforce)
  • Excessive Modify All Data (salesforce)
  • Profile View All Data (salesforce)
  • Profile Manage Users (salesforce)
  • Profile Author Apex (salesforce)
  • API Access Review (salesforce)
  • Permission Set Modify All Data (salesforce)
  • Permission Set View All Data (salesforce)
  • Permission Set Manage Users Wide (salesforce)
  • Permission Set API Access (salesforce)
  • Login From Multiple IPs (salesforce)
  • Active User Without Role (salesforce)
  • Weak Password Complexity (salesforce)
  • Permission Set Manage Malicious Files (salesforce)
  • Profile Manage Malicious Files (salesforce)
  • Profile Data Export (salesforce)
  • Permission Set Data Export (salesforce)
  • Profile Bulk API Hard Delete (salesforce)
  • Permission Set Bulk API Hard Delete (salesforce)
  • SSO Disabled (sentry)
  • Default Role Not Member (sentry)
  • Excessive Admins (sentry)
  • Dormant User (sentry)
  • Old Pending Invite (sentry)
  • Inactive Admin (sentry)
  • Expired Invitation Not Removed (sentry)
  • Events Member Admin Disabled (sentry)
  • Alerts Member Write Enabled (sentry)
  • Long-Term Inactive Member (sentry)
  • Deactivated Member Not Removed (sentry)
  • Owner Role Review (sentry)
  • Pending Admin Invite (sentry)
  • Inactive Member 90 Days (sentry)
  • Default Role Elevated to Admin or Owner (sentry)
  • Expired Admin Invite Not Cleaned Up (sentry)
  • Admin Redundancy Missing (sentry)
  • Very Stale Pending Invite (sentry)
  • Admin Role Sprawl (servicenow)
  • Empty Group With Roles (servicenow)
  • Overly Permissive ACL (servicenow)
  • Excessive Admins (shopify)
  • Staff Unrestricted Permissions (shopify)
  • Excessive API Scopes (shopify)
  • Write Payment Gateways Scope (shopify)
  • Write Themes Scope (shopify)
  • Write Script Tags Scope (shopify)
  • Write Price Rules Scope (shopify)
  • Write Inventory Scope (shopify)
  • Staff No Permissions (shopify)
  • Write Fulfillments Scope (shopify)
  • Unauthenticated Write Checkouts Scope (shopify)
  • Admin Staff MFA Disabled (shopify)
  • Read All Orders Scope (shopify)
  • Write Draft Orders Scope (shopify)
  • Write Order Edits Scope (shopify)
  • Write Users Scope (shopify)
  • Public Channel Creation Unrestricted (slack)
  • App Management Unrestricted (slack)
  • Guest Slash Commands (slack)
  • Excessive Admins (slack)
  • Excessive Owners (slack)
  • External Admin (slack)
  • Owner Redundancy (slack)
  • Guest Multi Channel (slack)
  • App Approval Not Required (slack)
  • Password Only Auth (snowflake)
  • Service Account Password Auth (snowflake)
  • ACCOUNTADMIN Default Role (snowflake)
  • Excessive Admin Roles (snowflake)
  • No Separation Of Duties (snowflake)
  • Disabled User With Active Grants (snowflake)
  • Dormant User (snowflake)
  • User Not Disabled (snowflake)
  • ACCOUNTADMIN Excessive Grants (snowflake)
  • Weak Password Policy (snowflake)
  • OAuth Integration Permissive (snowflake)
  • Guest Members in Team (teams)
  • Excessive Team Owners (teams)
  • Anonymous Meeting Join Enabled (teams)
  • Lobby Bypass for Everyone (teams)
  • Guest Access Overly Permissive (teams)
  • Members Can Delete Channels (teams)
  • Members Can Install Apps (teams)
  • Guests Can Delete Channels (teams)
  • Guests Can Create and Update Channels (teams)
  • Single Team Owner (teams)
  • Meeting Auto-Admits Everyone (teams)
  • External Consumer Teams Access (teams)
  • Role Has Wildcard Node Labels (teleport)
  • Role Has Wildcard Database Labels (teleport)
  • Role Has Wildcard Kubernetes Labels (teleport)
  • Role Has Wildcard App Labels (teleport)
  • Role Enables SSH Agent Forwarding (teleport)
  • Role Has Unlimited Session TTL (teleport)
  • Role Allows Impersonation (teleport)
  • Role Has Broad Admin RBAC Rules (teleport)
  • User Account Is Locked (teleport)
  • Local User Has No SSO Identity (teleport)
  • User Has Excessive Roles (teleport)
  • User Has Admin Role (teleport)
  • Auth Connector Maps Claims to Admin Role (teleport)
  • Auth Connector Has Broad Claim Mapping (teleport)
  • Auth Connector Has No Role Mappings (teleport)
  • GitHub Connector Maps All Teams (teleport)
  • Token Uses Static Join Method (teleport)
  • Token Has No Expiry (teleport)
  • Token Grants Auth System Role (teleport)
  • Token Grants Admin Role (teleport)
  • Trusted Cluster Has Broad Role Map (teleport)
  • Organization 2FA Not Enforced (terraform_cloud)
  • Organization SAML Not Enabled (terraform_cloud)
  • Organization Session Timeout Too Long (terraform_cloud)
  • Team Excessive Permissions (terraform_cloud)
  • Team Workspace Admin Access (terraform_cloud)
  • Team Secret Visibility (terraform_cloud)
  • User 2FA Not Enabled (terraform_cloud)
  • User Pending Invitation (terraform_cloud)
  • SSO Not Enforced (vercel)
  • Auto Join Enabled (vercel)
  • Excessive Owners (vercel)
  • Non-SSO Member (vercel)
  • Overly Broad Access (vercel)
  • Excessive Members (vercel)
  • Overprivileged Integration (vercel)
  • Token No Expiration (vercel)
  • Token Stale (vercel)
  • Token Overprivileged (vercel)
  • Project No Deployment Protection (vercel)
  • Member Unconfirmed (vercel)
  • Access Group Empty (vercel)
  • Excessive Admins (workato)
  • Inactive Member (workato)
  • Overprivileged Member (workato)
  • No Custom Roles (workato)
  • Empty Collaborator Group (workato)
  • Large Collaborator Group (workato)
  • No Custom Project Roles (workato)
  • Inactive Admin Member (workato)
  • API Platform Client Excessive Keys (workato)
  • Workspace Single Admin (workato)
  • Security Group With Excessive Members (workday)
  • Empty Security Group (workday)
  • Security Group With Broad Domain Access (workday)
  • Admin With App Password (workspace)
  • User With App Password (workspace)
  • OAuth App With Restricted Scopes (workspace)
  • Dormant Users (workspace)
  • Never Logged In Users (workspace)
  • OAuth App Critical Scopes (workspace)
  • OAuth App With Restricted Scopes Widely Authorized (workspace)
  • OAuth App AI With Data Scopes (workspace)
  • Super Admin Count Excessive (workspace)
  • Super Admin Redundancy Missing (workspace)
  • SSO Not Configured (workspace)
  • Gemini Unmanaged Actors (workspace)
  • Super Admin Account Recovery Enabled (workspace)
  • Gmail App Passwords Active (workspace)
  • Gmail Delegate Privileged (workspace)
  • Gmail Stale Delegates (workspace)
  • Weak Session Control (workspace)
  • Inactive User (zoom)
  • Excessive Admins (zoom)
  • SSO Not Enforced (zoom)
  • Encryption Not Required For Third-Party Endpoints (zoom)
  • Password Embedded In Join Link (zoom)
  • Join Before Host Allowed (zoom)
  • No Password For Instant Meetings (zoom)
  • No Password For PMI Meetings (zoom)

DORA-9.3 — Privileged access management

Strictly control, review and limit privileged and administrative access rights (Article 9(4)(c))

  • Role Targets Management API (auth0)
  • Bedrock Agent Overprivileged Execution Role (bedrock)
  • Bedrock Agent Cross-Account Role (bedrock)
  • Bedrock Agent No Guardrail (bedrock)
  • Bedrock Agent Excessive Action Groups (bedrock)
  • Admin With Privileged Role and No Admin-Unit Restriction (duo)
  • Owner-Role Administrator (duo)
  • Admin API Integration With Write Permission (duo)
  • Admin API Integration Can Manage Admins (duo)
  • Excessive Organization Admins (huggingface)
  • Member With Org Admin Role (huggingface)
  • Local Admin Account On Managed Mac (jamf)
  • Policy Ongoing Self Service Script (jamf)
  • API Role Overbroad (jamf)
  • Sudo User Without MFA (jumpcloud)
  • Passwordless Sudo Enabled (jumpcloud)
  • LangSmith Agent High Tool Diversity (langsmith)
  • LangSmith Agent External API Tools (langsmith)
  • Copilot Agent Excessive Connectors (m365)
  • Copilot Agent Sensitive Connector Write Access (m365)
  • Copilot Agent Maker Provided Credentials (m365)
  • Copilot Agent No User Consent Required (m365)
  • n8n Workflow Agent Excessive Credentials (n8n)
  • n8n Workflow Agent Sensitive Credential (n8n)
  • n8n Workflow Agent HTTP Request Node (n8n)
  • Scheduled Job Runs As Admin (servicenow)

DORA-9.4 — Strong authentication

Strong authentication mechanisms including multi-factor authentication and credential protection (Article 9(4)(d))

  • User MFA Not Enabled (akamai)
  • User Without MFA (atlassian)
  • Two-Step Verification Not Enforced (atlassian)
  • User Without MFA (auth0)
  • Connection MFA Disabled (auth0)
  • Tenant MFA Not Enforced (auth0)
  • Weak Connection Password Policy (auth0)
  • Connection Brute Force Protection Disabled (auth0)
  • Root Account MFA Not Enabled (aws)
  • User MFA Not Enabled (aws)
  • MFA Not Enabled (cloudflare)
  • Two-Factor Enforcement Disabled (cloudflare)
  • No MFA Requirement (cloudflare_access)
  • One-Time PIN Only Authentication (cloudflare_access)
  • No SAML or OIDC Provider (cloudflare_access)
  • User Not Enrolled in MFA (duo)
  • User in MFA Bypass Status (duo)
  • User Has Only SMS/Phone Factors (duo)
  • Orphan Phone Device (duo)
  • Landline Phone Factor (duo)
  • Unactivated Phone Device (duo)
  • Orphan Hardware/OTP Token (duo)
  • Org 2FA Not Required (github)
  • Member Without 2FA (github)
  • Group 2FA Not Enforced (gitlab)
  • Group 2FA Grace Period Too Long (gitlab)
  • Member Without 2FA (gitlab)
  • Group Owner Without 2FA (gitlab)
  • SSO Not Observed (huggingface)
  • User Without MFA (jumpcloud)
  • Password Never Expires (jumpcloud)
  • System MFA Not Required At Login (jumpcloud)
  • SSO Application Without SSO Configured (jumpcloud)
  • MFA Not Enabled (lastpass)
  • Admin Without MFA (lastpass)
  • Security Defaults Disabled (m365)
  • Guest Email OTP Not Enabled (m365)
  • CA MFA Not Enforced (m365)
  • Weak Authentication Factors Enabled (m365)
  • MFA Suspicious Activity Reporting Disabled (m365)
  • Admin Without MFA (okta)
  • MFA Not Enrolled (okta)
  • Phishing Resistant MFA Factors (okta)
  • Session MFA Not Required (okta)
  • Phishing Resistant Auth Policies (okta)
  • MFA Disabled (1password)
  • MFA Status Unknown (1password)
  • Sign-in Without MFA (1password)
  • SSO Disabled (pagerduty)
  • Advanced Permissions Disabled (pagerduty)
  • User Without MFA (pingone)
  • Weak Password Policy (pingone)
  • Password Policy Without History (pingone)
  • Password Policy Without Expiry (pingone)
  • Password Policy Low Complexity (pingone)
  • Sign-On Policy Without MFA (pingone)
  • Default Sign-On Policy Without MFA (pingone)
  • Environment MFA Disabled (pingone)
  • Admin Without MFA (salesforce)
  • User Without MFA (salesforce)
  • Weak Password Policy (salesforce)
  • Password Never Expires (salesforce)
  • No Password History (salesforce)
  • Weak Max Login Attempts (salesforce)
  • Short Lockout Interval (salesforce)
  • High Failed Logins (salesforce)
  • Member Without 2FA (sentry)
  • Admin Without 2FA (sentry)
  • MFA Not Enforced For Admins (servicenow)
  • Weak Password Policy (servicenow)
  • Staff MFA Disabled (shopify)
  • Account Owner MFA Disabled (shopify)
  • MFA Not Required (slack)
  • User No MFA (slack)
  • MFA Not Enabled (snowflake)
  • Authentication Policy No MFA (snowflake)
  • Cluster MFA Disabled (teleport)
  • Session MFA Not Enforced (teleport)
  • TOTP Without WebAuthn (teleport)
  • Local Auth Enabled With SSO (teleport)
  • Passwordless Without Hardware Key Policy (teleport)
  • Admin Action MFA Not Enforced (teleport)
  • Expired Certificate Disconnect Disabled (teleport)
  • Device Trust Disabled (teleport)
  • Role Does Not Require Session MFA (teleport)
  • Local User Has No MFA Device (teleport)
  • User Uses Only TOTP for MFA (teleport)
  • Workday User Without MFA Required (workday)
  • Weak Password Policy (workday)
  • SSO Not Enabled (workday)
  • MFA Not Enforced (workday)
  • Excessive Session Timeout (workday)
  • No Account Lockout Policy (workday)
  • Delegated Auth Certificate Expiring Soon (workday)
  • Delegated Auth Allows Local Fallback (workday)
  • Account Lockout Duration Too Short (workday)
  • Admin Without 2-Step Verification (workspace)
  • Admin 2-Step Verification Not Enforced (workspace)
  • Delegated Admin Without 2-Step Verification (workspace)
  • User Without 2-Step Verification (workspace)
  • User 2-Step Verification Not Enforced (workspace)
  • User Without MFA (zoom)
  • Admin Without MFA (zoom)

DORA-9.5 — Session management

Control session lifetime, timeout and re-authentication for ICT system access (Article 9(4)(d))

  • Long Tenant Session Lifetime (auth0)
  • Long Session Duration (cloudflare_access)
  • Long Global Session Duration (cloudflare_access)
  • Long WARP Authentication Session (cloudflare_access)
  • HTTPS Not Required (salesforce)
  • CSRF Protection Disabled (salesforce)
  • Session Timeout Too Long (salesforce)
  • No Clickjack Protection (salesforce)
  • Sessions Not Locked to Domain (salesforce)
  • No Forced Logout on Session Timeout (salesforce)
  • Session Cookies Not HttpOnly (salesforce)
  • Session Timeout Too Long (servicenow)

DORA-9.6 — Identity lifecycle and provisioning

Govern joiner/mover/leaver provisioning and timely deprovisioning of access (Article 9(4)(c))

  • Dormant User (auth0)
  • Terminated Employee With Active Login (bamboohr)
  • Stale BambooHR Login (bamboohr)
  • Orphaned BambooHR Login (bamboohr)
  • Active Employee Without Manager (bamboohr)
  • Active Employee Without Department (bamboohr)
  • Active Employee Without Work Email (bamboohr)
  • Bedrock Agent Failed Status (bedrock)
  • Bedrock Agent Not Prepared (7+ days) (bedrock)
  • Bedrock Agent Stale (bedrock)
  • Bedrock Agent Orphaned Owner (bedrock)
  • Disabled Member Present (chatgpt_enterprise)
  • Non-SCIM-Managed User (chatgpt_enterprise)
  • Cloudflare AI Gateway Agent Orphaned Owner (cloudflare)
  • Dormant User (duo)
  • Disabled User Still Has Factors (duo)
  • Locked Out User (duo)
  • Dormant Administrator (duo)
  • Member External Domain (dust)
  • Instance Uses Full Cloud-Platform API Scope (gcp)
  • Instance Does Not Block Project-Wide SSH Keys (gcp)
  • OS Login Disabled on Instance (gcp)
  • Cloud Function Default Service Account (gcp)
  • Terminated Employee Still Active (hibob)
  • Active Employee Without Manager (hibob)
  • Active Employee Without Department (hibob)
  • Active Employee Without Email (hibob)
  • Computer Stale Check-in (jamf)
  • Computer Activation Lock Enabled (jamf)
  • API Integration Disabled (jamf)
  • Locally Managed Account Outside SSO (jumpcloud)
  • LangSmith Agent Stale (langsmith)
  • LangSmith Agent High Error Rate (langsmith)
  • LangSmith Agent Orphaned Owner (langsmith)
  • Copilot Agent No Owner (m365)
  • Copilot Agent Never Published (30+ days) (m365)
  • Copilot Agent Quarantined (m365)
  • Copilot Agent Stale (90+ days inactive) (m365)
  • Copilot Agent Orphaned Owner (m365)
  • n8n Workflow Agent Stale (n8n)
  • n8n Workflow Agent Active Never Executed (n8n)
  • n8n Workflow Agent Inactive Webhook (n8n)
  • n8n Workflow Agent Orphaned Owner (n8n)
  • Excessive Org Admins (openrouter)
  • Workspace Member Has Admin Role (openrouter)
  • SCIM Group Without Workspace Mapping (openrouter)
  • Terminated Employee Still Active (personio)
  • Active Employee Without Manager (personio)
  • Active Employee Without Department (personio)
  • Active Employee Without Email (personio)
  • Disabled User Still Present (pingone)
  • Dormant User (pingone)
  • Empty Group (pingone)
  • Inactive User With Roles (servicenow)
  • User Locked Out (servicenow)
  • Default Admin Account Active (servicenow)
  • Workday Dormant User Account (workday)
  • Terminated User With Active Account (workday)
  • User Without Manager Assigned (workday)

DORA-9.7 — Encryption of data at rest and in transit

Protect data at rest, in use and in transit with appropriate cryptographic controls (Article 9(4)(b))

  • HSTS Not Enabled (akamai)
  • HSTS Max-Age Too Short (akamai)
  • HTTP/2 Not Enabled (akamai)
  • Origin Not Using TLS (akamai)
  • Edge Hostname Using Shared Cert (akamai)
  • Device Without Disk Encryption (chrome_enterprise)
  • SSL Encryption Disabled (cloudflare)
  • SSL Mode Flexible (cloudflare)
  • Always Use HTTPS Disabled (cloudflare)
  • Automatic HTTPS Rewrites Disabled (cloudflare)
  • HSTS Disabled (cloudflare)
  • Minimum TLS Version Weak (cloudflare)
  • Opportunistic Encryption Disabled (cloudflare)
  • TLS 1.3 Disabled (cloudflare)
  • TLS Mode Not Strict (cloudflare)
  • SSL Not Enforced (digitalocean)
  • No SSL Termination (digitalocean)
  • Insecure Backend (digitalocean)
  • HTTP Allowed (digitalocean)
  • SSL Policy Weak TLS Version (gcp)
  • Computer FileVault Disabled (jamf)
  • Computer FileVault Recovery Key Invalid (jamf)
  • Local Account FileVault Disabled (jamf)
  • System Full Disk Encryption Disabled (jumpcloud)
  • S/MIME Encryption Not Enforced (m365)
  • S/MIME Signing Not Enforced (m365)
  • S/MIME Clear Signing Not Enabled (m365)
  • S/MIME Cert Chain Without Root Not Included (m365)
  • S/MIME Cert Chain With Root Not Included (m365)
  • S/MIME Triple-Wrap Not Enabled (m365)
  • S/MIME CRL Timeout Too Long (m365)
  • S/MIME Encryption Algorithms Not Configured (m365)
  • S/MIME Buffer Encryption Not Enabled (m365)
  • Data Rekeying Disabled (snowflake)
  • Database Configured Without TLS (teleport)
  • Application Has TLS Verification Disabled (teleport)
  • S/MIME Not Configured (workspace)

DORA-9.8 — Cryptographic key and secret management

Manage cryptographic keys, secrets, tokens and credentials throughout their lifecycle (Article 9(4)(b))

  • Storage Key Not Rotated (azure)
  • Key Vault Key No Expiry (azure)
  • Key Vault Secret No Expiry (azure)
  • Password Manager Disabled (chrome_enterprise)
  • Service Token Without Expiry (cloudflare_access)
  • Stale Service Token (cloudflare_access)
  • Expired Service Token Not Deleted (cloudflare_access)
  • Unused API Key (datadog)
  • API Key Exceeds Maximum Age (datadog)
  • Stale API Token In Use (figma)
  • Cloud Function Plaintext Secrets in Environment (gcp)
  • Excessive Tokens Per Policy (grafana_cloud)
  • Non-Expiring Cloud Token (grafana_cloud)
  • Dormant Cloud Token (grafana_cloud)
  • Token With Wildcard Policy (grafana_cloud)
  • Recently Created Token Without Use (grafana_cloud)
  • Orphaned Access Policy (grafana_cloud)
  • Token Never Used After 30 Days (grafana_cloud)
  • Write-Capable Token Inactive for 30 Days (grafana_cloud)
  • Token Approval Policy Disabled (huggingface)
  • Variable Not Marked Sensitive (terraform_cloud)
  • Variable Set Global Scope (terraform_cloud)
  • Variable Plaintext Credentials (terraform_cloud)
  • API Platform Client No Key Rotation (workato)

DORA-9.9 — Network security and segmentation

Design and control network connections and segmentation to limit ICT risk propagation (Article 9(4)(e))

  • DNSSEC Not Enabled (akamai)
  • TSIG Not Enabled (akamai)
  • SOA Serial Stale (akamai)
  • IP Allowlist Policy Disabled (atlassian)
  • DNS Wildcard Record (cloudflare)
  • DNS Record Points to Private IP (cloudflare)
  • DNS Record Not Proxied (cloudflare)
  • Login from Residential Proxy (generic)
  • Login from Datacenter Proxy (generic)
  • High Confidence Proxy Login (generic)
  • Failed Login from Proxy (generic)
  • Admin Login from Proxy (generic)
  • No VPC (digitalocean)
  • No Firewall (digitalocean)
  • Allows All Inbound (digitalocean)
  • SSH Open To All (digitalocean)
  • Allows All Outbound (digitalocean)
  • Publicly Accessible (digitalocean)
  • Default VPC Used (digitalocean)
  • IP Forwarding Enabled on Instance (gcp)
  • Legacy VPC Network In Use (gcp)
  • Cloud SQL Authorized Networks Open to World (gcp)
  • Cloud Function Public Ingress (gcp)
  • Cloud Run Service Public Ingress (gcp)
  • IP Allowlist Disabled (incidentio)
  • IP Allowlist Enabled With No Rules (incidentio)
  • Instance Has Public IP (ovhcloud)
  • API Credential No IP Restriction (ovhcloud)
  • Webhook Private Destination (shopify)
  • No Network Policy (snowflake)
  • Network Policy Wildcard (snowflake)
  • Network Policy No Blocklist (snowflake)
  • Integration No Network Policy (snowflake)
  • No Network Restrictions Configured (teleport)
  • Overly Broad Network Allow Rule (teleport)
  • No IP Restrictions Configured (workday)

DORA-9.10 — Secure configuration and hardening

Maintain secure baseline configuration of ICT systems and manage configuration change (Article 9(2)/(4)(a))

  • Group With No Contracts (akamai)
  • WAF In Alert-Only Mode (akamai)
  • Rate Controls Disabled (akamai)
  • Slow POST Protection Disabled (akamai)
  • IP Firewall Not Configured (akamai)
  • Geo Firewall Not Configured (akamai)
  • WAF Policy Alert-Only Mode (akamai)
  • Rate Control Threshold Too Permissive (akamai)
  • Bot Management Disabled (akamai)
  • Edge Hostname IPv4 Only (akamai)
  • SureRoute Not Enabled (akamai)
  • Property No Origin Failover (akamai)
  • Property Caching Disabled (akamai)
  • CP Code Unused (akamai)
  • Account Protection Disabled (akamai)
  • Archived Workspace Not Deleted (anthropic)
  • Stale Workspace (anthropic)
  • Usage Spike Detected (anthropic)
  • Workspace Default Rate Limits (anthropic)
  • Web Search Tool Usage (anthropic)
  • Claude Code High Session Count (anthropic)
  • Rate Limit High Requests Per Minute (anthropic)
  • Mobile App Policy Disabled (atlassian)
  • Dynamic Client Registration Enabled (auth0)
  • S3 Bucket Encryption Disabled (aws)
  • S3 Bucket Versioning Disabled (aws)
  • S3 Bucket Logging Disabled (aws)
  • Unrestricted SSH Access (aws)
  • Unrestricted RDP Access (aws)
  • Unrestricted Egress (aws)
  • Default Security Group Has Rules (aws)
  • KMS Key Rotation Disabled (aws)
  • KMS Key Pending Deletion (aws)
  • KMS Key Disabled (aws)
  • Default VPC In Use (aws)
  • GuardDuty Not Enabled (aws)
  • EC2 IMDSv2 Not Enforced (aws)
  • EC2 Instance Has Public IP (aws)
  • RDS Publicly Accessible (aws)
  • RDS Storage Not Encrypted (aws)
  • RDS Backup Retention Too Short (aws)
  • Organization All Features Not Enabled (aws)
  • Resource Control Policies Not Used (aws)
  • Organization Account Security Alternate Contact Missing (aws)
  • Organization Account Suspended (aws)
  • Security Hub Not Enabled (aws)
  • Security Hub No Standards Enabled (aws)
  • Security Hub Critical Findings Unresolved (aws)
  • Security Hub High Findings Unresolved (aws)
  • Security Hub Auto-Enable Controls Disabled (aws)
  • Security Hub CIS Standard Not Enabled (aws)
  • NSG Unrestricted SSH (azure)
  • NSG Unrestricted RDP (azure)
  • NSG All Ports Open (azure)
  • NSG UDP Open (azure)
  • NSG Permissive Outbound (azure)
  • Network Watcher Disabled (azure)
  • Storage HTTPS Not Required (azure)
  • Storage Network Default Allow (azure)
  • Storage Minimum TLS (azure)
  • Storage Infrastructure Encryption Disabled (azure)
  • Storage Shared Key Enabled (azure)
  • Storage Blob Soft Delete Disabled (azure)
  • Storage Container Soft Delete Disabled (azure)
  • Key Vault Soft Delete Disabled (azure)
  • Key Vault Purge Protection Disabled (azure)
  • Key Vault Network ACLs Allow (azure)
  • Key Vault No Private Endpoint (azure)
  • Defender Servers Disabled (azure)
  • Defender App Service Disabled (azure)
  • Defender SQL Disabled (azure)
  • Defender Storage Disabled (azure)
  • Defender Containers Disabled (azure)
  • Defender Key Vault Disabled (azure)
  • Defender Resource Manager Disabled (azure)
  • Security Contact Email Missing (azure)
  • Security Contact Phone Missing (azure)
  • Security Alert Notifications Disabled (azure)
  • SQL TDE Disabled (azure)
  • SQL Firewall Allow Azure Services (azure)
  • SQL Firewall Unrestricted (azure)
  • SQL Minimum TLS (azure)
  • SQL Vulnerability Assessment Disabled (azure)
  • SQL Threat Detection Disabled (azure)
  • App Service HTTPS Disabled (azure)
  • App Service Minimum TLS (azure)
  • App Service FTP Enabled (azure)
  • App Service Remote Debugging Enabled (azure)
  • App Service HTTP/2 Disabled (azure)
  • Bedrock Guardrail Weak Content Filters (bedrock)
  • Bedrock No Guardrails Configured (bedrock)
  • Bedrock Flow References Draft Prompt (bedrock)
  • Bedrock Orphaned Knowledge Base (bedrock)
  • Empty Group (box)
  • Empty Group (chatgpt_enterprise)
  • Workspace Allows Unapproved Connectors (chatgpt_enterprise)
  • Non-Stable Browser Channel In Use (chrome_enterprise)
  • Browser Running Windows 10 (chrome_enterprise)
  • Widespread Outdated Browser Version (chrome_enterprise)
  • Telemetry Device Missing OS Version (chrome_enterprise)
  • Browser Not Reporting Version (chrome_enterprise)
  • Config Policies Disabled (circleci)
  • Config Policies Soft Fail (circleci)
  • Forked PR Builds Enabled (circleci)
  • Webhook Insecure URL (circleci)
  • Webhook Unverified TLS (circleci)
  • Stale Runner (circleci)
  • Schedule Non-Default Branch (circleci)
  • Pipeline Deprecated Image (circleci)
  • Webhook No Signing Secret (circleci)
  • Pipeline Machine Executor (circleci)
  • Pipeline Setup Remote Docker (circleci)
  • Excessive Orb Allowlist (circleci)
  • Runner Without Name (circleci)
  • Schedule Without Description (circleci)
  • Browser Integrity Check Disabled (cloudflare)
  • WAF Disabled (cloudflare)
  • Security Level Essentially Off (cloudflare)
  • Security Level Low (cloudflare)
  • Zone Settings Unavailable (cloudflare)
  • CORS Allows All Origins (cloudflare_access)
  • Application Hidden from App Launcher (cloudflare_access)
  • Service Token Without Name (cloudflare_access)
  • Email Not Verified (digitalocean)
  • Backups Disabled (digitalocean)
  • IPv6 Disabled (digitalocean)
  • No Droplets Attached (digitalocean)
  • Outdated Version (digitalocean)
  • No Backups (digitalocean)
  • Outdated Kubernetes Version (digitalocean)
  • Auto Upgrade Disabled (digitalocean)
  • Surge Upgrade Disabled (digitalocean)
  • No Garbage Collection (digitalocean)
  • Basic Tier (digitalocean)
  • Kubernetes HA Disabled (digitalocean)
  • Kubernetes No Registry Integration (digitalocean)
  • Database No Maintenance Window (digitalocean)
  • Database Single Node (digitalocean)
  • Droplet Powered Off (digitalocean)
  • AutoMod Rule Disabled (discord)
  • AutoMod Excessive Exemptions (discord)
  • Channel Excessive Permission Overwrites (discord)
  • Sign On Paper Enabled (docusign)
  • Signer Reassignment Enabled (docusign)
  • PowerForms Enabled (docusign)
  • No Signer Certificate Required (docusign)
  • Recipient Domain Validation Disabled (docusign)
  • No IP Restrictions (docusign)
  • Bulk Recipients Enabled (docusign)
  • Empty Group (dropbox)
  • Archived Team Folder (dropbox)
  • Admin API Integration Without IP Restriction (duo)
  • Integration Without Enforced Enrollment Policy (duo)
  • Inactive User Expiration Not Configured (duo)
  • No Lockout For Unenrolled Users (duo)
  • Weak Password Complexity (duo)
  • Short Minimum Password Length (duo)
  • Fraud Notification Email Disabled (duo)
  • No Authentication Lockout Threshold (duo)
  • Webhook Endpoint Not HTTPS (figma)
  • Webhook Without Passcode (figma)
  • Webhook Targets Raw IP Endpoint (figma)
  • Public Firewall Rule (gcp)
  • Firewall Rule Exposes Dangerous Port (gcp)
  • Firewall Rule Egress Open to World (gcp)
  • Bucket Versioning Disabled (gcp)
  • Security Contact Missing (gcp)
  • Essential Contacts Coverage Incomplete (gcp)
  • Instance Serial Port Enabled (gcp)
  • Shielded VM Disabled (gcp)
  • Default VPC In Use (gcp)
  • Cloud SQL Instance Has Public IP (gcp)
  • Cloud SQL SSL Not Required (gcp)
  • MySQL skip_show_database Not Enabled (gcp)
  • MySQL local_infile Enabled (gcp)
  • Cloud SQL Backup Not Enabled (gcp)
  • Cloud KMS Key Rotation Period Exceeds 90 Days (gcp)
  • Cloud KMS Encryption Key Has No Rotation Schedule (gcp)
  • Cloud KMS Key Primary Version Not Active (gcp)
  • Cloud KMS Key Uses Software Protection Level (gcp)
  • Secret Manager Secret Has No Rotation (gcp)
  • Secret Manager Secret Has No Versioning (gcp)
  • GKE Network Policy Disabled (gcp)
  • GKE Private Cluster Disabled (gcp)
  • GKE Shielded Nodes Disabled (gcp)
  • GKE Release Channel Not Set (gcp)
  • GKE Binary Authorization Disabled (gcp)
  • GKE Database Encryption Disabled (gcp)
  • GKE Intranode Visibility Disabled (gcp)
  • GKE Logging Disabled (gcp)
  • GKE Node Pool Auto-Upgrade Disabled (gcp)
  • Cloud Logging Sink Missing (gcp)
  • Log Metric for Project Ownership Missing (gcp)
  • Log Metric for Audit Config Changes Missing (gcp)
  • Log Metric for Custom Role Changes Missing (gcp)
  • Alert Policy Disabled (gcp)
  • Alert Policy Has No Notification Channels (gcp)
  • Log Metric Project Ownership Alert Missing (gcp)
  • Log Metric Audit Config Alert Missing (gcp)
  • Log Metric Custom Role Alert Missing (gcp)
  • DNS DNSSEC Disabled (gcp)
  • DNS DNSSEC RSASHA1 Key-Signing Key (gcp)
  • DNS DNSSEC RSASHA1 Zone-Signing Key (gcp)
  • DNS Logging Disabled (gcp)
  • No IAM Deny Policy Configured (gcp)
  • IAM Deny Policy Does Not Cover Service Account Key Creation (gcp)
  • IAM Deny Policy Has Overly Broad Exception Principals (gcp)
  • Repo Secret Scanning Disabled (github)
  • Repo Dependabot Disabled (github)
  • Public Repo Without Security Policy (github)
  • Actions Allow All External (github)
  • Webhook Insecure URL (github)
  • Org Dependabot Alerts Disabled (github)
  • Org Secret Scanning Disabled (github)
  • Actions Runner Allows Public Repos (github)
  • GitHub Actions Enabled For All Repositories (github)
  • Org Web Commit Signoff Not Required (github)
  • Repo Secret Scanning Push Protection Disabled (github)
  • Actions SHA Pinning Not Required (github)
  • Actions Selected-Actions Allowlist Pattern Unpinned (github)
  • Group No IP Restriction (gitlab)
  • Project Container Scanning Disabled (gitlab)
  • Project Discussions Not Required (gitlab)
  • Shared Runner Not Locked (gitlab)
  • Active Runner Offline (gitlab)
  • Integration Insecure URL (gitlab)
  • No Compliance Framework (gitlab)
  • Project Pipeline Not Required (gitlab)
  • Runner Not Locked to Project (gitlab)
  • Project Shared Runners Enabled (gitlab)
  • Recent Sensitive Change (google_ads)
  • Recent Admin Role Change (google_ads)
  • Direct Access Data Source (grafana)
  • Data Source Basic Auth (grafana)
  • Data Source TLS Skip Verify (grafana)
  • Data Source With Credentials (grafana)
  • No Alert Rules Configured (grafana)
  • External Contact Point (grafana)
  • Broad Mute Timing (grafana)
  • Unsigned Plugin (grafana)
  • Community Plugin (grafana)
  • Outdated Plugin (grafana)
  • Paused Alert Rules (grafana)
  • Alert Rules Without Contact Points (grafana)
  • Token Expiring Within 14 Days (grafana_cloud)
  • Stale Access Policy Not Updated in 180 Days (grafana_cloud)
  • Workflow Has No Steps (incidentio)
  • User No Slack Linked (incidentio)
  • Computer SIP Disabled (jamf)
  • Computer Gatekeeper Disabled (jamf)
  • Computer Firewall Disabled (jamf)
  • Computer Remote Desktop Enabled (jamf)
  • Computer Recovery Lock Missing (jamf)
  • Computer Secure Boot Reduced (jamf)
  • Configuration Profile User Removable (jamf)
  • API Integration Long Token Lifetime (jamf)
  • SSO Not Enabled (jamf)
  • SSO Bypass Allowed (jamf)
  • SSO Not Enforced For Enrollment (jamf)
  • SSO Not Enforced For macOS Self Service (jamf)
  • System SSH Password Authentication Enabled (jumpcloud)
  • System SSH Root Login Enabled (jumpcloud)
  • Dynamic User Group Without Restriction (jumpcloud)
  • Weak Master Password (lastpass)
  • Very Weak Master Password (lastpass)
  • Empty Vault User (lastpass)
  • Stale Master Password (lastpass)
  • Master Password Never Changed (lastpass)
  • Admin Stale Master Password (lastpass)
  • Low Shared Folder Security Score (lastpass)
  • Critically Low Shared Folder Score (lastpass)
  • Admin With Weak Master Password (lastpass)
  • Empty Shared Folder (lastpass)
  • Admin Master Password Never Changed (lastpass)
  • Self-Service Subscriptions Enabled (m365)
  • Risk-Based Consent Not Configured (m365)
  • Group Naming Convention Not Configured (m365)
  • Customer Lockbox Not Enabled (m365)
  • Copilot License Assigned (m365)
  • Unverified Domain (m365)
  • Unverified Federated Domain (m365)
  • SPF Record Missing (m365)
  • DMARC Record Missing (m365)
  • DKIM Record Missing (m365)
  • Multi-Tenant App Without Verified Publisher (m365)
  • SMTP Auth Not Disabled Globally (m365)
  • External Recipient Mail Tips Disabled (m365)
  • Mail Tips Not Fully Enabled (m365)
  • Mailbox SMTP Auth Not Disabled (m365)
  • OWA Clickjacking Protection Not Set (m365)
  • ActiveSync Integration Enabled for OWA (m365)
  • On-Send Add-ins Enabled in OWA (m365)
  • No File Types Blocked in OWA (m365)
  • No MIME Types Blocked in OWA (m365)
  • Unknown File Types Not Blocked (m365)
  • Transport Rule Includes BCC (m365)
  • Transport Rule Processes External Sender (m365)
  • Transport Rule Deletes Messages (m365)
  • Transport Rule Disabled (m365)
  • Remote Domain Trusted Inbound Enabled (m365)
  • Remote Domain Trusted Outbound Enabled (m365)
  • Remote Domain Auto-Reply Enabled (m365)
  • Remote Domain Delivery Reports Enabled (m365)
  • Remote Domain NDR Enabled (m365)
  • Remote Domain TNEF Enabled (m365)
  • Distribution List Hidden From GAL (m365)
  • Mailbox Move Enabled for Org Relationships (m365)
  • Common Attachment Types Filter Disabled (m365)
  • Common Attachment Types Missing (m365)
  • Zero-Hour Auto Purge Disabled (m365)
  • Admin Malware Notifications Disabled (m365)
  • Blocked File Type Action Not Quarantine (m365)
  • Anti-Phishing Spoof Detection Weak (m365)
  • Anti-Phishing First Contact Tip Disabled (m365)
  • Outbound Spam Thresholds Not Configured (m365)
  • Inbound Spam Bulk Threshold Too High (m365)
  • SPF Hard Fail Not Enabled (m365)
  • High Confidence Spam Not Quarantined (m365)
  • Connection Filter Not Configured (m365)
  • Outbound Spam Notification Disabled (m365)
  • Suspicious Outbound Copy Not Enabled (m365)
  • Comprehensive Spam Marking Disabled (m365)
  • Sensitivity Labels Not Configured (m365)
  • Copilot Inventory Degraded (m365)
  • Agent Uses Code Interpreter (mistral)
  • Agent References Org-Shared Library (mistral)
  • Agent Deployed Without Guardrails (mistral)
  • Stale Page (notion)
  • Orphaned Page Without Parent (notion)
  • Stale Database (notion)
  • Password Policy No Symbol Requirement (okta)
  • Password Policy No Username Exclusion (okta)
  • Account Lockout Auto-Unlock Too Fast (okta)
  • Inactive Application (okta)
  • ThreatInsight Not Blocking (okta)
  • ThreatInsight Excluded Zones (okta)
  • Anonymizer Block Absent (okta)
  • SSO Policy Modified (1password)
  • SSO Disabled (1password)
  • Signing Key Changed (1password)
  • Firewall Rule Changed (1password)
  • Project Without Rate Limits (openai)
  • Active Project Without Users (openai)
  • Usage Anomaly (openai)
  • Excessive API Request Volume (openai)
  • Disproportionate Output Tokens (openai)
  • Usage Category Anomaly (openai)
  • Certificate Expiring Soon (openai)
  • Inactive Certificate (openai)
  • Certificate Without Project Scope (openai)
  • API Key Without Spend Limit (openrouter)
  • API Key Without Expiry (openrouter)
  • Disabled API Key Not Deleted (openrouter)
  • Stale API Key (openrouter)
  • BYOK Spend Uncapped (openrouter)
  • API Key Spend Limit Without Reset Interval (openrouter)
  • API Key Relies Solely On Workspace Default Guardrail (openrouter)
  • Workspace Without Guardrails (openrouter)
  • Workspace Without Spending Budget (openrouter)
  • Guardrail Without Content Filters (openrouter)
  • Guardrail Without Key Or Member Assignments (openrouter)
  • API Key Sprawl (openrouter)
  • BYOK Credential Disabled Not Deleted (openrouter)
  • BYOK Spend Ungoverned (openrouter)
  • Excessive BYOK Provider Diversity (openrouter)
  • Workspace Has Excessive Members (openrouter)
  • SCIM Mapping Stale (openrouter)
  • Preset Targets Model Outside Workspace Allowlist (openrouter)
  • Disabled Preset Not Deleted (openrouter)
  • Stale Preset (openrouter)
  • Stale File (openrouter)
  • Oversized File (openrouter)
  • Excessive Model Diversity (openrouter)
  • Developer Mode Enabled (ovhcloud)
  • IAM Policy No Identities (ovhcloud)
  • OAuth2 Client No Description (ovhcloud)
  • Cloud Project Suspended (ovhcloud)
  • Instance Using Default Image (ovhcloud)
  • Instance In Shelved State (ovhcloud)
  • Instance Rescue Mode (ovhcloud)
  • User Without Notification Rules (pagerduty)
  • User Without Contact Methods (pagerduty)
  • Empty Team (pagerduty)
  • Service Without Integrations (pagerduty)
  • Service Without Acknowledgement Timeout (pagerduty)
  • Escalation Policy Without Services (pagerduty)
  • Schedule Not Linked to Escalation Policy (pagerduty)
  • Unused Permission Set (salesforce)
  • Webhook XML Format (shopify)
  • Store Setup Required (shopify)
  • Low Data Retention (snowflake)
  • SSO Login Page Disabled (snowflake)
  • No SSO Configured (snowflake)
  • No SCIM Configured (snowflake)
  • Warehouse No Auto Suspend (snowflake)
  • Warehouse No Auto Resume (snowflake)
  • Warehouse No Resource Monitor (snowflake)
  • Warehouse Oversized (snowflake)
  • No Account Resource Monitor (snowflake)
  • Resource Monitor Notify Only (snowflake)
  • Archived Team (teams)
  • Skype for Business Interop Enabled (teams)
  • Trusted Cluster Is Disabled (teleport)
  • No Client Idle Timeout Configured (teleport)
  • Node Running Outdated Teleport Version (teleport)
  • Organization Force Delete Allowed (terraform_cloud)
  • Organization Default Execution Mode Local (terraform_cloud)
  • Workspace Auto Apply Enabled (terraform_cloud)
  • Workspace Destroy Plan Allowed (terraform_cloud)
  • Workspace No VCS Connection (terraform_cloud)
  • Workspace Drift Detection Disabled (terraform_cloud)
  • Workspace Outdated Terraform Version (terraform_cloud)
  • Variable Set Priority Override (terraform_cloud)
  • Agent Pool Organization Scoped (terraform_cloud)
  • VCS Connection Organization Scoped (terraform_cloud)
  • Run Task Advisory Enforcement (terraform_cloud)
  • Notification No HMAC Token (terraform_cloud)
  • SSH Key Present (terraform_cloud)
  • Deployment Protection Disabled (vercel)
  • Strict Deployment Protection Disabled (vercel)
  • Fork Protection Disabled (vercel)
  • No Target Restriction (vercel)
  • SSL Not Verified (vercel)
  • Domain Expiring Soon (vercel)
  • Stale Integration (vercel)
  • Insecure Log Drain (vercel)
  • Auto Expose System Environment Variables (vercel)
  • Workspace Recipe Limit (workato)
  • Broken Connection (workato)
  • Stale Connection (workato)
  • Workspace Trial Expired (workato)
  • Recipe Never Executed (workato)
  • Recipe Long Stopped (workato)
  • Connection Never Authorized (workato)
  • Recipe Excessive Application Integrations (workato)
  • Domain Not Verified (workspace)
  • DKIM Not Configured (workspace)
  • Group Spam Moderation Disabled (workspace)
  • Gemini Not Licensed (workspace)
  • Gemini Enabled Without DLP (workspace)
  • Gemini Active Without DLP (workspace)
  • Automatic Email Forwarding Enabled (workspace)
  • IMAP Access Enabled (workspace)
  • POP Access Enabled (workspace)
  • Drive Shared Drive Creation Unrestricted (workspace)
  • Shared Drive No Admin Restrictions (workspace)
  • Shared Drive Folder Sharing Unrestricted (workspace)
  • Chat Webhooks Enabled (workspace)
  • Gmail Confidential Mode Disabled (workspace)
  • Gmail Send-As External Alias (workspace)
  • Gmail Unverified Send-As Alias (workspace)
  • Meet Recording Unrestricted (workspace)
  • Weak Password Policy (workspace)
  • Spoofing Protection Disabled (workspace)
  • Gmail Encrypted Attachment Protection Disabled (workspace)
  • Gmail Shortener Scanning Disabled (workspace)
  • No Meeting Password Required (zoom)
  • Waiting Room Disabled (zoom)
  • Unauthenticated Join Allowed (zoom)
  • Local Recording Enabled (zoom)
  • Cloud Recording No Auto-Delete (zoom)
  • Weak Password Policy (zoom)
  • Chat File Transfer Enabled (zoom)
  • Automatic Recording Enabled (zoom)
  • Auto Save Meeting Chats (zoom)
  • Continuous Meeting Chat Enabled (zoom)
  • Email Notification On Join Before Host Disabled (zoom)
  • Far End Camera Control Enabled (zoom)
  • Host Video On By Default (zoom)
  • Guest Participant Identification Disabled (zoom)
  • Participant Video On By Default (zoom)
  • Join/Leave Sound Disabled (zoom)
  • Remote Control Enabled (zoom)
  • Request To Unmute Not Required (zoom)
  • Screen Sharing Allowed For All Participants (zoom)
  • Screen Share Watermark Disabled (zoom)

DORA-9.11 — Data protection and leakage prevention

Prevent unauthorized disclosure, corruption or loss of data held in ICT systems (Article 9(3))

  • Claude Retention Set To Indefinite (anthropic)
  • Claude Content Redaction Disabled (anthropic)
  • Claude Code Execution Egress Open (anthropic)
  • Secret Detected In Claude Conversation (anthropic)
  • Storage Public Blob Access (azure)
  • No Collaboration Whitelist Entries (box)
  • Broad Inbound Collaboration Whitelist (box)
  • Bidirectional Collaboration Whitelist (box)
  • Secret Detected In ChatGPT Conversation (chatgpt_enterprise)
  • Excessive Env Vars (circleci)
  • Pipeline Hardcoded Secrets (circleci)
  • Dashboard Public Sharing (datadog)
  • Dashboard Public URL (datadog)
  • Plain Text Env Var (digitalocean)
  • Content Filter Not Full (discord)
  • Guild Publicly Discoverable (discord)
  • Widget Enabled (discord)
  • No AutoMod Rules (discord)
  • No Keyword Filtering (discord)
  • No Spam Protection (discord)
  • No Mention Spam Protection (discord)
  • NSFW Channel (discord)
  • Public Shared Links Allowed by Default (dropbox)
  • Shared Folders Open to Anyone (dropbox)
  • External Folder Join Unrestricted (dropbox)
  • Folder Link Restriction Not Enforced (dropbox)
  • Open Space With Connected Data (dust)
  • Agent Shared Broadly (dust)
  • Sensitive Data Source In Open Space (dust)
  • BigQuery Dataset Public Access (gcp)
  • Public Org Repository (huggingface)
  • Public Gated Repository Misconfiguration (huggingface)
  • Public Status Page (incidentio)
  • Workflow Unconstrained on All Incidents (incidentio)
  • Vault Exported (1password)
  • Prompt/Response Logging Enabled (openrouter)
  • Logging At Full Sampling (openrouter)
  • Observability Broadcast Enabled (openrouter)
  • Data-Discount Logging Enabled (openrouter)
  • LLM Data Exported To External Sink (openrouter)
  • Guardrail Without Zero Data Retention Enforcement (openrouter)
  • Guardrail With Partial Zero Data Retention Enforcement (openrouter)
  • Guardrail Allows Training Data (openrouter)
  • Permissive Privacy Posture (openrouter)
  • Storage Container Public (ovhcloud)
  • Public Sharing Model (salesforce)
  • External Access Read Write (salesforce)
  • Shared Issues Enabled (sentry)
  • Enhanced Privacy Disabled (sentry)
  • Open Membership (sentry)
  • Event Attachments Access (sentry)
  • Data Scrubber Disabled (sentry)
  • Data Scrubber Defaults Disabled (sentry)
  • Debug Files Access (sentry)
  • Password Protection Disabled (shopify)
  • Webhook Using HTTP (shopify)
  • Webhook External Destination (shopify)
  • Unauthenticated Read Customers Scope (shopify)
  • Write Customers Read Payment Scope (shopify)
  • No Storage Integration Required (snowflake)
  • Unload To Inline URL (snowflake)
  • Unload To Internal Stages (snowflake)
  • Outbound Share Review (snowflake)
  • Share To Many Accounts (snowflake)
  • Share Listing Unrestricted (snowflake)
  • Public Team (teams)
  • External Shared Channel (teams)
  • External Messaging Enabled (teams)
  • Unrestricted External Federation (teams)
  • Workspace Global Remote State (terraform_cloud)
  • Sensitive Env Var Policy Disabled (vercel)
  • IP Visibility Enabled (vercel)
  • Public Source (vercel)
  • Directory Listing Enabled (vercel)
  • Plain Text Secret (vercel)
  • Exposed to Preview (vercel)
  • Recipe Integrates with Sensitive Application (workato)

DORA-9.12 — Data sharing and external exposure

Control external sharing, third-party integrations and delegated access to entity data (Article 9(4)(e))

  • Jira Project Public Access (atlassian)
  • Confluence Space Anonymous Access (atlassian)
  • Confluence Space Public Links (atlassian)
  • Jira Project Externally Shared (atlassian)
  • Confluence Space Externally Shared (atlassian)
  • Archived Confluence Space With Anonymous Access (atlassian)
  • Application Risky Grant Type (auth0)
  • Public Client With Confidential Grant (auth0)
  • Wildcard Callback URL (auth0)
  • S3 Bucket Public Access Not Blocked (aws)
  • S3 Bucket Policy Public (aws)
  • Bedrock Agent Multiple Knowledge Bases (bedrock)
  • Bedrock Agent No Customer-Managed Encryption (bedrock)
  • Bedrock Agent Session Memory Enabled (bedrock)
  • Bedrock Agent Long Session TTL (bedrock)
  • Group Allows External Collaborator Invitations (box)
  • Outbound Collaboration Whitelist Entry (box)
  • Excessive Collaboration Whitelist Entries (box)
  • Dashboard Publicly Shared and Writable (datadog)
  • Suggest Members Enabled (dropbox)
  • Public Storage Bucket (gcp)
  • Group Public Visibility (gitlab)
  • Group Sharing Unlocked (gitlab)
  • Group Forking Allowed Outside (gitlab)
  • Group Sharing Outside Organization (gitlab)
  • Public Project (gitlab)
  • Active External Data Link (google_ads)
  • Overly Permissive Dashboard (grafana)
  • Public Dashboard (grafana)
  • Overly Permissive Folder (grafana)
  • Workflow Accesses Private Data (incidentio)
  • LangSmith Agent Dataset Access (langsmith)
  • LangSmith Agent Retriever Tools (langsmith)
  • Shared Folder Credential Export Permission (lastpass)
  • Guest Access to Group Content Not Restricted (m365)
  • Organization Sharing Enabled (m365)
  • Default Calendar Sharing Too Permissive (m365)
  • Default Group Access Public (m365)
  • External Forwarding on Mailbox (m365)
  • Mailbox Delivers to Both Mailbox and Forward (m365)
  • Forwarding SMTP to External (m365)
  • Forwarding Address Configured (m365)
  • LinkedIn Integration Enabled in OWA (m365)
  • Mobile Contact Sync Enabled in OWA (m365)
  • Transport Rule Redirects Externally (m365)
  • Transport Rule Forwards Outside Org (m365)
  • Remote Domain Auto-Forwarding Allowed (m365)
  • Default Sharing Policy Allows External (m365)
  • Sharing Policy Allows External Domains (m365)
  • Distribution List Allows External Senders (m365)
  • Distribution Group Open Join Policy (m365)
  • Public Microsoft 365 Group (m365)
  • Outbound Spam External Forwarding Allowed (m365)
  • Copilot Agent Tenant-Wide Sharing (m365)
  • Copilot Agent Broad Sharing (m365)
  • Copilot Agent Web Search Enabled (m365)
  • Library Shared Org-Wide With Documents (mistral)
  • Library Shared Org-Wide Editable (mistral)
  • n8n Workflow Agent Database Access (n8n)
  • n8n Workflow Agent File Access (n8n)
  • n8n Workflow Agent Code Execution (n8n)
  • Publicly Shared Page (notion)
  • Stale Public Page (notion)
  • Publicly Shared Database (notion)
  • Root Level Public Page (notion)
  • Stale Publicly Shared Database (notion)
  • Root Level Public Database (notion)
  • Inline Public Database (notion)
  • Extension Disabled (pagerduty)
  • Webhook External URL (pagerduty)
  • Webhook Inactive (pagerduty)
  • Application Risky Grant Type (pingone)
  • Application Public Client Without Auth (pingone)
  • Application Wildcard Redirect URI (pingone)
  • Disabled Application Still Present (pingone)
  • OAuth App Long Token Lifespan (servicenow)
  • OAuth App Insecure Redirect (servicenow)
  • Insecure Plugin Active (servicenow)
  • Integration Using Basic Auth (servicenow)
  • Webhook Customer Data Topic (shopify)
  • API Client No IP Restriction (workato)
  • Excessive API Clients (workato)
  • API Endpoint Inactive (workato)
  • API Platform Client Static Auth Token (workato)
  • API Platform Client No Active Keys (workato)
  • Developer API Client with Admin Role (workato)
  • Stale Integration System (workday)
  • Integration With Excessive Scope (workday)
  • Group Allows External Members (workspace)
  • Group Allows External Posting (workspace)
  • Group Allows Open Join (workspace)
  • Group Public Conversations (workspace)
  • Group Domain-Wide Membership Visibility (workspace)
  • Group Contact Owner Anyone (workspace)
  • Group Discoverable by Anyone (workspace)
  • Mail Delegation Enabled (workspace)
  • Drive External Sharing Enabled (workspace)
  • Drive Link Sharing Anyone (workspace)
  • Drive Sharing Outside Organization (workspace)
  • Drive Publish to Web Allowed (workspace)
  • Drive External Shared Drives Allowed (workspace)
  • Drive File Public Sharing (workspace)
  • Drive File Publicly Indexed (workspace)
  • Drive File Link Sharing Enabled (workspace)
  • Drive File Shared With Personal Email (workspace)
  • Drive File External Edit Access (workspace)
  • Drive Shared Drive Has External Members (workspace)
  • Drive File Owner Is External (workspace)
  • Drive File Shared With External Domain (workspace)
  • Drive File Stale External Sharing (workspace)
  • Drive File Excessive Permissions (workspace)
  • Drive File External Commenter Access (workspace)
  • Drive File Broad Internal Sharing (workspace)
  • Drive File Org-Wide Link Sharing (workspace)
  • Drive User Excessive External Sharing (workspace)
  • Shared Drive Allows External Users (workspace)
  • Shared Drive Allows Non-Members (workspace)
  • Shared Drive No Download Restriction (workspace)
  • Shared Drive Has External Members (workspace)
  • Chat External Access Enabled (workspace)
  • DLP Rules Not Configured (workspace)
  • Gmail Filter Forwards Externally (workspace)
  • Gmail Multiple Forwarding Destinations (workspace)
  • Gmail Suspicious Forwarding (workspace)
  • Live Streaming Enabled (zoom)

DORA-9.13 — Device and endpoint trust

Ensure devices accessing ICT systems meet defined security and trust requirements (Article 9(4)(d))

  • User Exempt from Device Limits (box)
  • No Device Pins Configured (box)
  • Widely Deployed Extension With Risky Permissions (chrome_enterprise)
  • Browser Running on Unsupported OS (chrome_enterprise)
  • Admin-Forced Extension With Risky Permissions (chrome_enterprise)
  • Shadow IT Extension Widely Deployed (chrome_enterprise)
  • Device Running Outdated OS (Telemetry) (chrome_enterprise)
  • EMM Not Required (dropbox)
  • Stale Web Session (dropbox)
  • Stale Desktop Session (dropbox)
  • Excessive Device Sessions (dropbox)
  • Mobile Device Unsupervised (jamf)
  • Mobile Device Unmanaged (jamf)
  • System Agent Inactive (jumpcloud)

DORA-10 — Detection

Mechanisms to promptly detect anomalous activities and ICT incidents (Article 10)

DORA-10.1 — Logging and audit trails

Record and retain logs and audit trails of activity across ICT systems (Article 10(1)/(3))

  • No Recent Audit Events (auth0)
  • Management API Change Event (auth0)
  • CloudTrail Not Logging (aws)
  • CloudTrail Log Validation Disabled (aws)
  • CloudTrail Not Multi-Region (aws)
  • CloudTrail Data Events Disabled (aws)
  • VPC Flow Logs Disabled (aws)
  • AWS Config Not Recording (aws)
  • NSG Flow Logs Disabled (azure)
  • Key Vault Diagnostic Logging Disabled (azure)
  • SQL Auditing Disabled (azure)
  • SQL Audit Retention Short (azure)
  • App Service Logging Disabled (azure)
  • Diagnostic Retention Short (azure)
  • Alert Policy Assignment Missing (azure)
  • Alert NSG Create Missing (azure)
  • Alert NSG Delete Missing (azure)
  • Alert Security Solution Create Missing (azure)
  • Alert Security Solution Delete Missing (azure)
  • Alert SQL Firewall Missing (azure)
  • Alert Disabled (azure)
  • Bedrock Model Invocation Logging Disabled (bedrock)
  • Audit Logging Disabled (datadog)
  • Audit Log Retention Period (datadog)
  • Audit Retention Below Critical Threshold (datadog)
  • Monitoring Disabled (digitalocean)
  • Office Add-in Disabled (dropbox)
  • Suspended Member Not Removed (dropbox)
  • Account Not Org-Scoped (No Audit Visibility) (figma)
  • Activity Permission Change Event (figma)
  • Activity Member Role Change Event (figma)
  • Audit Logging Not Enabled (gcp)
  • Data Access Logs Incomplete (gcp)
  • Subnet Flow Logs Disabled (gcp)
  • PostgreSQL log_connections Not Enabled (gcp)
  • PostgreSQL log_disconnections Not Enabled (gcp)
  • PostgreSQL log_min_messages Below WARNING (gcp)
  • PostgreSQL log_min_error_statement Above ERROR (gcp)
  • PostgreSQL log_min_duration_statement Not Disabled (gcp)
  • PostgreSQL pgaudit Extension Not Enabled (gcp)
  • Audit Logs Unavailable (huggingface)
  • No Recent Directory Insights Events (jumpcloud)
  • Global Mailbox Auditing Disabled (m365)
  • Mailbox Audit Bypass Configured (m365)
  • Mailbox Auditing Disabled (m365)
  • Shared Mailbox Sent-As Not Audited (m365)
  • Shared Mailbox Sent-On-Behalf Not Audited (m365)
  • Non-Shared Mailbox Audit Bypass (m365)
  • User Mailbox Auditing Disabled (m365)
  • Unified Audit Log Not Enabled (m365)
  • Audit Log Anonymous Actor (notion)
  • Master Password Changed (1password)
  • Sensitive Audit Event (openai)
  • Session Recording Disabled (teleport)
  • Session Recording in Async Mode (teleport)
  • Session Recording in Proxy Mode (teleport)
  • Proxy Host Key Checks Disabled (teleport)
  • Role Disables Session Recording (teleport)
  • Audit Log Using Local Filesystem Storage (teleport)
  • No Log Drain (vercel)
  • Log Drain Disabled (vercel)
  • Audit Logging Disabled (workday)

DORA-10.2 — Anomaly and threat detection

Detect anomalous activity, including performance issues and threat indicators (Article 10(1))

  • Safe Browsing Disabled (chrome_enterprise)
  • Login from Disallowed Country (generic)
  • Login from New Country (generic)
  • Impossible Travel Login (generic)

DORA-10.3 — Detection coverage review

Review and test detection mechanisms and alert thresholds for adequate coverage (Article 10(2)/(4))

DORA-11 — Response and Recovery

ICT business continuity, response and recovery capability (Articles 11-12)

DORA-11.1 — ICT business continuity policy

A documented ICT business continuity policy covering ICT-supported business functions (Article 11(1))

DORA-11.2 — Response and recovery plans

Response and recovery plans with defined objectives, activated and tested for ICT incidents (Article 11(3))

DORA-12.1 — Backup policy and procedures

Backup policies and procedures defining scope, frequency and retention of backups (Article 12(1))

  • No Retention Policies Defined (box)
  • Retired Retention Policy (box)
  • Short Retention Period (box)
  • Modifiable Retention Policy (box)
  • Permanent Delete Disposition Action (box)
  • No Indefinite Retention Policies (box)
  • Single Node Cluster (digitalocean)
  • No Health Check (digitalocean)
  • Suspended Account in MCC Hierarchy (google_ads)
  • Org Credit Balance Depleted (openrouter)

DORA-12.2 — Restoration and recovery testing

Test restoration from backup and recovery procedures, isolated from production systems (Article 12(2))

DORA-13 — Learning and Communication

Post-incident learning, awareness and crisis communication (Articles 13-14)

DORA-13.1 — Post-incident review and lessons learned

Conduct post-incident reviews and feed findings back into the ICT risk framework (Article 13(2))

DORA-13.2 — ICT security awareness and training

Deliver ICT security awareness programs and digital operational resilience training to staff (Article 13(6))

DORA-14.1 — Crisis communication plan

Communication plans for disclosing ICT incidents to clients, counterparts and the public (Article 14)

DORA-17 — ICT Incident Management

Detect, manage, classify and report ICT-related incidents (Articles 17-19)

DORA-17.1 — ICT incident management process

A documented process to detect, manage, log and follow up on ICT-related incidents (Article 17(1))

DORA-17.2 — Incident detection and recording

Record all ICT-related incidents and significant cyber threats with defined roles and escalation (Article 17(2)/(3))

  • Single Responder Escalation (incidentio)
  • Single Rotation Schedule (incidentio)
  • Schedule Without Active Shift (incidentio)
  • Workflow Disabled or Error (incidentio)
  • Workflow Ignores Step Errors (incidentio)
  • Alert Source No Auto-Resolve (incidentio)
  • Alert Route No Escalation Path (incidentio)
  • Alert Route No Grouping (incidentio)
  • Escalation Path No Current Responders (incidentio)
  • Alert Source Auto-Resolve Timeout Too Long (incidentio)
  • Escalation Path Shallow (incidentio)
  • Service Without Escalation Policy (pagerduty)
  • Possibly Abandoned Service (pagerduty)
  • Service Without Auto-Resolve (pagerduty)
  • Single User Escalation Rule (pagerduty)
  • Escalation Policy Without Schedule (pagerduty)
  • Escalation Policy Without Loops (pagerduty)
  • Single User Schedule (pagerduty)
  • Incident Auto-Assignment Disabled (servicenow)
  • Change Approval Not Required (servicenow)
  • Change Risk Assessment Disabled (servicenow)

DORA-18.1 — Incident classification

Classify ICT incidents against the major-incident criteria and determine their impact (Article 18)

DORA-19.1 — Reporting to the competent authority

Submit initial, intermediate and final reports on major ICT incidents to the competent authority (Article 19(4))

DORA-19.2 — Client and user notification

Inform affected clients and users of major ICT incidents and protective measures (Article 19(3))

DORA-24 — Digital Operational Resilience Testing

A risk-based program of digital operational resilience testing (Articles 24-27)

DORA-24.1 — Resilience testing program

Establish and maintain a sound, comprehensive digital operational resilience testing program (Article 24(1))

DORA-25.1 — Vulnerability assessment and scanning

Perform vulnerability assessments and scans of ICT systems supporting critical functions (Article 25(1))

DORA-26.1 — Threat-led penetration testing

Carry out advanced threat-led penetration testing (TLPT) at least every three years (Article 26(1))

DORA-27.1 — Tester requirements

Testers meet the independence, reputation and technical-capability requirements (Article 27)

DORA-28 — ICT Third-Party Risk

Manage ICT third-party risk as an integral part of the ICT risk framework (Articles 28-30)

DORA-28.1 — Third-party risk strategy and policy

A strategy and policy on ICT third-party risk, reviewed regularly (Article 28(2))

DORA-28.2 — Register of Information

Maintain and update a register of information on all contractual arrangements with ICT third-party service providers (Article 28(3))

DORA-28.3 — Pre-contract due diligence

Assess and perform due diligence on ICT third-party providers before entering a contractual arrangement (Article 28(4))

DORA-28.4 — Third-party and app-governance monitoring

Continuously monitor ICT third-party providers, integrations and delegated application access (Article 28(1))

  • Bedrock Action Group Code Interpreter (bedrock)
  • Bedrock Action Group Computer Use / Bash (bedrock)
  • Bedrock Agent Custom Orchestration (bedrock)
  • Bedrock Agent Supervisor Mode (bedrock)
  • Bedrock Agent High Risk Unblocked (bedrock)
  • Excessive Applications Installed (box)
  • Stale Extension Request (chrome_enterprise)
  • Orb Allowlist Empty (circleci)
  • AI Gateway Logging Disabled (cloudflare)
  • AI Gateway No Authentication (cloudflare)
  • AI Gateway No Rate Limiting (cloudflare)
  • AI Gateway ZDR Disabled (cloudflare)
  • AI Gateway No Guardrails (cloudflare)
  • AI Gateway No Log Export (cloudflare)
  • AI Gateway Log Overflow Silent (cloudflare)
  • AI Gateway Aggressive Retry Without Rate Limit (cloudflare)
  • Worker AI Binding Ungoverned (cloudflare)
  • AI Gateway Account-Wide No Authentication (cloudflare)
  • Fine-Tuned Model Present (cloudflare)
  • Cloudflare AI Gateway Agent High Risk Unblocked (cloudflare)
  • Excessive Integrations (discord)
  • Webhook Inventory (discord)
  • Orphaned Webhook (discord)
  • Bot With Admin (discord)
  • Connected App with Full Dropbox Access (dropbox)
  • Agent Using Unapproved Model Provider (dust)
  • Shadow Tool Usage (dust)
  • Billing Setup Pending (google_ads)
  • Canceled Account in MCC Hierarchy (google_ads)
  • Billing Setup Without Payments Account (google_ads)
  • Access Policy Without Display Name (grafana_cloud)
  • Alert Source Unowned (incidentio)
  • Alert Route No Conditions (incidentio)
  • Escalation Path No Team Assignment (incidentio)
  • Schedule No Team Assignment (incidentio)
  • Active Workflow Never Updated (incidentio)
  • Schedule Missing Timezone (incidentio)
  • Schedule No Holiday Configuration (incidentio)
  • Configuration Profile Scoped To All Computers (jamf)
  • Policy Disabled (jamf)
  • Policy Scoped To All Computers (jamf)
  • LangSmith Agent Unmonitored (langsmith)
  • LangSmith Agent High Run Volume (langsmith)
  • LangSmith Agent No Evaluation (langsmith)
  • LangSmith Agent High Risk Unblocked (langsmith)
  • Copilot Agent Generative Orchestration (m365)
  • Copilot Agent No Authentication (m365)
  • Copilot Agent Multi-Channel Exposure (m365)
  • Copilot Agent Unconstrained Tool Use (m365)
  • Copilot Agent Unreviewed (14+ days) (m365)
  • Copilot Agent High Risk Unblocked (m365)
  • n8n Workflow Agent No Error Handling (n8n)
  • n8n Workflow Agent Webhook Trigger (n8n)
  • n8n Workflow Agent Schedule Trigger (n8n)
  • n8n Workflow Agent Multi AI Model (n8n)
  • n8n Workflow Agent High Risk Unblocked (n8n)
  • Message Edit Unrestricted (slack)
  • Slackbot Responses Unrestricted (slack)
  • Everyone Notify General (slack)
  • Archive Channel Unrestricted (slack)
  • Remove Public Channel Unrestricted (slack)
  • Workflow Creation Unrestricted (slack)
  • Remove Private Channel Unrestricted (slack)
  • User Groups Unrestricted (slack)
  • Notify Channel Unrestricted (slack)
  • Display Name Not Validated (slack)
  • Default Channels Excessive (slack)
  • Inactive Channel (slack)
  • App No Description (slack)
  • Team Without Description (teams)
  • Large Team Without Moderation (teams)
  • Channel Without Moderation (teams)
  • Unapproved Third-Party App (teams)
  • Custom App Sideloading (teams)
  • Message Edit Delete Unrestricted (teams)
  • Recipe High Error Rate (workato)
  • Stopped Recipe With Errors (workato)

DORA-28.5 — Exit strategies and transition plans

Exit strategies and transition plans for ICT services supporting critical or important functions (Article 28(8))

DORA-29.1 — Concentration risk assessment

Assess ICT concentration risk arising from contractual arrangements with providers (Article 29(1))

DORA-29.2 — Sub-outsourcing conditions

Conditions governing sub-outsourcing of ICT services supporting critical functions (Article 29(2))

DORA-30.1 — Key contractual provisions

Contractual arrangements include the required provisions on access, audit, security and termination (Article 30)

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial