How Black Cat SSPM maps to DORA (SaaS Security)
Digital Operational Resilience Act — ICT risk management and third-party risk for financial entities in SaaS environments (Articles 5-6, 8-14, 17-19, 24-30)
DORA-5 — ICT Risk Management Framework
Sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system (Articles 5-6)
DORA-5.1 — Governance and board oversight
The management body defines, approves, oversees and is accountable for the ICT risk management framework (Article 5(2))
DORA-6.1 — Documented ICT risk management framework
The ICT risk management framework is documented in a comprehensive manner, covering strategies, policies, protocols and tools (Article 6(1)-(2))
DORA-6.2 — Roles, responsibilities and control function
Clear ICT roles and responsibilities with an independent ICT risk control function (Article 6(4))
DORA-6.3 — Post-incident and periodic framework review
Review the ICT risk management framework after major ICT incidents and following supervisory instructions (Article 6(5))
DORA-6.4 — Internal audit of the ICT framework
The ICT risk management framework is subject to internal audit by auditors with sufficient ICT knowledge (Article 6(6))
DORA-6.5 — ICT risk tolerance and strategy
Digital operational resilience strategy setting ICT risk tolerance in line with the entity's risk appetite (Article 6(8))
DORA-8 — Identification
Identify, classify and document ICT-supported business functions, assets and dependencies (Article 8)
DORA-8.1 — ICT asset inventory
Identify and maintain an inventory of all ICT assets, accounts and applications supporting business functions (Article 8(1)/(4))
- Stale Browser (90+ Days Inactive) (chrome_enterprise)
- Unmanaged Browser (30+ Days Inactive) (chrome_enterprise)
- Orphaned Extension With Zero Installs (chrome_enterprise)
- Browser Flagged as Needing Attention (chrome_enterprise)
- CMDB Stale Records (servicenow)
DORA-8.2 — ICT-supported business functions
Identify and classify the business functions, roles and dependencies that ICT assets support (Article 8(1))
DORA-8.3 — Legacy and end-of-life ICT systems
Identify ICT systems that are outdated, unsupported or approaching end of life (Article 8(7))
- Sideloaded Extension Detected (chrome_enterprise)
- Outdated Browser Version (chrome_enterprise)
- Extension With Risky Permissions (chrome_enterprise)
- Extension Not Hosted on Chrome Web Store (chrome_enterprise)
- Computer OS Outdated (jamf)
- Mobile Device OS Outdated (jamf)
DORA-9 — Protection and Prevention
ICT security policies, tools and controls that protect ICT systems and data (Article 9)
DORA-9.1 — Identity and access management policy
Documented policies governing identity and access management across ICT systems (Article 9(4)(c))
- Browser Without Organizational Unit Assignment (chrome_enterprise)
- Sentinel Policy Advisory Only (terraform_cloud)
- Policy Set Overridable (terraform_cloud)
- Policy Set Not Global (terraform_cloud)
- Policy Set Empty (terraform_cloud)
DORA-9.2 — Access control and least privilege
Restrict access rights to the minimum required for each role, applying least privilege and separation of duties (Article 9(4)(c))
- User Account Locked (akamai)
- User Inactive (akamai)
- User All Groups Access (akamai)
- API Client Credentials Near Expiry (akamai)
- API Client Inactive (akamai)
- Custom Role With Admin Permissions (akamai)
- Excessive Org Admins (anthropic)
- Unscoped Admin (anthropic)
- Managed User Review (anthropic)
- Admin Redundancy Missing (anthropic)
- Dormant Member (anthropic)
- Stale API Key (anthropic)
- Unscoped API Key (anthropic)
- Inactive API Key Not Removed (anthropic)
- API Key Created By Non-User (anthropic)
- Stale Invite (anthropic)
- Expired Invite Not Cleaned (anthropic)
- Admin Invite Pending Review (anthropic)
- Excessive Workspace Admins (anthropic)
- Workspace Single Admin (anthropic)
- API Key Expired Or Expiring (anthropic)
- API Key No Expiration (anthropic)
- Claude Code User Not In Workspace (anthropic)
- Claude Code User Role Review (anthropic)
- Claude Code Commits Without Pull Requests (anthropic)
- Unscoped API Usage (anthropic)
- Claude SSO Not Enforced (anthropic)
- Claude SSO Provisioning Not Required (anthropic)
- Claude No Active IP Allowlist (anthropic)
- Claude Excessive Session Duration (anthropic)
- Compliance Key Has Delete Scope (anthropic)
- Deactivated Compliance Key Still Listed (anthropic)
- Compliance Key Stale (anthropic)
- Claude Admin Sprawl (anthropic)
- Claude Empty Group (anthropic)
- Claude Custom Role Broad Connector Access (anthropic)
- Compliance Key No Expiry (anthropic)
- Inactive User (atlassian)
- Suspended User With Access (atlassian)
- User Dual Admin Role (atlassian)
- External User With Product Access (atlassian)
- API Token Older Than 90 Days (atlassian)
- User With Multiple API Tokens (atlassian)
- SSO Not Configured (atlassian)
- Session Duration Excessive (atlassian)
- Jira Project Permissive Default Roles (atlassian)
- API Token No Label (atlassian)
- External Users Policy Disabled (atlassian)
- Org Admin Product Access (atlassian)
- User Account Closed (atlassian)
- API Token Generic Label (atlassian)
- Empty Group (atlassian)
- Admin Without MFA (atlassian)
- Product Access Admin (atlassian)
- Root Access Key Exists (aws)
- Unused Access Keys (aws)
- Old Access Keys Not Rotated (aws)
- Inactive IAM Users (aws)
- Password Never Used (aws)
- Overly Permissive IAM Policy (aws)
- Weak Password Policy (aws)
- Password Policy Expiration Too Long (aws)
- SCP Not Attached to Root (aws)
- SCP Allows All Actions (aws)
- SCP Overly Broad Deny Exception (aws)
- Owner Count Exceeded (azure)
- Custom Admin Roles (azure)
- Classic Administrators (azure)
- Guest Privileged Role (azure)
- Key Vault RBAC Not Enabled (azure)
- SQL AD Admin Not Configured (azure)
- App Service Managed Identity Disabled (azure)
- App Service Auth Disabled (azure)
- Excessive Admin Users (box)
- Inactive User Account (box)
- External Collaboration Not Restricted (box)
- Platform Access Only Admin (box)
- User Exempt from Login Verification (box)
- User Account Deactivated But Not Removed (box)
- Admin Exempt From Login Verification (box)
- GPT With Unreviewed Third-Party Actions (chatgpt_enterprise)
- Download Restrictions Not Set (chrome_enterprise)
- Incognito Mode Allowed (chrome_enterprise)
- Extension With Excessive Permissions (chrome_enterprise)
- No Groups Defined (circleci)
- Unrestricted Context (circleci)
- User Checkout Key (circleci)
- OIDC Not Configured (circleci)
- Empty Group (circleci)
- Large Group (circleci)
- OIDC Default Audience (circleci)
- External Account Member (cloudflare)
- SSO Not Configured (cloudflare)
- Super Admin Count Excessive (cloudflare)
- Super Admin Redundancy Missing (cloudflare)
- Super Admin Without MFA (cloudflare)
- Pending Account Member (cloudflare)
- Role-less Account Member (cloudflare)
- API Token Without Expiry (cloudflare)
- API Token Stale (cloudflare)
- Application Without Policies (cloudflare_access)
- Bypass Decision Policy (cloudflare_access)
- Policy Allows Everyone (cloudflare_access)
- No Purpose Justification (cloudflare_access)
- Group Includes Everyone (cloudflare_access)
- Group With Empty Include Rules (cloudflare_access)
- Single Identity Provider (cloudflare_access)
- Application Allows All IdPs (cloudflare_access)
- Application No Auto-Redirect to IdP (cloudflare_access)
- Policy Without Require Rules (cloudflare_access)
- Group Without Require Rules (cloudflare_access)
- Service Token Over One Year Old (cloudflare_access)
- Seat Expiration Not Configured (cloudflare_access)
- Dashboard Not Read-Only (cloudflare_access)
- SSO Disabled (datadog)
- SSO Not Enforced (datadog)
- Admin Redundancy (datadog)
- Excessive Admins (datadog)
- External Admin (datadog)
- Unverified User (datadog)
- Disabled User Present (datadog)
- External User Access (datadog)
- Dashboard Permissions Open (datadog)
- Dashboard Read-Only Without Role Restriction (datadog)
- External Admin Service Account (datadog)
- Service Account Admin Privileges (datadog)
- Service Account Custom Role (datadog)
- Application Key Write Scopes (datadog)
- Application Key Has No Scopes (datadog)
- External Service Account (datadog)
- Admin User Not Verified (datadog)
- Disabled Admin User (datadog)
- Application Key Excessive Scopes (datadog)
- API Key Critical Age (datadog)
- Weak SSH Key (digitalocean)
- Kubernetes SSO Not Enabled (digitalocean)
- MFA Not Required for Admins (discord)
- Low Verification Level (discord)
- Member Verification Gate Disabled (discord)
- Role Has Administrator Permission (discord)
- Role Has Dangerous Permissions (discord)
- Everyone Role Has Dangerous Permissions (discord)
- Excessive Admin Roles (discord)
- Role Can Mention Everyone (discord)
- Permanent Invite (discord)
- Unlimited Use Invite (discord)
- Channel Everyone Overwrite (discord)
- Overly Permissive Channel (discord)
- Excessive Admins (discord)
- Admin Role High Member Count (discord)
- Bot-Managed Role With Admin (discord)
- Weak Password Length (docusign)
- Weak Password Strength (docusign)
- No Password Expiration (docusign)
- No Account Lockout (docusign)
- Long Web Session Timeout (docusign)
- Long Signing Session Timeout (docusign)
- Long Mobile Session Timeout (docusign)
- Excessive Admins (docusign)
- Inactive User With Access (docusign)
- Overly Broad Permission Profile (docusign)
- User Without Group (docusign)
- No SSO Configured (docusign)
- Unclaimed Domain (docusign)
- SSO Not Mandatory (docusign)
- Empty Group (docusign)
- Permission Profile Manages Users (docusign)
- Unused Admin Permission Profile (docusign)
- Disabled Admin Account (docusign)
- Domain Not Linked to Identity Provider (docusign)
- Password Security Questions Enabled (docusign)
- Group Creation Unrestricted (dropbox)
- Excessive Admin Users (dropbox)
- Inactive Member Account (dropbox)
- Stale Pending Invite (dropbox)
- Email Not Verified (dropbox)
- Admin Email Not Verified (dropbox)
- User-Managed Group (dropbox)
- Stale Mobile Session (dropbox)
- High Pending Invitation Count (dropbox)
- Suspended Members Present (dropbox)
- Overly Permissive IAM Binding (gcp)
- SA Impersonation Role Binding (gcp)
- Excessive Project Owners (gcp)
- Owner Role Group Assignment (gcp)
- Privileged Service Account Binding (gcp)
- Old Service Account Keys (gcp)
- User Managed Service Account Keys (gcp)
- Bucket Uniform Access Disabled (gcp)
- SA Key Creation Not Disabled (gcp)
- SA Key Upload Not Disabled (gcp)
- Default SA Grant Not Disabled (gcp)
- Service Account Key Expiry Not Enforced (gcp)
- Unrestricted API Key (gcp)
- Stale API Key (gcp)
- KMS Separation of Duties Violation (gcp)
- SA Separation of Duties Violation (gcp)
- Org-Level Owner Binding (gcp)
- Org-Level Editor Binding (gcp)
- External Members at Org Level (gcp)
- Instance Uses Default Service Account (gcp)
- Cloud KMS Key Publicly Accessible (gcp)
- Secret Manager Secret Publicly Accessible (gcp)
- GKE Legacy ABAC Enabled (gcp)
- GKE Workload Identity Disabled (gcp)
- GKE Master Authorized Networks Disabled (gcp)
- Unbounded Conditional Privileged Binding (gcp)
- WIF Provider Trusts Public Issuer Without Attribute Condition (gcp)
- WIF Provider Missing Attribute Condition (gcp)
- Privileged Service Account Impersonable From Unconditioned WIF Pool (gcp)
- Privileged Role Granted to Workload Identity Pool via Wildcard (gcp)
- Org Default Permission Too Permissive (github)
- Repo Branch Protection Disabled (github)
- Stale Organization Member (github)
- Repo Admins Bypass Branch Protection (github)
- Repo Stale Reviews Not Dismissed (github)
- Team Admin Permission (github)
- OAuth App Broad Repository Access (github)
- GitHub Actions Can Approve Pull Requests (github)
- GitHub Actions Default Workflow Permissions Read-Write (github)
- Org Members Can Fork Private Repos (github)
- Org Members Can Create Public Repos (github)
- Org Repository Creation Unrestricted (github)
- Repo Branch Deletion Allowed (github)
- Repo Force Pushes Allowed (github)
- Repo Insufficient Required Reviews (github)
- Too Few Organization Owners (github)
- Too Many Organization Owners (github)
- Fine-Grained PAT Stale (github)
- Fine-Grained PAT Broad Access (github)
- Copilot Allows Public Code Suggestions (github)
- Copilot Seat Inactive (github)
- Group Membership Unlocked (gitlab)
- Project Merge Approvals Disabled (gitlab)
- Project Branch Protection Disabled (gitlab)
- Project Force Push Allowed (gitlab)
- Project No Code Owner Approval (gitlab)
- Deactivated Member Not Removed (gitlab)
- Pending Invitation Not Accepted (gitlab)
- Group Subgroup Creation Permissive (gitlab)
- Blocked Member Not Removed (gitlab)
- Email-Only User Access (google_ads)
- Excessive Admin Users (google_ads)
- Stale Pending Invitation (google_ads)
- Stale User Access (google_ads)
- Account With No Admin Users (google_ads)
- Account With Single Admin User (google_ads)
- Stale Standard User Access (google_ads)
- Stale Admin Invitation (google_ads)
- Self-Granted User Access (google_ads)
- Stale Read-Only Invitation (google_ads)
- Stale Email-Only User Access (google_ads)
- Stale Admin Access (google_ads)
- User Access Without Inviter (google_ads)
- Stale Standard Access Invitation (google_ads)
- SSO Disabled (grafana)
- Basic Auth Enabled With SSO (grafana)
- Single SSO Provider (grafana)
- Excessive Admins (grafana)
- Dormant User (grafana)
- Admin Without Recent Activity (grafana)
- Service Account Admin Role (grafana)
- Non-Expiring Service Account Token (grafana)
- Disabled Service Account With Tokens (grafana)
- Expired Service Account Token (grafana)
- Service Account Token Age Exceeds 180 Days (grafana)
- Folder Without Custom ACL (grafana)
- Excessive Cloud Admins (grafana_cloud)
- Cloud Wildcard Access Policy (grafana_cloud)
- Overly Permissive Access Policy (grafana_cloud)
- Access Policy Without IP Restriction (grafana_cloud)
- Single Cloud Admin (grafana_cloud)
- Access Policy With No Scopes (grafana_cloud)
- Access Policy With No Realm Binding (grafana_cloud)
- Access Policy Combines Write and Delete Scopes (grafana_cloud)
- Access Policy Uses Org-Wide Realm (grafana_cloud)
- Recently Added Admin Member (grafana_cloud)
- Write-Scoped Access Policy Without IP Restriction (grafana_cloud)
- Organization Member Without Email (grafana_cloud)
- Excessive Scope Count on Access Policy (grafana_cloud)
- Token Bound to Unknown or Deleted Policy (grafana_cloud)
- Token With Expiration Over 365 Days (grafana_cloud)
- Token Not Rotated in 180 Days (grafana_cloud)
- Resource Group Auto-Join With Write Access (huggingface)
- Excessive Admins (incidentio)
- Single Account Owner (incidentio)
- User Without Base Role (incidentio)
- User Has Custom Roles But No Base Role (incidentio)
- User With Excessive Custom Roles (incidentio)
- Dormant Account (lastpass)
- Admin Dormant (lastpass)
- Never Logged In Account (lastpass)
- Admin Never Logged In (lastpass)
- Disabled Account Not Removed (lastpass)
- Excessive Shared Folder Admins (lastpass)
- Shared Folder All Admin (lastpass)
- Shared Folder No Read-Only Users (lastpass)
- Shared Folder Single Admin (lastpass)
- Shared Folder Excessive Users (lastpass)
- User Not Assigned to Any Group (lastpass)
- Disabled Account With Admin Privileges (lastpass)
- Recently Created Admin Account (lastpass)
- Guest User Permissions Not Restricted (m365)
- Guest Invitation Not Restricted (m365)
- Users Can Create Security Groups (m365)
- Users Can Register Applications (m365)
- User Consent to Apps Not Restricted (m365)
- Guest Group Privileges Not Restricted (m365)
- Admin Consent Requests Disabled (m365)
- Users Can Create Tenants (m365)
- M365 Group Creation Not Restricted (m365)
- MSOL PowerShell Not Blocked (m365)
- Self-Service Sign Up Enabled (m365)
- Guest Access to Groups Not Restricted (m365)
- Global Admin Redundancy Missing (m365)
- Excessive Global Administrators (m365)
- Global Admin Not Cloud-Only (m365)
- External Users With Admin Role (m365)
- Guest Users Present (m365)
- Copilot License on Guest User (m365)
- CA Block High Risk Users Missing (m365)
- CA Block Risky Sign-ins Missing (m365)
- CA Legacy Auth Not Blocked (m365)
- CA Session Duration Not Set (m365)
- CA Compliant Devices Not Required (m365)
- CA Device Code Flow Not Blocked (m365)
- Auth Methods Migration Incomplete (m365)
- TAP Enabled for All Users (m365)
- TAP Not One-Time Use (m365)
- TAP Global Policy Enabled (m365)
- TAP Maximum Lifetime Too Long (m365)
- TAP Character Length Too Short (m365)
- Password Expiration Policy Enabled (m365)
- Password Lockout Threshold Too High (m365)
- Lockout Duration Too Short (m365)
- Custom Banned Passwords Not Enforced (m365)
- Password Protection On-Prem Disabled (m365)
- Password Protection Mode Audit Only (m365)
- SP Using Password Credentials (m365)
- SP Expired Password Credentials (m365)
- SP Expired Certificate Credentials (m365)
- SP Long-Lived Password Credentials (m365)
- SP Long-Lived Certificate Credentials (m365)
- SP Password Credentials Expiring Soon (m365)
- SP Certificate Credentials Expiring Soon (m365)
- App Using Password Credentials (m365)
- App Long-Lived Password Credentials (m365)
- App Long-Lived Certificate Credentials (m365)
- App Expired Password Credentials (m365)
- App Expired Certificate Credentials (m365)
- App Password Credentials Expiring Soon (m365)
- App Certificate Credentials Expiring Soon (m365)
- OAuth App AI With Data Scopes (m365)
- OWA Session Timeout Disabled (m365)
- Shared Mailbox Sign-In Enabled (m365)
- Users Can Install Outlook Add-ins (m365)
- Direct File Access on Public Computers (m365)
- WAC Viewing on Public Computers (m365)
- Mobile Device Allows Non-Provisionable (m365)
- ActiveSync Does Not Block Unmanaged Devices (m365)
- Guest User Sprawl (notion)
- Member Without Email (notion)
- Bot Without Description (notion)
- Excessive Workspace Members (notion)
- Excessive Guest Ratio (notion)
- Bot User Without Name (notion)
- Dormant Accounts (okta)
- Dormant Super Admins (okta)
- Weak Password Policy (okta)
- Weak Account Lockout (okta)
- Session Idle Timeout Too Long (okta)
- Session Lifetime Too Long (okta)
- App Not Using Federated Auth (okta)
- App With Individual User Assignments (okta)
- OAuth App Broad Scopes (okta)
- OAuth App Inactive With Grants (okta)
- OAuth App AI With Broad Access (okta)
- Access Policy Default Not Deny (okta)
- Super Admin API Tokens (okta)
- Super Admin Count Excessive (okta)
- Super Admin Redundancy Missing (okta)
- Admin API Token Usage (okta)
- User Account Suspended (okta)
- User Account Locked Out (okta)
- Excessive Total Admin Accounts (okta)
- Stale API Token (okta)
- Old API Token (okta)
- Suspended User Activity (1password)
- Suspended User Not Removed (1password)
- Dormant User (1password)
- Failed Sign-in Attempt (1password)
- Sign-in From Untrusted Location (1password)
- Failed Sign-in From Untrusted Location (1password)
- Service Account Token Created (1password)
- Sign-in From Unknown Country (1password)
- Failed Sign-in Without MFA (1password)
- Sign-in With No Client Recorded (1password)
- Sign-in With No IP Recorded (1password)
- Failed Sign-in From Unknown Country (1password)
- Resource Created (1password)
- Suspended User With MFA Disabled (1password)
- User With No Recorded Activity (1password)
- Stale API Key (openai)
- API Key Non-User Owner (openai)
- Admin Key Sprawl (openai)
- Stale Admin Key (openai)
- Admin Key Non-User Owner (openai)
- Excessive Organization Owners (openai)
- Owner Redundancy Missing (openai)
- Disabled User Not Removed (openai)
- Excessive Service Accounts (openai)
- Excessive Project API Keys (openai)
- Project With Only Service Accounts (openai)
- Orphaned Service Account (openai)
- Stale Service Account (openai)
- Empty Group (openai)
- Group Not SCIM-Managed (openai)
- Stale Expired Invite (openai)
- Invite Grants Owner Role (openai)
- Stale Pending Invite (openai)
- Overpermissive Custom Role (openai)
- Guardrail Without Provider Allowlist (openrouter)
- Guardrail Without Model Allowlist (openrouter)
- BYOK Credential Without Workspace Scope (openrouter)
- SCIM Group Grants Admin Role (openrouter)
- SCIM Group Mapped to Default Workspace (openrouter)
- MFA Not Enabled (ovhcloud)
- Only SMS MFA Enabled (ovhcloud)
- No IP Restrictions (ovhcloud)
- API Credential No Expiry (ovhcloud)
- API Credential Never Used (ovhcloud)
- API Credential Overly Permissive (ovhcloud)
- Identity User Disabled Not Removed (ovhcloud)
- Identity User No Group (ovhcloud)
- Identity User MFA Not Enabled (ovhcloud)
- IAM Policy Wildcard Actions (ovhcloud)
- IAM Policy Wildcard Resources (ovhcloud)
- Excessive OAuth2 Clients (ovhcloud)
- Weak SSH Key Algorithm (ovhcloud)
- SSH Key Size Too Small (ovhcloud)
- API Credential OVH Support Access (ovhcloud)
- IAM Policy Excessive Identities (ovhcloud)
- Identity User Password Never Changed (ovhcloud)
- Excessive Admins (pagerduty)
- Single Account Owner (pagerduty)
- Unassigned User (pagerduty)
- User Pending Invitation (pagerduty)
- Team Without Manager (pagerduty)
- Service Not Assigned to Team (pagerduty)
- Inactive Admin (salesforce)
- Frozen Active User (salesforce)
- User Never Logged In (salesforce)
- Excessive Modify All Data (salesforce)
- Profile View All Data (salesforce)
- Profile Manage Users (salesforce)
- Profile Author Apex (salesforce)
- API Access Review (salesforce)
- Permission Set Modify All Data (salesforce)
- Permission Set View All Data (salesforce)
- Permission Set Manage Users Wide (salesforce)
- Permission Set API Access (salesforce)
- Login From Multiple IPs (salesforce)
- Active User Without Role (salesforce)
- Weak Password Complexity (salesforce)
- Permission Set Manage Malicious Files (salesforce)
- Profile Manage Malicious Files (salesforce)
- Profile Data Export (salesforce)
- Permission Set Data Export (salesforce)
- Profile Bulk API Hard Delete (salesforce)
- Permission Set Bulk API Hard Delete (salesforce)
- SSO Disabled (sentry)
- Default Role Not Member (sentry)
- Excessive Admins (sentry)
- Dormant User (sentry)
- Old Pending Invite (sentry)
- Inactive Admin (sentry)
- Expired Invitation Not Removed (sentry)
- Events Member Admin Disabled (sentry)
- Alerts Member Write Enabled (sentry)
- Long-Term Inactive Member (sentry)
- Deactivated Member Not Removed (sentry)
- Owner Role Review (sentry)
- Pending Admin Invite (sentry)
- Inactive Member 90 Days (sentry)
- Default Role Elevated to Admin or Owner (sentry)
- Expired Admin Invite Not Cleaned Up (sentry)
- Admin Redundancy Missing (sentry)
- Very Stale Pending Invite (sentry)
- Admin Role Sprawl (servicenow)
- Empty Group With Roles (servicenow)
- Overly Permissive ACL (servicenow)
- Excessive Admins (shopify)
- Staff Unrestricted Permissions (shopify)
- Excessive API Scopes (shopify)
- Write Payment Gateways Scope (shopify)
- Write Themes Scope (shopify)
- Write Script Tags Scope (shopify)
- Write Price Rules Scope (shopify)
- Write Inventory Scope (shopify)
- Staff No Permissions (shopify)
- Write Fulfillments Scope (shopify)
- Unauthenticated Write Checkouts Scope (shopify)
- Admin Staff MFA Disabled (shopify)
- Read All Orders Scope (shopify)
- Write Draft Orders Scope (shopify)
- Write Order Edits Scope (shopify)
- Write Users Scope (shopify)
- Public Channel Creation Unrestricted (slack)
- App Management Unrestricted (slack)
- Guest Slash Commands (slack)
- Excessive Admins (slack)
- Excessive Owners (slack)
- External Admin (slack)
- Owner Redundancy (slack)
- Guest Multi Channel (slack)
- App Approval Not Required (slack)
- Password Only Auth (snowflake)
- Service Account Password Auth (snowflake)
- ACCOUNTADMIN Default Role (snowflake)
- Excessive Admin Roles (snowflake)
- No Separation Of Duties (snowflake)
- Disabled User With Active Grants (snowflake)
- Dormant User (snowflake)
- User Not Disabled (snowflake)
- ACCOUNTADMIN Excessive Grants (snowflake)
- Weak Password Policy (snowflake)
- OAuth Integration Permissive (snowflake)
- Guest Members in Team (teams)
- Excessive Team Owners (teams)
- Anonymous Meeting Join Enabled (teams)
- Lobby Bypass for Everyone (teams)
- Guest Access Overly Permissive (teams)
- Members Can Delete Channels (teams)
- Members Can Install Apps (teams)
- Guests Can Delete Channels (teams)
- Guests Can Create and Update Channels (teams)
- Single Team Owner (teams)
- Meeting Auto-Admits Everyone (teams)
- External Consumer Teams Access (teams)
- Role Has Wildcard Node Labels (teleport)
- Role Has Wildcard Database Labels (teleport)
- Role Has Wildcard Kubernetes Labels (teleport)
- Role Has Wildcard App Labels (teleport)
- Role Enables SSH Agent Forwarding (teleport)
- Role Has Unlimited Session TTL (teleport)
- Role Allows Impersonation (teleport)
- Role Has Broad Admin RBAC Rules (teleport)
- User Account Is Locked (teleport)
- Local User Has No SSO Identity (teleport)
- User Has Excessive Roles (teleport)
- User Has Admin Role (teleport)
- Auth Connector Maps Claims to Admin Role (teleport)
- Auth Connector Has Broad Claim Mapping (teleport)
- Auth Connector Has No Role Mappings (teleport)
- GitHub Connector Maps All Teams (teleport)
- Token Uses Static Join Method (teleport)
- Token Has No Expiry (teleport)
- Token Grants Auth System Role (teleport)
- Token Grants Admin Role (teleport)
- Trusted Cluster Has Broad Role Map (teleport)
- Organization 2FA Not Enforced (terraform_cloud)
- Organization SAML Not Enabled (terraform_cloud)
- Organization Session Timeout Too Long (terraform_cloud)
- Team Excessive Permissions (terraform_cloud)
- Team Workspace Admin Access (terraform_cloud)
- Team Secret Visibility (terraform_cloud)
- User 2FA Not Enabled (terraform_cloud)
- User Pending Invitation (terraform_cloud)
- SSO Not Enforced (vercel)
- Auto Join Enabled (vercel)
- Excessive Owners (vercel)
- Non-SSO Member (vercel)
- Overly Broad Access (vercel)
- Excessive Members (vercel)
- Overprivileged Integration (vercel)
- Token No Expiration (vercel)
- Token Stale (vercel)
- Token Overprivileged (vercel)
- Project No Deployment Protection (vercel)
- Member Unconfirmed (vercel)
- Access Group Empty (vercel)
- Excessive Admins (workato)
- Inactive Member (workato)
- Overprivileged Member (workato)
- No Custom Roles (workato)
- Empty Collaborator Group (workato)
- Large Collaborator Group (workato)
- No Custom Project Roles (workato)
- Inactive Admin Member (workato)
- API Platform Client Excessive Keys (workato)
- Workspace Single Admin (workato)
- Security Group With Excessive Members (workday)
- Empty Security Group (workday)
- Security Group With Broad Domain Access (workday)
- Admin With App Password (workspace)
- User With App Password (workspace)
- OAuth App With Restricted Scopes (workspace)
- Dormant Users (workspace)
- Never Logged In Users (workspace)
- OAuth App Critical Scopes (workspace)
- OAuth App With Restricted Scopes Widely Authorized (workspace)
- OAuth App AI With Data Scopes (workspace)
- Super Admin Count Excessive (workspace)
- Super Admin Redundancy Missing (workspace)
- SSO Not Configured (workspace)
- Gemini Unmanaged Actors (workspace)
- Super Admin Account Recovery Enabled (workspace)
- Gmail App Passwords Active (workspace)
- Gmail Delegate Privileged (workspace)
- Gmail Stale Delegates (workspace)
- Weak Session Control (workspace)
- Inactive User (zoom)
- Excessive Admins (zoom)
- SSO Not Enforced (zoom)
- Encryption Not Required For Third-Party Endpoints (zoom)
- Password Embedded In Join Link (zoom)
- Join Before Host Allowed (zoom)
- No Password For Instant Meetings (zoom)
- No Password For PMI Meetings (zoom)
DORA-9.3 — Privileged access management
Strictly control, review and limit privileged and administrative access rights (Article 9(4)(c))
- Role Targets Management API (auth0)
- Bedrock Agent Overprivileged Execution Role (bedrock)
- Bedrock Agent Cross-Account Role (bedrock)
- Bedrock Agent No Guardrail (bedrock)
- Bedrock Agent Excessive Action Groups (bedrock)
- Admin With Privileged Role and No Admin-Unit Restriction (duo)
- Owner-Role Administrator (duo)
- Admin API Integration With Write Permission (duo)
- Admin API Integration Can Manage Admins (duo)
- Excessive Organization Admins (huggingface)
- Member With Org Admin Role (huggingface)
- Local Admin Account On Managed Mac (jamf)
- Policy Ongoing Self Service Script (jamf)
- API Role Overbroad (jamf)
- Sudo User Without MFA (jumpcloud)
- Passwordless Sudo Enabled (jumpcloud)
- LangSmith Agent High Tool Diversity (langsmith)
- LangSmith Agent External API Tools (langsmith)
- Copilot Agent Excessive Connectors (m365)
- Copilot Agent Sensitive Connector Write Access (m365)
- Copilot Agent Maker Provided Credentials (m365)
- Copilot Agent No User Consent Required (m365)
- n8n Workflow Agent Excessive Credentials (n8n)
- n8n Workflow Agent Sensitive Credential (n8n)
- n8n Workflow Agent HTTP Request Node (n8n)
- Scheduled Job Runs As Admin (servicenow)
DORA-9.4 — Strong authentication
Strong authentication mechanisms including multi-factor authentication and credential protection (Article 9(4)(d))
- User MFA Not Enabled (akamai)
- User Without MFA (atlassian)
- Two-Step Verification Not Enforced (atlassian)
- User Without MFA (auth0)
- Connection MFA Disabled (auth0)
- Tenant MFA Not Enforced (auth0)
- Weak Connection Password Policy (auth0)
- Connection Brute Force Protection Disabled (auth0)
- Root Account MFA Not Enabled (aws)
- User MFA Not Enabled (aws)
- MFA Not Enabled (cloudflare)
- Two-Factor Enforcement Disabled (cloudflare)
- No MFA Requirement (cloudflare_access)
- One-Time PIN Only Authentication (cloudflare_access)
- No SAML or OIDC Provider (cloudflare_access)
- User Not Enrolled in MFA (duo)
- User in MFA Bypass Status (duo)
- User Has Only SMS/Phone Factors (duo)
- Orphan Phone Device (duo)
- Landline Phone Factor (duo)
- Unactivated Phone Device (duo)
- Orphan Hardware/OTP Token (duo)
- Org 2FA Not Required (github)
- Member Without 2FA (github)
- Group 2FA Not Enforced (gitlab)
- Group 2FA Grace Period Too Long (gitlab)
- Member Without 2FA (gitlab)
- Group Owner Without 2FA (gitlab)
- SSO Not Observed (huggingface)
- User Without MFA (jumpcloud)
- Password Never Expires (jumpcloud)
- System MFA Not Required At Login (jumpcloud)
- SSO Application Without SSO Configured (jumpcloud)
- MFA Not Enabled (lastpass)
- Admin Without MFA (lastpass)
- Security Defaults Disabled (m365)
- Guest Email OTP Not Enabled (m365)
- CA MFA Not Enforced (m365)
- Weak Authentication Factors Enabled (m365)
- MFA Suspicious Activity Reporting Disabled (m365)
- Admin Without MFA (okta)
- MFA Not Enrolled (okta)
- Phishing Resistant MFA Factors (okta)
- Session MFA Not Required (okta)
- Phishing Resistant Auth Policies (okta)
- MFA Disabled (1password)
- MFA Status Unknown (1password)
- Sign-in Without MFA (1password)
- SSO Disabled (pagerduty)
- Advanced Permissions Disabled (pagerduty)
- User Without MFA (pingone)
- Weak Password Policy (pingone)
- Password Policy Without History (pingone)
- Password Policy Without Expiry (pingone)
- Password Policy Low Complexity (pingone)
- Sign-On Policy Without MFA (pingone)
- Default Sign-On Policy Without MFA (pingone)
- Environment MFA Disabled (pingone)
- Admin Without MFA (salesforce)
- User Without MFA (salesforce)
- Weak Password Policy (salesforce)
- Password Never Expires (salesforce)
- No Password History (salesforce)
- Weak Max Login Attempts (salesforce)
- Short Lockout Interval (salesforce)
- High Failed Logins (salesforce)
- Member Without 2FA (sentry)
- Admin Without 2FA (sentry)
- MFA Not Enforced For Admins (servicenow)
- Weak Password Policy (servicenow)
- Staff MFA Disabled (shopify)
- Account Owner MFA Disabled (shopify)
- MFA Not Required (slack)
- User No MFA (slack)
- MFA Not Enabled (snowflake)
- Authentication Policy No MFA (snowflake)
- Cluster MFA Disabled (teleport)
- Session MFA Not Enforced (teleport)
- TOTP Without WebAuthn (teleport)
- Local Auth Enabled With SSO (teleport)
- Passwordless Without Hardware Key Policy (teleport)
- Admin Action MFA Not Enforced (teleport)
- Expired Certificate Disconnect Disabled (teleport)
- Device Trust Disabled (teleport)
- Role Does Not Require Session MFA (teleport)
- Local User Has No MFA Device (teleport)
- User Uses Only TOTP for MFA (teleport)
- Workday User Without MFA Required (workday)
- Weak Password Policy (workday)
- SSO Not Enabled (workday)
- MFA Not Enforced (workday)
- Excessive Session Timeout (workday)
- No Account Lockout Policy (workday)
- Delegated Auth Certificate Expiring Soon (workday)
- Delegated Auth Allows Local Fallback (workday)
- Account Lockout Duration Too Short (workday)
- Admin Without 2-Step Verification (workspace)
- Admin 2-Step Verification Not Enforced (workspace)
- Delegated Admin Without 2-Step Verification (workspace)
- User Without 2-Step Verification (workspace)
- User 2-Step Verification Not Enforced (workspace)
- User Without MFA (zoom)
- Admin Without MFA (zoom)
DORA-9.5 — Session management
Control session lifetime, timeout and re-authentication for ICT system access (Article 9(4)(d))
- Long Tenant Session Lifetime (auth0)
- Long Session Duration (cloudflare_access)
- Long Global Session Duration (cloudflare_access)
- Long WARP Authentication Session (cloudflare_access)
- HTTPS Not Required (salesforce)
- CSRF Protection Disabled (salesforce)
- Session Timeout Too Long (salesforce)
- No Clickjack Protection (salesforce)
- Sessions Not Locked to Domain (salesforce)
- No Forced Logout on Session Timeout (salesforce)
- Session Cookies Not HttpOnly (salesforce)
- Session Timeout Too Long (servicenow)
DORA-9.6 — Identity lifecycle and provisioning
Govern joiner/mover/leaver provisioning and timely deprovisioning of access (Article 9(4)(c))
- Dormant User (auth0)
- Terminated Employee With Active Login (bamboohr)
- Stale BambooHR Login (bamboohr)
- Orphaned BambooHR Login (bamboohr)
- Active Employee Without Manager (bamboohr)
- Active Employee Without Department (bamboohr)
- Active Employee Without Work Email (bamboohr)
- Bedrock Agent Failed Status (bedrock)
- Bedrock Agent Not Prepared (7+ days) (bedrock)
- Bedrock Agent Stale (bedrock)
- Bedrock Agent Orphaned Owner (bedrock)
- Disabled Member Present (chatgpt_enterprise)
- Non-SCIM-Managed User (chatgpt_enterprise)
- Cloudflare AI Gateway Agent Orphaned Owner (cloudflare)
- Dormant User (duo)
- Disabled User Still Has Factors (duo)
- Locked Out User (duo)
- Dormant Administrator (duo)
- Member External Domain (dust)
- Instance Uses Full Cloud-Platform API Scope (gcp)
- Instance Does Not Block Project-Wide SSH Keys (gcp)
- OS Login Disabled on Instance (gcp)
- Cloud Function Default Service Account (gcp)
- Terminated Employee Still Active (hibob)
- Active Employee Without Manager (hibob)
- Active Employee Without Department (hibob)
- Active Employee Without Email (hibob)
- Computer Stale Check-in (jamf)
- Computer Activation Lock Enabled (jamf)
- API Integration Disabled (jamf)
- Locally Managed Account Outside SSO (jumpcloud)
- LangSmith Agent Stale (langsmith)
- LangSmith Agent High Error Rate (langsmith)
- LangSmith Agent Orphaned Owner (langsmith)
- Copilot Agent No Owner (m365)
- Copilot Agent Never Published (30+ days) (m365)
- Copilot Agent Quarantined (m365)
- Copilot Agent Stale (90+ days inactive) (m365)
- Copilot Agent Orphaned Owner (m365)
- n8n Workflow Agent Stale (n8n)
- n8n Workflow Agent Active Never Executed (n8n)
- n8n Workflow Agent Inactive Webhook (n8n)
- n8n Workflow Agent Orphaned Owner (n8n)
- Excessive Org Admins (openrouter)
- Workspace Member Has Admin Role (openrouter)
- SCIM Group Without Workspace Mapping (openrouter)
- Terminated Employee Still Active (personio)
- Active Employee Without Manager (personio)
- Active Employee Without Department (personio)
- Active Employee Without Email (personio)
- Disabled User Still Present (pingone)
- Dormant User (pingone)
- Empty Group (pingone)
- Inactive User With Roles (servicenow)
- User Locked Out (servicenow)
- Default Admin Account Active (servicenow)
- Workday Dormant User Account (workday)
- Terminated User With Active Account (workday)
- User Without Manager Assigned (workday)
DORA-9.7 — Encryption of data at rest and in transit
Protect data at rest, in use and in transit with appropriate cryptographic controls (Article 9(4)(b))
- HSTS Not Enabled (akamai)
- HSTS Max-Age Too Short (akamai)
- HTTP/2 Not Enabled (akamai)
- Origin Not Using TLS (akamai)
- Edge Hostname Using Shared Cert (akamai)
- Device Without Disk Encryption (chrome_enterprise)
- SSL Encryption Disabled (cloudflare)
- SSL Mode Flexible (cloudflare)
- Always Use HTTPS Disabled (cloudflare)
- Automatic HTTPS Rewrites Disabled (cloudflare)
- HSTS Disabled (cloudflare)
- Minimum TLS Version Weak (cloudflare)
- Opportunistic Encryption Disabled (cloudflare)
- TLS 1.3 Disabled (cloudflare)
- TLS Mode Not Strict (cloudflare)
- SSL Not Enforced (digitalocean)
- No SSL Termination (digitalocean)
- Insecure Backend (digitalocean)
- HTTP Allowed (digitalocean)
- SSL Policy Weak TLS Version (gcp)
- Computer FileVault Disabled (jamf)
- Computer FileVault Recovery Key Invalid (jamf)
- Local Account FileVault Disabled (jamf)
- System Full Disk Encryption Disabled (jumpcloud)
- S/MIME Encryption Not Enforced (m365)
- S/MIME Signing Not Enforced (m365)
- S/MIME Clear Signing Not Enabled (m365)
- S/MIME Cert Chain Without Root Not Included (m365)
- S/MIME Cert Chain With Root Not Included (m365)
- S/MIME Triple-Wrap Not Enabled (m365)
- S/MIME CRL Timeout Too Long (m365)
- S/MIME Encryption Algorithms Not Configured (m365)
- S/MIME Buffer Encryption Not Enabled (m365)
- Data Rekeying Disabled (snowflake)
- Database Configured Without TLS (teleport)
- Application Has TLS Verification Disabled (teleport)
- S/MIME Not Configured (workspace)
DORA-9.8 — Cryptographic key and secret management
Manage cryptographic keys, secrets, tokens and credentials throughout their lifecycle (Article 9(4)(b))
- Storage Key Not Rotated (azure)
- Key Vault Key No Expiry (azure)
- Key Vault Secret No Expiry (azure)
- Password Manager Disabled (chrome_enterprise)
- Service Token Without Expiry (cloudflare_access)
- Stale Service Token (cloudflare_access)
- Expired Service Token Not Deleted (cloudflare_access)
- Unused API Key (datadog)
- API Key Exceeds Maximum Age (datadog)
- Stale API Token In Use (figma)
- Cloud Function Plaintext Secrets in Environment (gcp)
- Excessive Tokens Per Policy (grafana_cloud)
- Non-Expiring Cloud Token (grafana_cloud)
- Dormant Cloud Token (grafana_cloud)
- Token With Wildcard Policy (grafana_cloud)
- Recently Created Token Without Use (grafana_cloud)
- Orphaned Access Policy (grafana_cloud)
- Token Never Used After 30 Days (grafana_cloud)
- Write-Capable Token Inactive for 30 Days (grafana_cloud)
- Token Approval Policy Disabled (huggingface)
- Variable Not Marked Sensitive (terraform_cloud)
- Variable Set Global Scope (terraform_cloud)
- Variable Plaintext Credentials (terraform_cloud)
- API Platform Client No Key Rotation (workato)
DORA-9.9 — Network security and segmentation
Design and control network connections and segmentation to limit ICT risk propagation (Article 9(4)(e))
- DNSSEC Not Enabled (akamai)
- TSIG Not Enabled (akamai)
- SOA Serial Stale (akamai)
- IP Allowlist Policy Disabled (atlassian)
- DNS Wildcard Record (cloudflare)
- DNS Record Points to Private IP (cloudflare)
- DNS Record Not Proxied (cloudflare)
- Login from Residential Proxy (generic)
- Login from Datacenter Proxy (generic)
- High Confidence Proxy Login (generic)
- Failed Login from Proxy (generic)
- Admin Login from Proxy (generic)
- No VPC (digitalocean)
- No Firewall (digitalocean)
- Allows All Inbound (digitalocean)
- SSH Open To All (digitalocean)
- Allows All Outbound (digitalocean)
- Publicly Accessible (digitalocean)
- Default VPC Used (digitalocean)
- IP Forwarding Enabled on Instance (gcp)
- Legacy VPC Network In Use (gcp)
- Cloud SQL Authorized Networks Open to World (gcp)
- Cloud Function Public Ingress (gcp)
- Cloud Run Service Public Ingress (gcp)
- IP Allowlist Disabled (incidentio)
- IP Allowlist Enabled With No Rules (incidentio)
- Instance Has Public IP (ovhcloud)
- API Credential No IP Restriction (ovhcloud)
- Webhook Private Destination (shopify)
- No Network Policy (snowflake)
- Network Policy Wildcard (snowflake)
- Network Policy No Blocklist (snowflake)
- Integration No Network Policy (snowflake)
- No Network Restrictions Configured (teleport)
- Overly Broad Network Allow Rule (teleport)
- No IP Restrictions Configured (workday)
DORA-9.10 — Secure configuration and hardening
Maintain secure baseline configuration of ICT systems and manage configuration change (Article 9(2)/(4)(a))
- Group With No Contracts (akamai)
- WAF In Alert-Only Mode (akamai)
- Rate Controls Disabled (akamai)
- Slow POST Protection Disabled (akamai)
- IP Firewall Not Configured (akamai)
- Geo Firewall Not Configured (akamai)
- WAF Policy Alert-Only Mode (akamai)
- Rate Control Threshold Too Permissive (akamai)
- Bot Management Disabled (akamai)
- Edge Hostname IPv4 Only (akamai)
- SureRoute Not Enabled (akamai)
- Property No Origin Failover (akamai)
- Property Caching Disabled (akamai)
- CP Code Unused (akamai)
- Account Protection Disabled (akamai)
- Archived Workspace Not Deleted (anthropic)
- Stale Workspace (anthropic)
- Usage Spike Detected (anthropic)
- Workspace Default Rate Limits (anthropic)
- Web Search Tool Usage (anthropic)
- Claude Code High Session Count (anthropic)
- Rate Limit High Requests Per Minute (anthropic)
- Mobile App Policy Disabled (atlassian)
- Dynamic Client Registration Enabled (auth0)
- S3 Bucket Encryption Disabled (aws)
- S3 Bucket Versioning Disabled (aws)
- S3 Bucket Logging Disabled (aws)
- Unrestricted SSH Access (aws)
- Unrestricted RDP Access (aws)
- Unrestricted Egress (aws)
- Default Security Group Has Rules (aws)
- KMS Key Rotation Disabled (aws)
- KMS Key Pending Deletion (aws)
- KMS Key Disabled (aws)
- Default VPC In Use (aws)
- GuardDuty Not Enabled (aws)
- EC2 IMDSv2 Not Enforced (aws)
- EC2 Instance Has Public IP (aws)
- RDS Publicly Accessible (aws)
- RDS Storage Not Encrypted (aws)
- RDS Backup Retention Too Short (aws)
- Organization All Features Not Enabled (aws)
- Resource Control Policies Not Used (aws)
- Organization Account Security Alternate Contact Missing (aws)
- Organization Account Suspended (aws)
- Security Hub Not Enabled (aws)
- Security Hub No Standards Enabled (aws)
- Security Hub Critical Findings Unresolved (aws)
- Security Hub High Findings Unresolved (aws)
- Security Hub Auto-Enable Controls Disabled (aws)
- Security Hub CIS Standard Not Enabled (aws)
- NSG Unrestricted SSH (azure)
- NSG Unrestricted RDP (azure)
- NSG All Ports Open (azure)
- NSG UDP Open (azure)
- NSG Permissive Outbound (azure)
- Network Watcher Disabled (azure)
- Storage HTTPS Not Required (azure)
- Storage Network Default Allow (azure)
- Storage Minimum TLS (azure)
- Storage Infrastructure Encryption Disabled (azure)
- Storage Shared Key Enabled (azure)
- Storage Blob Soft Delete Disabled (azure)
- Storage Container Soft Delete Disabled (azure)
- Key Vault Soft Delete Disabled (azure)
- Key Vault Purge Protection Disabled (azure)
- Key Vault Network ACLs Allow (azure)
- Key Vault No Private Endpoint (azure)
- Defender Servers Disabled (azure)
- Defender App Service Disabled (azure)
- Defender SQL Disabled (azure)
- Defender Storage Disabled (azure)
- Defender Containers Disabled (azure)
- Defender Key Vault Disabled (azure)
- Defender Resource Manager Disabled (azure)
- Security Contact Email Missing (azure)
- Security Contact Phone Missing (azure)
- Security Alert Notifications Disabled (azure)
- SQL TDE Disabled (azure)
- SQL Firewall Allow Azure Services (azure)
- SQL Firewall Unrestricted (azure)
- SQL Minimum TLS (azure)
- SQL Vulnerability Assessment Disabled (azure)
- SQL Threat Detection Disabled (azure)
- App Service HTTPS Disabled (azure)
- App Service Minimum TLS (azure)
- App Service FTP Enabled (azure)
- App Service Remote Debugging Enabled (azure)
- App Service HTTP/2 Disabled (azure)
- Bedrock Guardrail Weak Content Filters (bedrock)
- Bedrock No Guardrails Configured (bedrock)
- Bedrock Flow References Draft Prompt (bedrock)
- Bedrock Orphaned Knowledge Base (bedrock)
- Empty Group (box)
- Empty Group (chatgpt_enterprise)
- Workspace Allows Unapproved Connectors (chatgpt_enterprise)
- Non-Stable Browser Channel In Use (chrome_enterprise)
- Browser Running Windows 10 (chrome_enterprise)
- Widespread Outdated Browser Version (chrome_enterprise)
- Telemetry Device Missing OS Version (chrome_enterprise)
- Browser Not Reporting Version (chrome_enterprise)
- Config Policies Disabled (circleci)
- Config Policies Soft Fail (circleci)
- Forked PR Builds Enabled (circleci)
- Webhook Insecure URL (circleci)
- Webhook Unverified TLS (circleci)
- Stale Runner (circleci)
- Schedule Non-Default Branch (circleci)
- Pipeline Deprecated Image (circleci)
- Webhook No Signing Secret (circleci)
- Pipeline Machine Executor (circleci)
- Pipeline Setup Remote Docker (circleci)
- Excessive Orb Allowlist (circleci)
- Runner Without Name (circleci)
- Schedule Without Description (circleci)
- Browser Integrity Check Disabled (cloudflare)
- WAF Disabled (cloudflare)
- Security Level Essentially Off (cloudflare)
- Security Level Low (cloudflare)
- Zone Settings Unavailable (cloudflare)
- CORS Allows All Origins (cloudflare_access)
- Application Hidden from App Launcher (cloudflare_access)
- Service Token Without Name (cloudflare_access)
- Email Not Verified (digitalocean)
- Backups Disabled (digitalocean)
- IPv6 Disabled (digitalocean)
- No Droplets Attached (digitalocean)
- Outdated Version (digitalocean)
- No Backups (digitalocean)
- Outdated Kubernetes Version (digitalocean)
- Auto Upgrade Disabled (digitalocean)
- Surge Upgrade Disabled (digitalocean)
- No Garbage Collection (digitalocean)
- Basic Tier (digitalocean)
- Kubernetes HA Disabled (digitalocean)
- Kubernetes No Registry Integration (digitalocean)
- Database No Maintenance Window (digitalocean)
- Database Single Node (digitalocean)
- Droplet Powered Off (digitalocean)
- AutoMod Rule Disabled (discord)
- AutoMod Excessive Exemptions (discord)
- Channel Excessive Permission Overwrites (discord)
- Sign On Paper Enabled (docusign)
- Signer Reassignment Enabled (docusign)
- PowerForms Enabled (docusign)
- No Signer Certificate Required (docusign)
- Recipient Domain Validation Disabled (docusign)
- No IP Restrictions (docusign)
- Bulk Recipients Enabled (docusign)
- Empty Group (dropbox)
- Archived Team Folder (dropbox)
- Admin API Integration Without IP Restriction (duo)
- Integration Without Enforced Enrollment Policy (duo)
- Inactive User Expiration Not Configured (duo)
- No Lockout For Unenrolled Users (duo)
- Weak Password Complexity (duo)
- Short Minimum Password Length (duo)
- Fraud Notification Email Disabled (duo)
- No Authentication Lockout Threshold (duo)
- Webhook Endpoint Not HTTPS (figma)
- Webhook Without Passcode (figma)
- Webhook Targets Raw IP Endpoint (figma)
- Public Firewall Rule (gcp)
- Firewall Rule Exposes Dangerous Port (gcp)
- Firewall Rule Egress Open to World (gcp)
- Bucket Versioning Disabled (gcp)
- Security Contact Missing (gcp)
- Essential Contacts Coverage Incomplete (gcp)
- Instance Serial Port Enabled (gcp)
- Shielded VM Disabled (gcp)
- Default VPC In Use (gcp)
- Cloud SQL Instance Has Public IP (gcp)
- Cloud SQL SSL Not Required (gcp)
- MySQL skip_show_database Not Enabled (gcp)
- MySQL local_infile Enabled (gcp)
- Cloud SQL Backup Not Enabled (gcp)
- Cloud KMS Key Rotation Period Exceeds 90 Days (gcp)
- Cloud KMS Encryption Key Has No Rotation Schedule (gcp)
- Cloud KMS Key Primary Version Not Active (gcp)
- Cloud KMS Key Uses Software Protection Level (gcp)
- Secret Manager Secret Has No Rotation (gcp)
- Secret Manager Secret Has No Versioning (gcp)
- GKE Network Policy Disabled (gcp)
- GKE Private Cluster Disabled (gcp)
- GKE Shielded Nodes Disabled (gcp)
- GKE Release Channel Not Set (gcp)
- GKE Binary Authorization Disabled (gcp)
- GKE Database Encryption Disabled (gcp)
- GKE Intranode Visibility Disabled (gcp)
- GKE Logging Disabled (gcp)
- GKE Node Pool Auto-Upgrade Disabled (gcp)
- Cloud Logging Sink Missing (gcp)
- Log Metric for Project Ownership Missing (gcp)
- Log Metric for Audit Config Changes Missing (gcp)
- Log Metric for Custom Role Changes Missing (gcp)
- Alert Policy Disabled (gcp)
- Alert Policy Has No Notification Channels (gcp)
- Log Metric Project Ownership Alert Missing (gcp)
- Log Metric Audit Config Alert Missing (gcp)
- Log Metric Custom Role Alert Missing (gcp)
- DNS DNSSEC Disabled (gcp)
- DNS DNSSEC RSASHA1 Key-Signing Key (gcp)
- DNS DNSSEC RSASHA1 Zone-Signing Key (gcp)
- DNS Logging Disabled (gcp)
- No IAM Deny Policy Configured (gcp)
- IAM Deny Policy Does Not Cover Service Account Key Creation (gcp)
- IAM Deny Policy Has Overly Broad Exception Principals (gcp)
- Repo Secret Scanning Disabled (github)
- Repo Dependabot Disabled (github)
- Public Repo Without Security Policy (github)
- Actions Allow All External (github)
- Webhook Insecure URL (github)
- Org Dependabot Alerts Disabled (github)
- Org Secret Scanning Disabled (github)
- Actions Runner Allows Public Repos (github)
- GitHub Actions Enabled For All Repositories (github)
- Org Web Commit Signoff Not Required (github)
- Repo Secret Scanning Push Protection Disabled (github)
- Actions SHA Pinning Not Required (github)
- Actions Selected-Actions Allowlist Pattern Unpinned (github)
- Group No IP Restriction (gitlab)
- Project Container Scanning Disabled (gitlab)
- Project Discussions Not Required (gitlab)
- Shared Runner Not Locked (gitlab)
- Active Runner Offline (gitlab)
- Integration Insecure URL (gitlab)
- No Compliance Framework (gitlab)
- Project Pipeline Not Required (gitlab)
- Runner Not Locked to Project (gitlab)
- Project Shared Runners Enabled (gitlab)
- Recent Sensitive Change (google_ads)
- Recent Admin Role Change (google_ads)
- Direct Access Data Source (grafana)
- Data Source Basic Auth (grafana)
- Data Source TLS Skip Verify (grafana)
- Data Source With Credentials (grafana)
- No Alert Rules Configured (grafana)
- External Contact Point (grafana)
- Broad Mute Timing (grafana)
- Unsigned Plugin (grafana)
- Community Plugin (grafana)
- Outdated Plugin (grafana)
- Paused Alert Rules (grafana)
- Alert Rules Without Contact Points (grafana)
- Token Expiring Within 14 Days (grafana_cloud)
- Stale Access Policy Not Updated in 180 Days (grafana_cloud)
- Workflow Has No Steps (incidentio)
- User No Slack Linked (incidentio)
- Computer SIP Disabled (jamf)
- Computer Gatekeeper Disabled (jamf)
- Computer Firewall Disabled (jamf)
- Computer Remote Desktop Enabled (jamf)
- Computer Recovery Lock Missing (jamf)
- Computer Secure Boot Reduced (jamf)
- Configuration Profile User Removable (jamf)
- API Integration Long Token Lifetime (jamf)
- SSO Not Enabled (jamf)
- SSO Bypass Allowed (jamf)
- SSO Not Enforced For Enrollment (jamf)
- SSO Not Enforced For macOS Self Service (jamf)
- System SSH Password Authentication Enabled (jumpcloud)
- System SSH Root Login Enabled (jumpcloud)
- Dynamic User Group Without Restriction (jumpcloud)
- Weak Master Password (lastpass)
- Very Weak Master Password (lastpass)
- Empty Vault User (lastpass)
- Stale Master Password (lastpass)
- Master Password Never Changed (lastpass)
- Admin Stale Master Password (lastpass)
- Low Shared Folder Security Score (lastpass)
- Critically Low Shared Folder Score (lastpass)
- Admin With Weak Master Password (lastpass)
- Empty Shared Folder (lastpass)
- Admin Master Password Never Changed (lastpass)
- Self-Service Subscriptions Enabled (m365)
- Risk-Based Consent Not Configured (m365)
- Group Naming Convention Not Configured (m365)
- Customer Lockbox Not Enabled (m365)
- Copilot License Assigned (m365)
- Unverified Domain (m365)
- Unverified Federated Domain (m365)
- SPF Record Missing (m365)
- DMARC Record Missing (m365)
- DKIM Record Missing (m365)
- Multi-Tenant App Without Verified Publisher (m365)
- SMTP Auth Not Disabled Globally (m365)
- External Recipient Mail Tips Disabled (m365)
- Mail Tips Not Fully Enabled (m365)
- Mailbox SMTP Auth Not Disabled (m365)
- OWA Clickjacking Protection Not Set (m365)
- ActiveSync Integration Enabled for OWA (m365)
- On-Send Add-ins Enabled in OWA (m365)
- No File Types Blocked in OWA (m365)
- No MIME Types Blocked in OWA (m365)
- Unknown File Types Not Blocked (m365)
- Transport Rule Includes BCC (m365)
- Transport Rule Processes External Sender (m365)
- Transport Rule Deletes Messages (m365)
- Transport Rule Disabled (m365)
- Remote Domain Trusted Inbound Enabled (m365)
- Remote Domain Trusted Outbound Enabled (m365)
- Remote Domain Auto-Reply Enabled (m365)
- Remote Domain Delivery Reports Enabled (m365)
- Remote Domain NDR Enabled (m365)
- Remote Domain TNEF Enabled (m365)
- Distribution List Hidden From GAL (m365)
- Mailbox Move Enabled for Org Relationships (m365)
- Common Attachment Types Filter Disabled (m365)
- Common Attachment Types Missing (m365)
- Zero-Hour Auto Purge Disabled (m365)
- Admin Malware Notifications Disabled (m365)
- Blocked File Type Action Not Quarantine (m365)
- Anti-Phishing Spoof Detection Weak (m365)
- Anti-Phishing First Contact Tip Disabled (m365)
- Outbound Spam Thresholds Not Configured (m365)
- Inbound Spam Bulk Threshold Too High (m365)
- SPF Hard Fail Not Enabled (m365)
- High Confidence Spam Not Quarantined (m365)
- Connection Filter Not Configured (m365)
- Outbound Spam Notification Disabled (m365)
- Suspicious Outbound Copy Not Enabled (m365)
- Comprehensive Spam Marking Disabled (m365)
- Sensitivity Labels Not Configured (m365)
- Copilot Inventory Degraded (m365)
- Agent Uses Code Interpreter (mistral)
- Agent References Org-Shared Library (mistral)
- Agent Deployed Without Guardrails (mistral)
- Stale Page (notion)
- Orphaned Page Without Parent (notion)
- Stale Database (notion)
- Password Policy No Symbol Requirement (okta)
- Password Policy No Username Exclusion (okta)
- Account Lockout Auto-Unlock Too Fast (okta)
- Inactive Application (okta)
- ThreatInsight Not Blocking (okta)
- ThreatInsight Excluded Zones (okta)
- Anonymizer Block Absent (okta)
- SSO Policy Modified (1password)
- SSO Disabled (1password)
- Signing Key Changed (1password)
- Firewall Rule Changed (1password)
- Project Without Rate Limits (openai)
- Active Project Without Users (openai)
- Usage Anomaly (openai)
- Excessive API Request Volume (openai)
- Disproportionate Output Tokens (openai)
- Usage Category Anomaly (openai)
- Certificate Expiring Soon (openai)
- Inactive Certificate (openai)
- Certificate Without Project Scope (openai)
- API Key Without Spend Limit (openrouter)
- API Key Without Expiry (openrouter)
- Disabled API Key Not Deleted (openrouter)
- Stale API Key (openrouter)
- BYOK Spend Uncapped (openrouter)
- API Key Spend Limit Without Reset Interval (openrouter)
- API Key Relies Solely On Workspace Default Guardrail (openrouter)
- Workspace Without Guardrails (openrouter)
- Workspace Without Spending Budget (openrouter)
- Guardrail Without Content Filters (openrouter)
- Guardrail Without Key Or Member Assignments (openrouter)
- API Key Sprawl (openrouter)
- BYOK Credential Disabled Not Deleted (openrouter)
- BYOK Spend Ungoverned (openrouter)
- Excessive BYOK Provider Diversity (openrouter)
- Workspace Has Excessive Members (openrouter)
- SCIM Mapping Stale (openrouter)
- Preset Targets Model Outside Workspace Allowlist (openrouter)
- Disabled Preset Not Deleted (openrouter)
- Stale Preset (openrouter)
- Stale File (openrouter)
- Oversized File (openrouter)
- Excessive Model Diversity (openrouter)
- Developer Mode Enabled (ovhcloud)
- IAM Policy No Identities (ovhcloud)
- OAuth2 Client No Description (ovhcloud)
- Cloud Project Suspended (ovhcloud)
- Instance Using Default Image (ovhcloud)
- Instance In Shelved State (ovhcloud)
- Instance Rescue Mode (ovhcloud)
- User Without Notification Rules (pagerduty)
- User Without Contact Methods (pagerduty)
- Empty Team (pagerduty)
- Service Without Integrations (pagerduty)
- Service Without Acknowledgement Timeout (pagerduty)
- Escalation Policy Without Services (pagerduty)
- Schedule Not Linked to Escalation Policy (pagerduty)
- Unused Permission Set (salesforce)
- Webhook XML Format (shopify)
- Store Setup Required (shopify)
- Low Data Retention (snowflake)
- SSO Login Page Disabled (snowflake)
- No SSO Configured (snowflake)
- No SCIM Configured (snowflake)
- Warehouse No Auto Suspend (snowflake)
- Warehouse No Auto Resume (snowflake)
- Warehouse No Resource Monitor (snowflake)
- Warehouse Oversized (snowflake)
- No Account Resource Monitor (snowflake)
- Resource Monitor Notify Only (snowflake)
- Archived Team (teams)
- Skype for Business Interop Enabled (teams)
- Trusted Cluster Is Disabled (teleport)
- No Client Idle Timeout Configured (teleport)
- Node Running Outdated Teleport Version (teleport)
- Organization Force Delete Allowed (terraform_cloud)
- Organization Default Execution Mode Local (terraform_cloud)
- Workspace Auto Apply Enabled (terraform_cloud)
- Workspace Destroy Plan Allowed (terraform_cloud)
- Workspace No VCS Connection (terraform_cloud)
- Workspace Drift Detection Disabled (terraform_cloud)
- Workspace Outdated Terraform Version (terraform_cloud)
- Variable Set Priority Override (terraform_cloud)
- Agent Pool Organization Scoped (terraform_cloud)
- VCS Connection Organization Scoped (terraform_cloud)
- Run Task Advisory Enforcement (terraform_cloud)
- Notification No HMAC Token (terraform_cloud)
- SSH Key Present (terraform_cloud)
- Deployment Protection Disabled (vercel)
- Strict Deployment Protection Disabled (vercel)
- Fork Protection Disabled (vercel)
- No Target Restriction (vercel)
- SSL Not Verified (vercel)
- Domain Expiring Soon (vercel)
- Stale Integration (vercel)
- Insecure Log Drain (vercel)
- Auto Expose System Environment Variables (vercel)
- Workspace Recipe Limit (workato)
- Broken Connection (workato)
- Stale Connection (workato)
- Workspace Trial Expired (workato)
- Recipe Never Executed (workato)
- Recipe Long Stopped (workato)
- Connection Never Authorized (workato)
- Recipe Excessive Application Integrations (workato)
- Domain Not Verified (workspace)
- DKIM Not Configured (workspace)
- Group Spam Moderation Disabled (workspace)
- Gemini Not Licensed (workspace)
- Gemini Enabled Without DLP (workspace)
- Gemini Active Without DLP (workspace)
- Automatic Email Forwarding Enabled (workspace)
- IMAP Access Enabled (workspace)
- POP Access Enabled (workspace)
- Drive Shared Drive Creation Unrestricted (workspace)
- Shared Drive No Admin Restrictions (workspace)
- Shared Drive Folder Sharing Unrestricted (workspace)
- Chat Webhooks Enabled (workspace)
- Gmail Confidential Mode Disabled (workspace)
- Gmail Send-As External Alias (workspace)
- Gmail Unverified Send-As Alias (workspace)
- Meet Recording Unrestricted (workspace)
- Weak Password Policy (workspace)
- Spoofing Protection Disabled (workspace)
- Gmail Encrypted Attachment Protection Disabled (workspace)
- Gmail Shortener Scanning Disabled (workspace)
- No Meeting Password Required (zoom)
- Waiting Room Disabled (zoom)
- Unauthenticated Join Allowed (zoom)
- Local Recording Enabled (zoom)
- Cloud Recording No Auto-Delete (zoom)
- Weak Password Policy (zoom)
- Chat File Transfer Enabled (zoom)
- Automatic Recording Enabled (zoom)
- Auto Save Meeting Chats (zoom)
- Continuous Meeting Chat Enabled (zoom)
- Email Notification On Join Before Host Disabled (zoom)
- Far End Camera Control Enabled (zoom)
- Host Video On By Default (zoom)
- Guest Participant Identification Disabled (zoom)
- Participant Video On By Default (zoom)
- Join/Leave Sound Disabled (zoom)
- Remote Control Enabled (zoom)
- Request To Unmute Not Required (zoom)
- Screen Sharing Allowed For All Participants (zoom)
- Screen Share Watermark Disabled (zoom)
DORA-9.11 — Data protection and leakage prevention
Prevent unauthorized disclosure, corruption or loss of data held in ICT systems (Article 9(3))
- Claude Retention Set To Indefinite (anthropic)
- Claude Content Redaction Disabled (anthropic)
- Claude Code Execution Egress Open (anthropic)
- Secret Detected In Claude Conversation (anthropic)
- Storage Public Blob Access (azure)
- No Collaboration Whitelist Entries (box)
- Broad Inbound Collaboration Whitelist (box)
- Bidirectional Collaboration Whitelist (box)
- Secret Detected In ChatGPT Conversation (chatgpt_enterprise)
- Excessive Env Vars (circleci)
- Pipeline Hardcoded Secrets (circleci)
- Dashboard Public Sharing (datadog)
- Dashboard Public URL (datadog)
- Plain Text Env Var (digitalocean)
- Content Filter Not Full (discord)
- Guild Publicly Discoverable (discord)
- Widget Enabled (discord)
- No AutoMod Rules (discord)
- No Keyword Filtering (discord)
- No Spam Protection (discord)
- No Mention Spam Protection (discord)
- NSFW Channel (discord)
- Public Shared Links Allowed by Default (dropbox)
- Shared Folders Open to Anyone (dropbox)
- External Folder Join Unrestricted (dropbox)
- Folder Link Restriction Not Enforced (dropbox)
- Open Space With Connected Data (dust)
- Agent Shared Broadly (dust)
- Sensitive Data Source In Open Space (dust)
- BigQuery Dataset Public Access (gcp)
- Public Org Repository (huggingface)
- Public Gated Repository Misconfiguration (huggingface)
- Public Status Page (incidentio)
- Workflow Unconstrained on All Incidents (incidentio)
- Vault Exported (1password)
- Prompt/Response Logging Enabled (openrouter)
- Logging At Full Sampling (openrouter)
- Observability Broadcast Enabled (openrouter)
- Data-Discount Logging Enabled (openrouter)
- LLM Data Exported To External Sink (openrouter)
- Guardrail Without Zero Data Retention Enforcement (openrouter)
- Guardrail With Partial Zero Data Retention Enforcement (openrouter)
- Guardrail Allows Training Data (openrouter)
- Permissive Privacy Posture (openrouter)
- Storage Container Public (ovhcloud)
- Public Sharing Model (salesforce)
- External Access Read Write (salesforce)
- Shared Issues Enabled (sentry)
- Enhanced Privacy Disabled (sentry)
- Open Membership (sentry)
- Event Attachments Access (sentry)
- Data Scrubber Disabled (sentry)
- Data Scrubber Defaults Disabled (sentry)
- Debug Files Access (sentry)
- Password Protection Disabled (shopify)
- Webhook Using HTTP (shopify)
- Webhook External Destination (shopify)
- Unauthenticated Read Customers Scope (shopify)
- Write Customers Read Payment Scope (shopify)
- No Storage Integration Required (snowflake)
- Unload To Inline URL (snowflake)
- Unload To Internal Stages (snowflake)
- Outbound Share Review (snowflake)
- Share To Many Accounts (snowflake)
- Share Listing Unrestricted (snowflake)
- Public Team (teams)
- External Shared Channel (teams)
- External Messaging Enabled (teams)
- Unrestricted External Federation (teams)
- Workspace Global Remote State (terraform_cloud)
- Sensitive Env Var Policy Disabled (vercel)
- IP Visibility Enabled (vercel)
- Public Source (vercel)
- Directory Listing Enabled (vercel)
- Plain Text Secret (vercel)
- Exposed to Preview (vercel)
- Recipe Integrates with Sensitive Application (workato)
DORA-9.12 — Data sharing and external exposure
Control external sharing, third-party integrations and delegated access to entity data (Article 9(4)(e))
- Jira Project Public Access (atlassian)
- Confluence Space Anonymous Access (atlassian)
- Confluence Space Public Links (atlassian)
- Jira Project Externally Shared (atlassian)
- Confluence Space Externally Shared (atlassian)
- Archived Confluence Space With Anonymous Access (atlassian)
- Application Risky Grant Type (auth0)
- Public Client With Confidential Grant (auth0)
- Wildcard Callback URL (auth0)
- S3 Bucket Public Access Not Blocked (aws)
- S3 Bucket Policy Public (aws)
- Bedrock Agent Multiple Knowledge Bases (bedrock)
- Bedrock Agent No Customer-Managed Encryption (bedrock)
- Bedrock Agent Session Memory Enabled (bedrock)
- Bedrock Agent Long Session TTL (bedrock)
- Group Allows External Collaborator Invitations (box)
- Outbound Collaboration Whitelist Entry (box)
- Excessive Collaboration Whitelist Entries (box)
- Dashboard Publicly Shared and Writable (datadog)
- Suggest Members Enabled (dropbox)
- Public Storage Bucket (gcp)
- Group Public Visibility (gitlab)
- Group Sharing Unlocked (gitlab)
- Group Forking Allowed Outside (gitlab)
- Group Sharing Outside Organization (gitlab)
- Public Project (gitlab)
- Active External Data Link (google_ads)
- Overly Permissive Dashboard (grafana)
- Public Dashboard (grafana)
- Overly Permissive Folder (grafana)
- Workflow Accesses Private Data (incidentio)
- LangSmith Agent Dataset Access (langsmith)
- LangSmith Agent Retriever Tools (langsmith)
- Shared Folder Credential Export Permission (lastpass)
- Guest Access to Group Content Not Restricted (m365)
- Organization Sharing Enabled (m365)
- Default Calendar Sharing Too Permissive (m365)
- Default Group Access Public (m365)
- External Forwarding on Mailbox (m365)
- Mailbox Delivers to Both Mailbox and Forward (m365)
- Forwarding SMTP to External (m365)
- Forwarding Address Configured (m365)
- LinkedIn Integration Enabled in OWA (m365)
- Mobile Contact Sync Enabled in OWA (m365)
- Transport Rule Redirects Externally (m365)
- Transport Rule Forwards Outside Org (m365)
- Remote Domain Auto-Forwarding Allowed (m365)
- Default Sharing Policy Allows External (m365)
- Sharing Policy Allows External Domains (m365)
- Distribution List Allows External Senders (m365)
- Distribution Group Open Join Policy (m365)
- Public Microsoft 365 Group (m365)
- Outbound Spam External Forwarding Allowed (m365)
- Copilot Agent Tenant-Wide Sharing (m365)
- Copilot Agent Broad Sharing (m365)
- Copilot Agent Web Search Enabled (m365)
- Library Shared Org-Wide With Documents (mistral)
- Library Shared Org-Wide Editable (mistral)
- n8n Workflow Agent Database Access (n8n)
- n8n Workflow Agent File Access (n8n)
- n8n Workflow Agent Code Execution (n8n)
- Publicly Shared Page (notion)
- Stale Public Page (notion)
- Publicly Shared Database (notion)
- Root Level Public Page (notion)
- Stale Publicly Shared Database (notion)
- Root Level Public Database (notion)
- Inline Public Database (notion)
- Extension Disabled (pagerduty)
- Webhook External URL (pagerduty)
- Webhook Inactive (pagerduty)
- Application Risky Grant Type (pingone)
- Application Public Client Without Auth (pingone)
- Application Wildcard Redirect URI (pingone)
- Disabled Application Still Present (pingone)
- OAuth App Long Token Lifespan (servicenow)
- OAuth App Insecure Redirect (servicenow)
- Insecure Plugin Active (servicenow)
- Integration Using Basic Auth (servicenow)
- Webhook Customer Data Topic (shopify)
- API Client No IP Restriction (workato)
- Excessive API Clients (workato)
- API Endpoint Inactive (workato)
- API Platform Client Static Auth Token (workato)
- API Platform Client No Active Keys (workato)
- Developer API Client with Admin Role (workato)
- Stale Integration System (workday)
- Integration With Excessive Scope (workday)
- Group Allows External Members (workspace)
- Group Allows External Posting (workspace)
- Group Allows Open Join (workspace)
- Group Public Conversations (workspace)
- Group Domain-Wide Membership Visibility (workspace)
- Group Contact Owner Anyone (workspace)
- Group Discoverable by Anyone (workspace)
- Mail Delegation Enabled (workspace)
- Drive External Sharing Enabled (workspace)
- Drive Link Sharing Anyone (workspace)
- Drive Sharing Outside Organization (workspace)
- Drive Publish to Web Allowed (workspace)
- Drive External Shared Drives Allowed (workspace)
- Drive File Public Sharing (workspace)
- Drive File Publicly Indexed (workspace)
- Drive File Link Sharing Enabled (workspace)
- Drive File Shared With Personal Email (workspace)
- Drive File External Edit Access (workspace)
- Drive Shared Drive Has External Members (workspace)
- Drive File Owner Is External (workspace)
- Drive File Shared With External Domain (workspace)
- Drive File Stale External Sharing (workspace)
- Drive File Excessive Permissions (workspace)
- Drive File External Commenter Access (workspace)
- Drive File Broad Internal Sharing (workspace)
- Drive File Org-Wide Link Sharing (workspace)
- Drive User Excessive External Sharing (workspace)
- Shared Drive Allows External Users (workspace)
- Shared Drive Allows Non-Members (workspace)
- Shared Drive No Download Restriction (workspace)
- Shared Drive Has External Members (workspace)
- Chat External Access Enabled (workspace)
- DLP Rules Not Configured (workspace)
- Gmail Filter Forwards Externally (workspace)
- Gmail Multiple Forwarding Destinations (workspace)
- Gmail Suspicious Forwarding (workspace)
- Live Streaming Enabled (zoom)
DORA-9.13 — Device and endpoint trust
Ensure devices accessing ICT systems meet defined security and trust requirements (Article 9(4)(d))
- User Exempt from Device Limits (box)
- No Device Pins Configured (box)
- Widely Deployed Extension With Risky Permissions (chrome_enterprise)
- Browser Running on Unsupported OS (chrome_enterprise)
- Admin-Forced Extension With Risky Permissions (chrome_enterprise)
- Shadow IT Extension Widely Deployed (chrome_enterprise)
- Device Running Outdated OS (Telemetry) (chrome_enterprise)
- EMM Not Required (dropbox)
- Stale Web Session (dropbox)
- Stale Desktop Session (dropbox)
- Excessive Device Sessions (dropbox)
- Mobile Device Unsupervised (jamf)
- Mobile Device Unmanaged (jamf)
- System Agent Inactive (jumpcloud)
DORA-10 — Detection
Mechanisms to promptly detect anomalous activities and ICT incidents (Article 10)
DORA-10.1 — Logging and audit trails
Record and retain logs and audit trails of activity across ICT systems (Article 10(1)/(3))
- No Recent Audit Events (auth0)
- Management API Change Event (auth0)
- CloudTrail Not Logging (aws)
- CloudTrail Log Validation Disabled (aws)
- CloudTrail Not Multi-Region (aws)
- CloudTrail Data Events Disabled (aws)
- VPC Flow Logs Disabled (aws)
- AWS Config Not Recording (aws)
- NSG Flow Logs Disabled (azure)
- Key Vault Diagnostic Logging Disabled (azure)
- SQL Auditing Disabled (azure)
- SQL Audit Retention Short (azure)
- App Service Logging Disabled (azure)
- Diagnostic Retention Short (azure)
- Alert Policy Assignment Missing (azure)
- Alert NSG Create Missing (azure)
- Alert NSG Delete Missing (azure)
- Alert Security Solution Create Missing (azure)
- Alert Security Solution Delete Missing (azure)
- Alert SQL Firewall Missing (azure)
- Alert Disabled (azure)
- Bedrock Model Invocation Logging Disabled (bedrock)
- Audit Logging Disabled (datadog)
- Audit Log Retention Period (datadog)
- Audit Retention Below Critical Threshold (datadog)
- Monitoring Disabled (digitalocean)
- Office Add-in Disabled (dropbox)
- Suspended Member Not Removed (dropbox)
- Account Not Org-Scoped (No Audit Visibility) (figma)
- Activity Permission Change Event (figma)
- Activity Member Role Change Event (figma)
- Audit Logging Not Enabled (gcp)
- Data Access Logs Incomplete (gcp)
- Subnet Flow Logs Disabled (gcp)
- PostgreSQL log_connections Not Enabled (gcp)
- PostgreSQL log_disconnections Not Enabled (gcp)
- PostgreSQL log_min_messages Below WARNING (gcp)
- PostgreSQL log_min_error_statement Above ERROR (gcp)
- PostgreSQL log_min_duration_statement Not Disabled (gcp)
- PostgreSQL pgaudit Extension Not Enabled (gcp)
- Audit Logs Unavailable (huggingface)
- No Recent Directory Insights Events (jumpcloud)
- Global Mailbox Auditing Disabled (m365)
- Mailbox Audit Bypass Configured (m365)
- Mailbox Auditing Disabled (m365)
- Shared Mailbox Sent-As Not Audited (m365)
- Shared Mailbox Sent-On-Behalf Not Audited (m365)
- Non-Shared Mailbox Audit Bypass (m365)
- User Mailbox Auditing Disabled (m365)
- Unified Audit Log Not Enabled (m365)
- Audit Log Anonymous Actor (notion)
- Master Password Changed (1password)
- Sensitive Audit Event (openai)
- Session Recording Disabled (teleport)
- Session Recording in Async Mode (teleport)
- Session Recording in Proxy Mode (teleport)
- Proxy Host Key Checks Disabled (teleport)
- Role Disables Session Recording (teleport)
- Audit Log Using Local Filesystem Storage (teleport)
- No Log Drain (vercel)
- Log Drain Disabled (vercel)
- Audit Logging Disabled (workday)
DORA-10.2 — Anomaly and threat detection
Detect anomalous activity, including performance issues and threat indicators (Article 10(1))
- Safe Browsing Disabled (chrome_enterprise)
- Login from Disallowed Country (generic)
- Login from New Country (generic)
- Impossible Travel Login (generic)
DORA-10.3 — Detection coverage review
Review and test detection mechanisms and alert thresholds for adequate coverage (Article 10(2)/(4))
DORA-11 — Response and Recovery
ICT business continuity, response and recovery capability (Articles 11-12)
DORA-11.1 — ICT business continuity policy
A documented ICT business continuity policy covering ICT-supported business functions (Article 11(1))
DORA-11.2 — Response and recovery plans
Response and recovery plans with defined objectives, activated and tested for ICT incidents (Article 11(3))
DORA-12.1 — Backup policy and procedures
Backup policies and procedures defining scope, frequency and retention of backups (Article 12(1))
- No Retention Policies Defined (box)
- Retired Retention Policy (box)
- Short Retention Period (box)
- Modifiable Retention Policy (box)
- Permanent Delete Disposition Action (box)
- No Indefinite Retention Policies (box)
- Single Node Cluster (digitalocean)
- No Health Check (digitalocean)
- Suspended Account in MCC Hierarchy (google_ads)
- Org Credit Balance Depleted (openrouter)
DORA-12.2 — Restoration and recovery testing
Test restoration from backup and recovery procedures, isolated from production systems (Article 12(2))
DORA-13 — Learning and Communication
Post-incident learning, awareness and crisis communication (Articles 13-14)
DORA-13.1 — Post-incident review and lessons learned
Conduct post-incident reviews and feed findings back into the ICT risk framework (Article 13(2))
DORA-13.2 — ICT security awareness and training
Deliver ICT security awareness programs and digital operational resilience training to staff (Article 13(6))
DORA-14.1 — Crisis communication plan
Communication plans for disclosing ICT incidents to clients, counterparts and the public (Article 14)
DORA-17 — ICT Incident Management
Detect, manage, classify and report ICT-related incidents (Articles 17-19)
DORA-17.1 — ICT incident management process
A documented process to detect, manage, log and follow up on ICT-related incidents (Article 17(1))
DORA-17.2 — Incident detection and recording
Record all ICT-related incidents and significant cyber threats with defined roles and escalation (Article 17(2)/(3))
- Single Responder Escalation (incidentio)
- Single Rotation Schedule (incidentio)
- Schedule Without Active Shift (incidentio)
- Workflow Disabled or Error (incidentio)
- Workflow Ignores Step Errors (incidentio)
- Alert Source No Auto-Resolve (incidentio)
- Alert Route No Escalation Path (incidentio)
- Alert Route No Grouping (incidentio)
- Escalation Path No Current Responders (incidentio)
- Alert Source Auto-Resolve Timeout Too Long (incidentio)
- Escalation Path Shallow (incidentio)
- Service Without Escalation Policy (pagerduty)
- Possibly Abandoned Service (pagerduty)
- Service Without Auto-Resolve (pagerduty)
- Single User Escalation Rule (pagerduty)
- Escalation Policy Without Schedule (pagerduty)
- Escalation Policy Without Loops (pagerduty)
- Single User Schedule (pagerduty)
- Incident Auto-Assignment Disabled (servicenow)
- Change Approval Not Required (servicenow)
- Change Risk Assessment Disabled (servicenow)
DORA-18.1 — Incident classification
Classify ICT incidents against the major-incident criteria and determine their impact (Article 18)
DORA-19.1 — Reporting to the competent authority
Submit initial, intermediate and final reports on major ICT incidents to the competent authority (Article 19(4))
DORA-19.2 — Client and user notification
Inform affected clients and users of major ICT incidents and protective measures (Article 19(3))
DORA-24 — Digital Operational Resilience Testing
A risk-based program of digital operational resilience testing (Articles 24-27)
DORA-24.1 — Resilience testing program
Establish and maintain a sound, comprehensive digital operational resilience testing program (Article 24(1))
DORA-25.1 — Vulnerability assessment and scanning
Perform vulnerability assessments and scans of ICT systems supporting critical functions (Article 25(1))
DORA-26.1 — Threat-led penetration testing
Carry out advanced threat-led penetration testing (TLPT) at least every three years (Article 26(1))
DORA-27.1 — Tester requirements
Testers meet the independence, reputation and technical-capability requirements (Article 27)
DORA-28 — ICT Third-Party Risk
Manage ICT third-party risk as an integral part of the ICT risk framework (Articles 28-30)
DORA-28.1 — Third-party risk strategy and policy
A strategy and policy on ICT third-party risk, reviewed regularly (Article 28(2))
DORA-28.2 — Register of Information
Maintain and update a register of information on all contractual arrangements with ICT third-party service providers (Article 28(3))
DORA-28.3 — Pre-contract due diligence
Assess and perform due diligence on ICT third-party providers before entering a contractual arrangement (Article 28(4))
DORA-28.4 — Third-party and app-governance monitoring
Continuously monitor ICT third-party providers, integrations and delegated application access (Article 28(1))
- Bedrock Action Group Code Interpreter (bedrock)
- Bedrock Action Group Computer Use / Bash (bedrock)
- Bedrock Agent Custom Orchestration (bedrock)
- Bedrock Agent Supervisor Mode (bedrock)
- Bedrock Agent High Risk Unblocked (bedrock)
- Excessive Applications Installed (box)
- Stale Extension Request (chrome_enterprise)
- Orb Allowlist Empty (circleci)
- AI Gateway Logging Disabled (cloudflare)
- AI Gateway No Authentication (cloudflare)
- AI Gateway No Rate Limiting (cloudflare)
- AI Gateway ZDR Disabled (cloudflare)
- AI Gateway No Guardrails (cloudflare)
- AI Gateway No Log Export (cloudflare)
- AI Gateway Log Overflow Silent (cloudflare)
- AI Gateway Aggressive Retry Without Rate Limit (cloudflare)
- Worker AI Binding Ungoverned (cloudflare)
- AI Gateway Account-Wide No Authentication (cloudflare)
- Fine-Tuned Model Present (cloudflare)
- Cloudflare AI Gateway Agent High Risk Unblocked (cloudflare)
- Excessive Integrations (discord)
- Webhook Inventory (discord)
- Orphaned Webhook (discord)
- Bot With Admin (discord)
- Connected App with Full Dropbox Access (dropbox)
- Agent Using Unapproved Model Provider (dust)
- Shadow Tool Usage (dust)
- Billing Setup Pending (google_ads)
- Canceled Account in MCC Hierarchy (google_ads)
- Billing Setup Without Payments Account (google_ads)
- Access Policy Without Display Name (grafana_cloud)
- Alert Source Unowned (incidentio)
- Alert Route No Conditions (incidentio)
- Escalation Path No Team Assignment (incidentio)
- Schedule No Team Assignment (incidentio)
- Active Workflow Never Updated (incidentio)
- Schedule Missing Timezone (incidentio)
- Schedule No Holiday Configuration (incidentio)
- Configuration Profile Scoped To All Computers (jamf)
- Policy Disabled (jamf)
- Policy Scoped To All Computers (jamf)
- LangSmith Agent Unmonitored (langsmith)
- LangSmith Agent High Run Volume (langsmith)
- LangSmith Agent No Evaluation (langsmith)
- LangSmith Agent High Risk Unblocked (langsmith)
- Copilot Agent Generative Orchestration (m365)
- Copilot Agent No Authentication (m365)
- Copilot Agent Multi-Channel Exposure (m365)
- Copilot Agent Unconstrained Tool Use (m365)
- Copilot Agent Unreviewed (14+ days) (m365)
- Copilot Agent High Risk Unblocked (m365)
- n8n Workflow Agent No Error Handling (n8n)
- n8n Workflow Agent Webhook Trigger (n8n)
- n8n Workflow Agent Schedule Trigger (n8n)
- n8n Workflow Agent Multi AI Model (n8n)
- n8n Workflow Agent High Risk Unblocked (n8n)
- Message Edit Unrestricted (slack)
- Slackbot Responses Unrestricted (slack)
- Everyone Notify General (slack)
- Archive Channel Unrestricted (slack)
- Remove Public Channel Unrestricted (slack)
- Workflow Creation Unrestricted (slack)
- Remove Private Channel Unrestricted (slack)
- User Groups Unrestricted (slack)
- Notify Channel Unrestricted (slack)
- Display Name Not Validated (slack)
- Default Channels Excessive (slack)
- Inactive Channel (slack)
- App No Description (slack)
- Team Without Description (teams)
- Large Team Without Moderation (teams)
- Channel Without Moderation (teams)
- Unapproved Third-Party App (teams)
- Custom App Sideloading (teams)
- Message Edit Delete Unrestricted (teams)
- Recipe High Error Rate (workato)
- Stopped Recipe With Errors (workato)
DORA-28.5 — Exit strategies and transition plans
Exit strategies and transition plans for ICT services supporting critical or important functions (Article 28(8))
DORA-29.1 — Concentration risk assessment
Assess ICT concentration risk arising from contractual arrangements with providers (Article 29(1))
DORA-29.2 — Sub-outsourcing conditions
Conditions governing sub-outsourcing of ICT services supporting critical functions (Article 29(2))
DORA-30.1 — Key contractual provisions
Contractual arrangements include the required provisions on access, audit, security and termination (Article 30)