Skip to content

Akamai configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Akamai, Black Cat runs 15 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.

Checks (15)

severity: low Group With No Contracts fix difficulty: easy #

Associate contracts with the empty group or remove the group if it is unused

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > Groups
  3. Locate the group flagged as having no associated contracts
  4. Determine whether the group is intended to manage any contracts or resources
  5. If the group is needed, navigate to the Contracts section and associate the relevant contracts
  6. If the group is unused, click "Delete" to remove it and reduce administrative clutter

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical WAF In Alert-Only Mode fix difficulty: medium #

Switch the WAF security configuration from alert-only mode to deny/block mode

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration from the list
  4. Click "Edit" to open the configuration editor
  5. Under "WAF Mode", change the setting from "Alert" to "Deny" (or "Block")
  6. Review the attack group settings to ensure no rules will cause false-positive disruption
  7. Activate the updated configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Rate Controls Disabled fix difficulty: medium #

Enable rate controls in the Akamai security configuration to mitigate volumetric attacks

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration
  4. Click "Edit" and navigate to "Rate Controls" in the left sidebar
  5. Click "Add Rate Control" and configure thresholds appropriate for your traffic patterns
  6. Set the enforcement action to "Deny" for requests exceeding thresholds
  7. Activate the updated configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Slow POST Protection Disabled fix difficulty: medium #

Enable Slow POST protection to defend against slow-body denial-of-service attacks

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration and click "Edit"
  4. Navigate to "Slow POST Protection" in the left sidebar
  5. Enable Slow POST protection and configure duration and minimum rate thresholds
  6. Set the action to "Abort" for connections detected as slow POST attacks
  7. Activate the updated configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium IP Firewall Not Configured fix difficulty: medium #

Configure IP-based firewall rules in the Akamai security configuration

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration and click "Edit"
  4. Navigate to "Network Layer Controls" > "IP/Geo Firewall" in the left sidebar
  5. Add IP blocklist or allowlist rules appropriate for your application
  6. Set the enforcement action (deny or alert) for matched IP ranges
  7. Activate the updated configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Geo Firewall Not Configured fix difficulty: medium #

Configure geographic blocking rules to restrict traffic from high-risk regions

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration and click "Edit"
  4. Navigate to "Network Layer Controls" > "IP/Geo Firewall" in the left sidebar
  5. Click "Add Geographic Control" and select the countries or regions to block
  6. Set the enforcement action to "Deny" for matched geographic locations
  7. Activate the updated configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high WAF Policy Alert-Only Mode fix difficulty: medium #

Switch the WAF policy from alert-only mode to deny mode to enforce active blocking

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration and open the WAF policy
  4. Under "Attack Groups" or "WAF Mode", identify groups set to "Alert" only
  5. Change the mode for each attack group from "Alert" to "Deny"
  6. Review tuning recommendations to minimise false positives before activating
  7. Activate the updated policy to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Rate Control Threshold Too Permissive fix difficulty: medium #

Lower the rate control threshold to a value that reflects legitimate traffic baselines

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Application Security
  3. Select the affected security configuration and click "Edit"
  4. Navigate to "Rate Controls" in the left sidebar
  5. Open the flagged rate control rule and review the current threshold value
  6. Lower the threshold to match observed legitimate peak traffic (use reporting data for guidance)
  7. Activate the updated configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Bot Management Disabled fix difficulty: hard #

Enable Akamai Bot Manager to detect and mitigate automated bot traffic

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Security > Bot Manager
  3. Select the property or security configuration to protect
  4. Enable Bot Manager and choose a protection level (Standard or Premier)
  5. Configure bot categories (known bots, unknown bots, user-defined bots) and their actions
  6. Set enforcement actions (allow, deny, slow, redirect, challenge) per bot category
  7. Activate the configuration to production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Edge Hostname IPv4 Only fix difficulty: easy #

Enable dual-stack (IPv4 and IPv6) support on the Akamai edge hostname

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Edge Hostnames
  3. Locate the edge hostname configured as IPv4-only
  4. Click "Edit" to modify the hostname configuration
  5. Change the IP version setting from "IPv4" to "IPv4 + IPv6" (dual stack)
  6. Save the updated hostname configuration
  7. Verify DNS resolution returns both A and AAAA records after propagation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low SureRoute Not Enabled fix difficulty: easy #

Enable SureRoute on the Akamai property to optimise origin connectivity performance

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. In the rule tree, click "Add Behavior" and search for "SureRoute"
  5. Add the SureRoute behavior and enable it with the recommended settings
  6. Configure the SureRoute test object URL if required
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Property No Origin Failover fix difficulty: medium #

Configure origin failover on the Akamai property to improve resilience

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. Locate the "Origin Server" behavior in the rule tree and click "Edit"
  5. Enable "Origin Failover" and add a secondary (failover) origin hostname
  6. Configure the failover conditions (e.g., HTTP error codes that trigger failover)
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Property Caching Disabled fix difficulty: easy #

Enable caching on the Akamai property to improve performance and reduce origin load

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. In the rule tree, locate or add a "Caching" behavior
  5. Set the caching option to "Cache" with an appropriate TTL for your content type
  6. Ensure cache keys are configured correctly (vary by relevant request headers if needed)
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low CP Code Unused fix difficulty: medium #

Remove CP codes that are no longer associated with any property to reduce billing clutter

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > CP Codes (or Reporting > CP Codes)
  3. Identify CP codes with no associated properties or recent traffic
  4. Confirm with the account team that the CP code is safe to remove
  5. Contact Akamai support or use the API to delete unused CP codes (Control Center UI may not support direct deletion)
  6. Document the removal for billing and audit purposes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Account Protection Disabled fix difficulty: medium #

Enable Account Protection Controls in the security configuration

  1. Log in to Akamai Control Center
  2. Navigate to Security > Application Security
  3. Select the security configuration
  4. Go to Protections > Account Protections
  5. Enable the Account Protection Controls toggle
  6. Activate the configuration version to staging, then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Akamai checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial