Akamai encryption, keys & secrets security checks
Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.
On Akamai, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.
Checks (5)
severity: high HSTS Not Enabled fix difficulty: easy #
Enable HTTP Strict Transport Security (HSTS) header on the Akamai property
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to CDN > Properties (Property Manager)
- Select the affected property and click "Edit New Version"
- In the rule tree, add a behavior under the default rule or HTTPS match
- Search for "Modify Outgoing Response Header" or "HTTP Strict Transport Security" behavior
- Set the Strict-Transport-Security header with max-age of at least 31536000
- Activate the updated property version to staging then production
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium HSTS Max-Age Too Short fix difficulty: easy #
Increase the HSTS max-age directive to at least 31536000 seconds (one year)
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to CDN > Properties (Property Manager)
- Select the affected property and click "Edit New Version"
- Locate the HSTS or Modify Outgoing Response Header behavior in the rule tree
- Update the max-age value in the Strict-Transport-Security header to 31536000 or higher
- Optionally add includeSubDomains and preload directives if appropriate
- Activate the updated property version to staging then production
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: low HTTP/2 Not Enabled fix difficulty: easy #
Enable HTTP/2 on the Akamai property to improve performance and security
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to CDN > Properties (Property Manager)
- Select the affected property and click "Edit New Version"
- In the rule tree, click "Add Behavior" and search for "HTTP/2"
- Add the HTTP/2 behavior and ensure it is enabled
- Verify the property's edge hostname uses an SSL/TLS-enabled certificate (HTTP/2 requires TLS)
- Activate the updated property version to staging then production
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: high Origin Not Using TLS fix difficulty: medium #
Configure the origin server to use HTTPS so traffic between Akamai and origin is encrypted
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to CDN > Properties (Property Manager)
- Select the affected property and click "Edit New Version"
- Locate the "Origin Server" behavior in the rule tree
- Under "Forward Protocol", change the protocol from HTTP to HTTPS
- Ensure the origin server has a valid TLS certificate installed; configure verification settings
- Activate the updated property version to staging then production
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium Edge Hostname Using Shared Cert fix difficulty: hard #
Replace the shared certificate with a dedicated TLS certificate for the edge hostname
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to CDN > Edge Hostnames
- Locate the edge hostname using a shared certificate
- Click "Edit" and change the certificate option from "Shared Certificate" to "Enhanced TLS" or "Standard TLS"
- Select or provision a dedicated certificate for the hostname (via CPS - Certificate Provisioning System)
- Save the updated edge hostname configuration
- Update any associated property activations if required
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7