Akamai network security checks
IP allow-lists, TLS, DNS and edge settings that keep the application reachable only from where it should be.
On Akamai, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.
Checks (3)
severity: high DNSSEC Not Enabled fix difficulty: medium #
Enable DNSSEC signing on the Akamai Edge DNS zone to protect against DNS spoofing
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to DNS > Edge DNS
- Select the affected DNS zone
- Click "Zone Settings" and locate the DNSSEC section
- Enable DNSSEC by clicking "Sign Zone" (Akamai generates and manages the signing keys)
- Retrieve the DS record provided by Akamai
- Submit the DS record to your domain registrar to complete the DNSSEC chain of trust
Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9
severity: medium TSIG Not Enabled fix difficulty: medium #
Enable TSIG authentication for DNS zone transfers to prevent unauthorised zone data access
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to DNS > Edge DNS
- Select the affected DNS zone and click "Zone Settings"
- Under "Zone Transfer" settings, locate the TSIG configuration section
- Generate a TSIG shared secret key (or use an existing one from your secondary DNS system)
- Enter the TSIG key name, algorithm (HMAC-SHA256 recommended), and secret value
- Associate the TSIG key with the allowed secondary name servers and save
Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9
severity: low SOA Serial Stale fix difficulty: medium #
Investigate and resolve why the DNS zone SOA serial has not been updated recently
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to DNS > Edge DNS
- Select the affected DNS zone and review recent change history
- Check whether DNS record changes have been submitted and propagated correctly
- If records have been changed but the SOA serial was not incremented, manually update a record to trigger a serial bump
- If no changes are expected, verify that zone transfer replication is working and secondary servers are in sync
- Monitor the zone for correct propagation after any corrective action
Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9