Skip to content

Akamai network security checks

IP allow-lists, TLS, DNS and edge settings that keep the application reachable only from where it should be.

On Akamai, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.

Checks (3)

severity: high DNSSEC Not Enabled fix difficulty: medium #

Enable DNSSEC signing on the Akamai Edge DNS zone to protect against DNS spoofing

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to DNS > Edge DNS
  3. Select the affected DNS zone
  4. Click "Zone Settings" and locate the DNSSEC section
  5. Enable DNSSEC by clicking "Sign Zone" (Akamai generates and manages the signing keys)
  6. Retrieve the DS record provided by Akamai
  7. Submit the DS record to your domain registrar to complete the DNSSEC chain of trust

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: medium TSIG Not Enabled fix difficulty: medium #

Enable TSIG authentication for DNS zone transfers to prevent unauthorised zone data access

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to DNS > Edge DNS
  3. Select the affected DNS zone and click "Zone Settings"
  4. Under "Zone Transfer" settings, locate the TSIG configuration section
  5. Generate a TSIG shared secret key (or use an existing one from your secondary DNS system)
  6. Enter the TSIG key name, algorithm (HMAC-SHA256 recommended), and secret value
  7. Associate the TSIG key with the allowed secondary name servers and save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: low SOA Serial Stale fix difficulty: medium #

Investigate and resolve why the DNS zone SOA serial has not been updated recently

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to DNS > Edge DNS
  3. Select the affected DNS zone and review recent change history
  4. Check whether DNS record changes have been submitted and propagated correctly
  5. If records have been changed but the SOA serial was not incremented, manually update a record to trigger a serial bump
  6. If no changes are expected, verify that zone transfer replication is working and secondary servers are in sync
  7. Monitor the zone for correct propagation after any corrective action

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

More Akamai checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial