Cloudflare encryption, keys & secrets security checks
Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.
On Cloudflare, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.
Checks (9)
severity: critical SSL Encryption Disabled fix difficulty: easy #
Enable SSL/TLS encryption on the Cloudflare zone and set the mode to at least Full
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Overview
- Set the encryption mode to Full or Full (strict)
- Save changes and verify HTTPS is working
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: high SSL Mode Flexible fix difficulty: medium #
Upgrade Cloudflare SSL mode from Flexible to Full (strict) to encrypt origin traffic
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Overview
- Change the encryption mode from Flexible to Full (strict)
- Ensure your origin server has a valid SSL certificate installed
- Save changes and verify end-to-end HTTPS is working
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: high Always Use HTTPS Disabled fix difficulty: easy #
Enable Always Use HTTPS for the Cloudflare zone to redirect all HTTP traffic
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Edge Certificates
- Enable Always Use HTTPS
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium Automatic HTTPS Rewrites Disabled fix difficulty: easy #
Enable Automatic HTTPS Rewrites for the Cloudflare zone to fix mixed content issues
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Edge Certificates
- Enable Automatic HTTPS Rewrites
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: high HSTS Disabled fix difficulty: easy #
Enable HSTS on the Cloudflare zone with a max-age of at least 6 months
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Edge Certificates
- Scroll to HTTP Strict Transport Security (HSTS) and click Enable
- Configure max-age to at least 6 months and enable includeSubDomains
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: high Minimum TLS Version Weak fix difficulty: easy #
Set the Cloudflare zone minimum TLS version to 1.2 or higher
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Edge Certificates
- Set Minimum TLS Version to TLS 1.2 or higher
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: low Opportunistic Encryption Disabled fix difficulty: easy #
Enable Opportunistic Encryption for the Cloudflare zone
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Edge Certificates
- Enable Opportunistic Encryption
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC7.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium TLS 1.3 Disabled fix difficulty: easy #
Enable TLS 1.3 for the Cloudflare zone to improve security and performance
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Edge Certificates
- Enable TLS 1.3
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium TLS Mode Not Strict fix difficulty: medium #
Set Cloudflare SSL/TLS encryption mode to Full (Strict) to verify origin certificates
- Log in to the Cloudflare Dashboard and select the zone
- Navigate to SSL/TLS > Overview
- Set the encryption mode to Full (Strict)
- Ensure a valid SSL certificate is installed on the origin server
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7