| AWS RDS database should be protected from direct internet traffic | Critical | rds | 1 |
| AWS root account should have MFA enabled | Critical | iam | 1 |
| AWS S3 bucket public access should be blocked | Critical | s3 | 1 |
| AWS user should have MFA enabled | Critical | iam | 1 |
| GCP user should have MFA enabled | Critical | iam | 1 |
| AWS access should be removed for offboarded user | High | iam | 1 |
| AWS application load balancer should be protected from direct internet traffic | High | loadbalancer | 1 |
| AWS Cloud Trail logging bucket should be protected from direct internet traffic | High | s3 | 1 |
| AWS CloudTrail log file integrity validation should be enabled | High | logging | 1 |
| AWS CloudTrail should be enabled | High | logging | 1 |
| AWS DynamoDB backup should be enabled | High | dynamodb | 1 |
| AWS DynamoDB point in time recovery should be enabled | High | dynamodb | 1 |
| AWS DynamoDB should be encrypted | High | dynamodb | 1 |
| AWS EBS volume backup should be enabled | High | ebs | 1 |
| AWS EBS volume should be encrypted | High | ebs | 1 |
| AWS EC2 instance should be protected from direct internet traffic | High | ec2 | 1 |
| AWS ECR repository should be encrypted | High | ecr | 1 |
| AWS EFS storage backup should be enabled | High | efs | 1 |
| AWS EFS storage should be encrypted | High | efs | 1 |
| AWS FSX File System storage backup should be enabled | High | fsx | 1 |
| AWS FSX File System storage should be encrypted | High | fsx | 1 |
| AWS GuardDuty should be enabled | High | security | 1 |
| AWS Lightsail disk backup should be enabled | High | lightsail | 1 |
| AWS Lightsail disk should be encrypted | High | lightsail | 1 |
| AWS load balancer should redirect traffic from http to https | High | loadbalancer | 1 |
| AWS RDS database backup should be enabled | High | rds | 1 |
| AWS RDS database storage should be encrypted | High | rds | 1 |
| AWS Redshift cluster backup should be enabled | High | redshift | 1 |
| AWS Redshift cluster should be encrypted | High | redshift | 1 |
| AWS root account usage should be avoided | High | iam | 1 |
| AWS S3 storage bucket should be encrypted | High | s3 | 1 |
| AWS should be on https | High | network | 1 |
| AWS should redirect http to https | High | network | 1 |
| AWS user access keys should not be older than 90 days | High | iam | 1 |
| AWS VPC flowlogs should be captured | High | vpc | 1 |
| Azure access should be removed for offboarded user | High | iam | 1 |
| Azure activity logs should be archived | High | logging | 1 |
| Azure CosmosDB backup should be enabled | High | database | 1 |
| Azure CosmosDB database should be protected from direct internet traffic | High | database | 1 |
| Azure CosmosDB should be encrypted | High | database | 1 |
| Azure Databricks workspace backup should be enabled | High | data | 1 |
| Azure Databricks workspace should be encrypted | High | data | 1 |
| Azure Defender should be enabled | High | security | 1 |
| Azure Disk should be encrypted | High | compute | 1 |
| Azure Key Vault should be recoverable | High | security | 1 |
| Azure postgreSQL Database Server enforce SSL connection should be enabled | High | database | 1 |
| Azure should be on https | High | network | 1 |
| Azure should redirect http to https | High | network | 1 |
| Azure SQL database backup should be enabled | High | database | 1 |
| Azure SQL database should be encrypted | High | database | 1 |
| Azure SQL database should be protected from direct internet traffic | High | database | 1 |
| Azure storage account allow blob anonymous access should be disabled | High | storage | 1 |
| Azure storage account default network access rule should set to deny | High | storage | 1 |
| Azure storage account Minimum TLS version should be version 1.2 | High | storage | 1 |
| Azure storage account public network access should be disabled | High | storage | 1 |
| Azure storage account secure transfer required should be enabled | High | storage | 1 |
| Azure storage account should be encrypted | High | storage | 1 |
| Azure VM should be protected from direct internet traffic | High | compute | 1 |
| Azure Web App is using the latest version of TLS encryption | High | webapp | 1 |
| Azure Web App Redirects All HTTP traffic to HTTPS in Azure App Service | High | webapp | 1 |
| GCP BigQuery storage should be encrypted | High | bigquery | 1 |
| GCP Bigtable should be encrypted | High | bigtable | 1 |
| GCP Biqquery dataset should be protected from direct internet traffic | High | bigquery | 1 |
| GCP bucket storage should be encrypted | High | storage | 1 |
| GCP Cloud Spanner should be encrypted | High | spanner | 1 |
| GCP Cloud SQL backup should be enabled | High | sql | 1 |
| GCP Cloud SQL connections requires to use SSL | High | sql | 1 |
| GCP Cloud SQL should be encrypted | High | sql | 1 |
| GCP Cloud SQL should be protected from direct internet traffic | High | sql | 1 |
| GCP Cloud storage bucket should be protected from direct internet traffic | High | storage | 1 |
| GCP Compute instance should be protected from direct internet traffic | High | compute | 1 |
| GCP KMS encryption keys should be protected from direct internet traffic | High | kms | 1 |
| GCP Kubernetes clusters have logging and cloud monitoring enabled | High | gke | 1 |
| GCP service account should not have admin privilege access | High | iam | 1 |
| GCP should be on https | High | network | 1 |
| GCP should redirect http to https | High | network | 1 |
| Google Security Center should be enabled | High | logging | 1 |
| Reported incident should be closed | Medium | security | 2 |
| AWS account password policy should be configured | Medium | iam | 1 |
| AWS API gateway V2 errors should be monitored | Medium | apigateway | 1 |
| AWS classic load balancer errors should be monitored | Medium | loadbalancer | 1 |
| AWS classic load balancer latency should be monitored | Medium | loadbalancer | 1 |
| AWS Cloud Trail S3 logging bucket access logging should be enabled | Medium | logging | 1 |
| AWS credentials not used in last 90 days should be disabled | Medium | iam | 1 |
| AWS DynamoDB latency should be monitored | Medium | dynamodb | 1 |
| AWS DynamoDB read capacity should be monitored | Medium | dynamodb | 1 |
| AWS DynamoDB write capacity should be monitored | Medium | dynamodb | 1 |
| AWS EBS health should be monitored | Medium | ebs | 1 |
| AWS EC2 instance CPU utilization should be monitored | Medium | ec2 | 1 |
| AWS ECS CPU utilization should be monitored | Medium | ecs | 1 |
| AWS ECS memory utilization should be monitored | Medium | ecs | 1 |
| AWS ElastiCache current connections should be monitored | Medium | elasticache | 1 |
| AWS ElastiCache datastore CPU utilization should be monitored | Medium | elasticache | 1 |
| AWS ElastiCache freeable memory should be monitored | Medium | elasticache | 1 |
| AWS Elasticsearch cluster CPU utilization should be monitored | Medium | elasticsearch | 1 |
| AWS Elasticsearch cluster freespace should be monitored | Medium | elasticsearch | 1 |
| AWS Elasticsearch cluster health should be monitored | Medium | elasticsearch | 1 |
| AWS Firehose stream throttling should be monitored | Medium | firehose | 1 |
| AWS FSX File System freespace should be monitored | Medium | fsx | 1 |
| AWS Lightsail instance CPU utilization should be monitored | Medium | lightsail | 1 |
| AWS load balancer errors should be monitored | Medium | loadbalancer | 1 |
| AWS load balancer healthy host count should be monitored | Medium | loadbalancer | 1 |
| AWS load balancer host health should be monitored | Medium | loadbalancer | 1 |
| AWS load balancer latency should be monitored | Medium | loadbalancer | 1 |
| AWS load balancer should have valid configuration | Medium | loadbalancer | 1 |
| AWS RDS database CPU utilization should be monitored | Medium | rds | 1 |
| AWS RDS Database freeable memory should be monitored | Medium | rds | 1 |
| AWS RDS database freespace should be monitored | Medium | rds | 1 |
| AWS RDS database IO utilization should be monitored | Medium | rds | 1 |
| AWS Redshift CPU utilization should be monitored | Medium | redshift | 1 |
| AWS Redshift health should be monitored | Medium | redshift | 1 |
| AWS S3 bucket should be versioned | Medium | s3 | 1 |
| AWS S3 server access logging should be enabled for important buckets | Medium | s3 | 1 |
| AWS server access logs should be retained for 90 days | Medium | logging | 1 |
| AWS SQS messages age should be monitored | Medium | sqs | 1 |
| AWS SQS messages visibility should be monitored | Medium | sqs | 1 |
| AWS users should not have attached IAM policies | Medium | iam | 1 |
| Azure AKS node CPU utilization should be monitored | Medium | kubernetes | 1 |
| Azure AKS node memory working set usage should be monitored | Medium | kubernetes | 1 |
| Azure Application Gateway healthy host count should be monitored | Medium | network | 1 |
| Azure Cache for Redis client connections should be monitored | Medium | cache | 1 |
| Azure Cache for Redis CPU utilization should be monitored | Medium | cache | 1 |
| Azure Cache for Redis freeable memory should be monitored | Medium | cache | 1 |
| Azure CosmosDB latency should be monitored | Medium | database | 1 |
| Azure Databricks CPU utilization should be monitored | Medium | data | 1 |
| Azure Databricks health should be monitored | Medium | data | 1 |
| Azure Disk backup should be enabled | Medium | compute | 1 |
| Azure flow logs should be captured | Medium | network | 1 |
| Azure Front Door Origin health should be monitored | Medium | network | 1 |
| Azure Load Balancer health probe status should be monitored | Medium | network | 1 |
| Azure Non RBAC Key Vault should have expiration set for all keys | Medium | security | 1 |
| Azure postgreSQL Database Server Infrastructure double encryption should be enabled | Medium | database | 1 |
| Azure RBAC Key Vault should have expiration set for all keys | Medium | security | 1 |
| Azure SQL database CPU utilization should be monitored | Medium | database | 1 |
| Azure SQL database IO utilization should be monitored | Medium | database | 1 |
| Azure SQL database memory utilization monitored | Medium | database | 1 |
| Azure storage account cross tenant replication should not be enabled | Medium | storage | 1 |
| Azure virtual network flow logs should be captured | Medium | network | 1 |
| Azure VM CPU utilization should be monitored | Medium | compute | 1 |
| Device encryption should be enabled | Medium | devices | 1 |
| DigitalOcean infrastructure should be properly configured | Medium | security | 1 |
| GCP Cloud SQL CPU utilization should be monitored | Medium | sql | 1 |
| GCP Cloud SQL memory utilization should be monitored | Medium | sql | 1 |
| GCP Cloud Storage should be uniform bucket level access enabled | Medium | storage | 1 |
| GCP Compute instance CPU utilization should be monitored | Medium | compute | 1 |
| GCP essential contacts should be setup | Medium | logging | 1 |
| GCP KMS encryption keys should be rotated within 90 days | Medium | kms | 1 |
| GCP Service account keys should only be GCP-Managed | Medium | iam | 1 |
| GCP service account user role/ token creator role should not be assigned at project level | Medium | iam | 1 |
| GCP Service account User-Managed/External keys are rotated every 90 days or fewer | Medium | iam | 1 |
| GCP Sink should be configured for all log entries | Medium | logging | 1 |
| GCP VPC Subnet flow logs should be captured | Medium | network | 1 |
| GKE Kubernetes Web UI (Dashboard) is disabled | Medium | gke | 1 |
| GKE Metadata Server is enabled | Medium | gke | 1 |
| Google Security Center vulnerability alert should be resolved within SLA | Medium | logging | 1 |
| Human access should use federated SSO | Medium | iam | 1 |
| Inactive user accounts should be disabled | Medium | iam | 1 |
| OS should be up to date | Medium | devices | 1 |
| Reported incident should be closed in Guard duty | Medium | security | 1 |
| Reported incident should be closed in Microsoft defender | Medium | security | 1 |
| Reported incident should be closed in security center | Medium | logging | 1 |
| Screen lock should be enabled on devices | Medium | devices | 1 |
| Service account keys should be rotated within 90 days | Medium | iam | 1 |
| User should be identified | Medium | iam | 1 |
| AWS groups should have at least one IAM policy | Low | iam | 1 |
| GCP Bigtable CPU utilization should be monitored | Low | bigtable | 1 |
| GCP Bigtable storage utilization should be monitored | Low | bigtable | 1 |
| GCP Firestore read frequency should be monitored | Low | firestore | 1 |
| GCP Firestore write frequency should be monitored | Low | firestore | 1 |
| Reported incident should be closed in DSALTA | Low | governance | 1 |
| Service accounts should be inventoried and owned | Low | iam | 1 |
| User access to Critical System should be valid | Info | access | 68 |
| All change tickets should have an assignee | Info | change-management | 4 |
| At least one change management system should be connected | Info | change-management | 4 |
| Change request ticket should be resolved within 30 days | Info | change-management | 4 |
| Ticketing system for change management should be setup | Info | change-management | 4 |
| Branch Protection rules should be enforced for admins | Info | governance | 2 |
| Branch protection should be enabled on repositories | Info | governance | 2 |
| Code changes should be reviewed by peers before merging | Info | governance | 2 |
| Code repo should be classified | Info | governance | 2 |
| Merging of code changes should require passing status-checks | Info | governance | 2 |
| Password policy should meet minimum requirements | Info | iam | 2 |
| Peer review should be enforced for code changes | Info | governance | 2 |
| Admin accounts should have MFA enabled | Info | iam | 1 |
| At least one identity source should be connected | Info | iam | 1 |
| Branch protection should be enabled | Info | governance | 1 |
| Code scanning alerts should be resolved | Info | security | 1 |
| Dependabot alerts should be resolved | Info | vulnerability | 1 |
| Dependabot alerts should be resolved within SLA | Info | vulnerability | 1 |
| GitLab group level MFA should be enforced | Info | access | 1 |
| HTTPS should be enabled | Info | network | 1 |
| MFA (two-factor authentication) should be enabled for all members | Info | iam | 1 |
| Secret scanning alerts should be resolved | Info | security | 1 |
| Vendor discovery should be configured | Info | governance | 1 |
| Offboarded users should not have active access | Varies | access | 65 |
| MFA should be enabled for all users | Varies | access / iam | 9 |
| Infra entity should be classified | Varies | inventory / governance | 3 |