> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance tests

> Every automated check DSALTA runs, what it looks at, and how to fix a failure.

DSALTA ships **197 distinct automated checks**, applied across integrations as **358 test definitions** — a check that runs on 65 integrations is one check counted once here and 65 definitions in the product.

Checks run once a day at 02:00 America/New\_York. A run that finishes shows **Completed** in the Tests list whatever it found; the compliance outcome is the result code on the test's **Source Data** tab. See [Understanding test results](/guides/data-library/test-results).

## By severity

| Severity | Distinct checks |
| -------- | --------------- |
| Critical | 5               |
| High     | 72              |
| Medium   | 87              |
| Low      | 7               |
| Info     | 23              |
| Varies   | 3               |

## All checks

| Check                                                                                                                                              | Severity | Category                 | Integrations |
| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------ |
| [AWS RDS database should be protected from direct internet traffic](/integrations/aws/aws-rds-no-public-access)                                    | Critical | `rds`                    | 1            |
| [AWS root account should have MFA enabled](/integrations/aws/aws-root-account-should-have-mfa-enabled)                                             | Critical | `iam`                    | 1            |
| [AWS S3 bucket public access should be blocked](/integrations/aws/aws-s3-bucket-public-access-should-be-blocked)                                   | Critical | `s3`                     | 1            |
| [AWS user should have MFA enabled](/integrations/aws/aws-users-should-have-mfa-enabled)                                                            | Critical | `iam`                    | 1            |
| [GCP user should have MFA enabled](/integrations/gcp/gcp-users-should-have-mfa-enabled)                                                            | Critical | `iam`                    | 1            |
| [AWS access should be removed for offboarded user](/integrations/aws/aws-access-should-be-removed-for-offboarded-users)                            | High     | `iam`                    | 1            |
| [AWS application load balancer should be protected from direct internet traffic](/integrations/aws/aws-alb-no-public-access)                       | High     | `loadbalancer`           | 1            |
| [AWS Cloud Trail logging bucket should be protected from direct internet traffic](/integrations/aws/aws-cloudtrail-bucket-no-public)               | High     | `s3`                     | 1            |
| [AWS CloudTrail log file integrity validation should be enabled](/integrations/aws/aws-cloudtrail-log-integrity)                                   | High     | `logging`                | 1            |
| [AWS CloudTrail should be enabled](/integrations/aws/aws-cloudtrail-should-be-enabled)                                                             | High     | `logging`                | 1            |
| [AWS DynamoDB backup should be enabled](/integrations/aws/aws-dynamodb-backup-should-be-enabled)                                                   | High     | `dynamodb`               | 1            |
| [AWS DynamoDB point in time recovery should be enabled](/integrations/aws/aws-dynamodb-point-in-time-recovery-should-be-enabled)                   | High     | `dynamodb`               | 1            |
| [AWS DynamoDB should be encrypted](/integrations/aws/aws-dynamodb-should-be-encrypted)                                                             | High     | `dynamodb`               | 1            |
| [AWS EBS volume backup should be enabled](/integrations/aws/aws-ebs-volume-backup-should-be-enabled)                                               | High     | `ebs`                    | 1            |
| [AWS EBS volume should be encrypted](/integrations/aws/aws-ebs-volumes-should-be-encrypted)                                                        | High     | `ebs`                    | 1            |
| [AWS EC2 instance should be protected from direct internet traffic](/integrations/aws/aws-ec2-no-public-access)                                    | High     | `ec2`                    | 1            |
| [AWS ECR repository should be encrypted](/integrations/aws/aws-ecr-repositories-should-be-encrypted)                                               | High     | `ecr`                    | 1            |
| [AWS EFS storage backup should be enabled](/integrations/aws/aws-efs-storage-backup-should-be-enabled)                                             | High     | `efs`                    | 1            |
| [AWS EFS storage should be encrypted](/integrations/aws/aws-efs-storage-should-be-encrypted)                                                       | High     | `efs`                    | 1            |
| [AWS FSX File System storage backup should be enabled](/integrations/aws/aws-fsx-file-system-storage-backup-should-be-enabled)                     | High     | `fsx`                    | 1            |
| [AWS FSX File System storage should be encrypted](/integrations/aws/aws-fsx-file-system-storage-should-be-encrypted)                               | High     | `fsx`                    | 1            |
| [AWS GuardDuty should be enabled](/integrations/aws/aws-guardduty-should-be-enabled)                                                               | High     | `security`               | 1            |
| [AWS Lightsail disk backup should be enabled](/integrations/aws/aws-lightsail-disk-backup-should-be-enabled)                                       | High     | `lightsail`              | 1            |
| [AWS Lightsail disk should be encrypted](/integrations/aws/aws-lightsail-disks-should-be-encrypted)                                                | High     | `lightsail`              | 1            |
| [AWS load balancer should redirect traffic from http to https](/integrations/aws/aws-load-balancer-should-redirect-http-to-https)                  | High     | `loadbalancer`           | 1            |
| [AWS RDS database backup should be enabled](/integrations/aws/aws-rds-database-backup-should-be-enabled)                                           | High     | `rds`                    | 1            |
| [AWS RDS database storage should be encrypted](/integrations/aws/aws-rds-database-storage-should-be-encrypted)                                     | High     | `rds`                    | 1            |
| [AWS Redshift cluster backup should be enabled](/integrations/aws/aws-redshift-cluster-backup-should-be-enabled)                                   | High     | `redshift`               | 1            |
| [AWS Redshift cluster should be encrypted](/integrations/aws/aws-redshift-cluster-should-be-encrypted)                                             | High     | `redshift`               | 1            |
| [AWS root account usage should be avoided](/integrations/aws/aws-root-account-usage-should-be-avoided)                                             | High     | `iam`                    | 1            |
| [AWS S3 storage bucket should be encrypted](/integrations/aws/aws-s3-storage-buckets-should-be-encrypted)                                          | High     | `s3`                     | 1            |
| [AWS should be on https](/integrations/aws/aws-should-be-on-https)                                                                                 | High     | `network`                | 1            |
| [AWS should redirect http to https](/integrations/aws/aws-should-redirect-http-to-https)                                                           | High     | `network`                | 1            |
| [AWS user access keys should not be older than 90 days](/integrations/aws/aws-user-access-keys-should-not-be-older-than-90-days)                   | High     | `iam`                    | 1            |
| [AWS VPC flowlogs should be captured](/integrations/aws/aws-vpc-flow-logs-should-be-captured)                                                      | High     | `vpc`                    | 1            |
| [Azure access should be removed for offboarded user](/integrations/azure/azure-access-should-be-removed-for-offboarded-users)                      | High     | `iam`                    | 1            |
| [Azure activity logs should be archived](/integrations/azure/azure-activity-logs-should-be-archived)                                               | High     | `logging`                | 1            |
| [Azure CosmosDB backup should be enabled](/integrations/azure/azure-cosmos-db-backup-should-be-enabled)                                            | High     | `database`               | 1            |
| [Azure CosmosDB database should be protected from direct internet traffic](/integrations/azure/azure-cosmos-db-no-public-access)                   | High     | `database`               | 1            |
| [Azure CosmosDB should be encrypted](/integrations/azure/azure-cosmos-db-should-be-encrypted)                                                      | High     | `database`               | 1            |
| [Azure Databricks workspace backup should be enabled](/integrations/azure/azure-databricks-workspace-backup-should-be-enabled)                     | High     | `data`                   | 1            |
| [Azure Databricks workspace should be encrypted](/integrations/azure/azure-databricks-workspaces-should-be-encrypted)                              | High     | `data`                   | 1            |
| [Azure Defender should be enabled](/integrations/azure/azure-defender-should-be-enabled)                                                           | High     | `security`               | 1            |
| [Azure Disk should be encrypted](/integrations/azure/azure-disks-should-be-encrypted)                                                              | High     | `compute`                | 1            |
| [Azure Key Vault should be recoverable](/integrations/azure/azure-key-vault-should-be-recoverable)                                                 | High     | `security`               | 1            |
| [Azure postgreSQL Database Server enforce SSL connection should be enabled](/integrations/azure/azure-postgresql-should-enforce-ssl-connections)   | High     | `database`               | 1            |
| [Azure should be on https](/integrations/azure/azure-should-be-on-https)                                                                           | High     | `network`                | 1            |
| [Azure should redirect http to https](/integrations/azure/azure-should-redirect-http-to-https)                                                     | High     | `network`                | 1            |
| [Azure SQL database backup should be enabled](/integrations/azure/azure-sql-database-backup-should-be-enabled)                                     | High     | `database`               | 1            |
| [Azure SQL database should be encrypted](/integrations/azure/azure-sql-databases-should-be-encrypted)                                              | High     | `database`               | 1            |
| [Azure SQL database should be protected from direct internet traffic](/integrations/azure/azure-sql-no-public-access)                              | High     | `database`               | 1            |
| [Azure storage account allow blob anonymous access should be disabled](/integrations/azure/azure-storage-no-anon-blob)                             | High     | `storage`                | 1            |
| [Azure storage account default network access rule should set to deny](/integrations/azure/azure-storage-default-deny)                             | High     | `storage`                | 1            |
| [Azure storage account Minimum TLS version should be version 1.2](/integrations/azure/azure-storage-account-minimum-tls-version-should-be-12)      | High     | `storage`                | 1            |
| [Azure storage account public network access should be disabled](/integrations/azure/azure-storage-no-public-network)                              | High     | `storage`                | 1            |
| [Azure storage account secure transfer required should be enabled](/integrations/azure/azure-storage-account-secure-transfer-should-be-enabled)    | High     | `storage`                | 1            |
| [Azure storage account should be encrypted](/integrations/azure/azure-storage-accounts-should-be-encrypted)                                        | High     | `storage`                | 1            |
| [Azure VM should be protected from direct internet traffic](/integrations/azure/azure-vms-should-be-protected-from-direct-internet-traffic)        | High     | `compute`                | 1            |
| [Azure Web App is using the latest version of TLS encryption](/integrations/azure/azure-web-app-should-use-the-latest-tls-version)                 | High     | `webapp`                 | 1            |
| [Azure Web App Redirects All HTTP traffic to HTTPS in Azure App Service](/integrations/azure/azure-web-app-should-redirect-http-to-https)          | High     | `webapp`                 | 1            |
| [GCP BigQuery storage should be encrypted](/integrations/gcp/gcp-bigquery-storage-should-be-encrypted)                                             | High     | `bigquery`               | 1            |
| [GCP Bigtable should be encrypted](/integrations/gcp/gcp-bigtable-should-be-encrypted)                                                             | High     | `bigtable`               | 1            |
| [GCP Biqquery dataset should be protected from direct internet traffic](/integrations/gcp/gcp-bigquery-no-public-access)                           | High     | `bigquery`               | 1            |
| [GCP bucket storage should be encrypted](/integrations/gcp/gcp-bucket-storage-should-be-encrypted)                                                 | High     | `storage`                | 1            |
| [GCP Cloud Spanner should be encrypted](/integrations/gcp/gcp-cloud-spanner-should-be-encrypted)                                                   | High     | `spanner`                | 1            |
| [GCP Cloud SQL backup should be enabled](/integrations/gcp/gcp-cloud-sql-backup-should-be-enabled)                                                 | High     | `sql`                    | 1            |
| [GCP Cloud SQL connections requires to use SSL](/integrations/gcp/gcp-cloud-sql-connections-should-require-ssl)                                    | High     | `sql`                    | 1            |
| [GCP Cloud SQL should be encrypted](/integrations/gcp/gcp-cloud-sql-should-be-encrypted)                                                           | High     | `sql`                    | 1            |
| [GCP Cloud SQL should be protected from direct internet traffic](/integrations/gcp/gcp-cloud-sql-no-public-access)                                 | High     | `sql`                    | 1            |
| [GCP Cloud storage bucket should be protected from direct internet traffic](/integrations/gcp/gcp-storage-buckets-no-public-access)                | High     | `storage`                | 1            |
| [GCP Compute instance should be protected from direct internet traffic](/integrations/gcp/gcp-compute-no-public-access)                            | High     | `compute`                | 1            |
| [GCP KMS encryption keys should be protected from direct internet traffic](/integrations/gcp/gcp-kms-no-public-access)                             | High     | `kms`                    | 1            |
| [GCP Kubernetes clusters have logging and cloud monitoring enabled](/integrations/gcp/gcp-gke-logging-monitoring)                                  | High     | `gke`                    | 1            |
| [GCP service account should not have admin privilege access](/integrations/gcp/gcp-service-accounts-should-not-have-admin-privileges)              | High     | `iam`                    | 1            |
| [GCP should be on https](/integrations/gcp/gcp-should-be-on-https)                                                                                 | High     | `network`                | 1            |
| [GCP should redirect http to https](/integrations/gcp/gcp-should-redirect-http-to-https)                                                           | High     | `network`                | 1            |
| [Google Security Center should be enabled](/integrations/gcp/google-security-command-center-should-be-enabled)                                     | High     | `logging`                | 1            |
| [Reported incident should be closed](/tests/reported-incidents-should-be-closed)                                                                   | Medium   | `security`               | 2            |
| [AWS account password policy should be configured](/integrations/aws/aws-account-password-policy-should-be-configured)                             | Medium   | `iam`                    | 1            |
| [AWS API gateway V2 errors should be monitored](/integrations/aws/aws-api-gateway-v2-errors-should-be-monitored)                                   | Medium   | `apigateway`             | 1            |
| [AWS classic load balancer errors should be monitored](/integrations/aws/aws-classic-load-balancer-errors-should-be-monitored)                     | Medium   | `loadbalancer`           | 1            |
| [AWS classic load balancer latency should be monitored](/integrations/aws/aws-classic-load-balancer-latency-should-be-monitored)                   | Medium   | `loadbalancer`           | 1            |
| [AWS Cloud Trail S3 logging bucket access logging should be enabled](/integrations/aws/aws-cloudtrail-s3-access-logging)                           | Medium   | `logging`                | 1            |
| [AWS credentials not used in last 90 days should be disabled](/integrations/aws/aws-credentials-not-used-in-last-90-days-should-be-disabled)       | Medium   | `iam`                    | 1            |
| [AWS DynamoDB latency should be monitored](/integrations/aws/aws-dynamodb-latency-should-be-monitored)                                             | Medium   | `dynamodb`               | 1            |
| [AWS DynamoDB read capacity should be monitored](/integrations/aws/aws-dynamodb-read-capacity-should-be-monitored)                                 | Medium   | `dynamodb`               | 1            |
| [AWS DynamoDB write capacity should be monitored](/integrations/aws/aws-dynamodb-write-capacity-should-be-monitored)                               | Medium   | `dynamodb`               | 1            |
| [AWS EBS health should be monitored](/integrations/aws/aws-ebs-health-should-be-monitored)                                                         | Medium   | `ebs`                    | 1            |
| [AWS EC2 instance CPU utilization should be monitored](/integrations/aws/aws-ec2-instance-cpu-utilization-should-be-monitored)                     | Medium   | `ec2`                    | 1            |
| [AWS ECS CPU utilization should be monitored](/integrations/aws/aws-ecs-cpu-utilization-should-be-monitored)                                       | Medium   | `ecs`                    | 1            |
| [AWS ECS memory utilization should be monitored](/integrations/aws/aws-ecs-memory-utilization-should-be-monitored)                                 | Medium   | `ecs`                    | 1            |
| [AWS ElastiCache current connections should be monitored](/integrations/aws/aws-elasticache-current-connections-should-be-monitored)               | Medium   | `elasticache`            | 1            |
| [AWS ElastiCache datastore CPU utilization should be monitored](/integrations/aws/aws-elasticache-cpu-utilization-should-be-monitored)             | Medium   | `elasticache`            | 1            |
| [AWS ElastiCache freeable memory should be monitored](/integrations/aws/aws-elasticache-freeable-memory-should-be-monitored)                       | Medium   | `elasticache`            | 1            |
| [AWS Elasticsearch cluster CPU utilization should be monitored](/integrations/aws/aws-elasticsearch-cpu-monitoring)                                | Medium   | `elasticsearch`          | 1            |
| [AWS Elasticsearch cluster freespace should be monitored](/integrations/aws/aws-elasticsearch-cluster-free-space-should-be-monitored)              | Medium   | `elasticsearch`          | 1            |
| [AWS Elasticsearch cluster health should be monitored](/integrations/aws/aws-elasticsearch-cluster-health-should-be-monitored)                     | Medium   | `elasticsearch`          | 1            |
| [AWS Firehose stream throttling should be monitored](/integrations/aws/aws-firehose-stream-throttling-should-be-monitored)                         | Medium   | `firehose`               | 1            |
| [AWS FSX File System freespace should be monitored](/integrations/aws/aws-fsx-file-system-free-space-should-be-monitored)                          | Medium   | `fsx`                    | 1            |
| [AWS Lightsail instance CPU utilization should be monitored](/integrations/aws/aws-lightsail-instance-cpu-utilization-should-be-monitored)         | Medium   | `lightsail`              | 1            |
| [AWS load balancer errors should be monitored](/integrations/aws/aws-load-balancer-errors-should-be-monitored)                                     | Medium   | `loadbalancer`           | 1            |
| [AWS load balancer healthy host count should be monitored](/integrations/aws/aws-load-balancer-healthy-host-count-should-be-monitored)             | Medium   | `loadbalancer`           | 1            |
| [AWS load balancer host health should be monitored](/integrations/aws/aws-load-balancer-host-health-should-be-monitored)                           | Medium   | `loadbalancer`           | 1            |
| [AWS load balancer latency should be monitored](/integrations/aws/aws-load-balancer-latency-should-be-monitored)                                   | Medium   | `loadbalancer`           | 1            |
| [AWS load balancer should have valid configuration](/integrations/aws/aws-load-balancer-should-have-valid-configuration)                           | Medium   | `loadbalancer`           | 1            |
| [AWS RDS database CPU utilization should be monitored](/integrations/aws/aws-rds-database-cpu-utilization-should-be-monitored)                     | Medium   | `rds`                    | 1            |
| [AWS RDS Database freeable memory should be monitored](/integrations/aws/aws-rds-database-freeable-memory-should-be-monitored)                     | Medium   | `rds`                    | 1            |
| [AWS RDS database freespace should be monitored](/integrations/aws/aws-rds-database-free-space-should-be-monitored)                                | Medium   | `rds`                    | 1            |
| [AWS RDS database IO utilization should be monitored](/integrations/aws/aws-rds-database-io-utilization-should-be-monitored)                       | Medium   | `rds`                    | 1            |
| [AWS Redshift CPU utilization should be monitored](/integrations/aws/aws-redshift-cpu-utilization-should-be-monitored)                             | Medium   | `redshift`               | 1            |
| [AWS Redshift health should be monitored](/integrations/aws/aws-redshift-health-should-be-monitored)                                               | Medium   | `redshift`               | 1            |
| [AWS S3 bucket should be versioned](/integrations/aws/aws-s3-buckets-should-be-versioned)                                                          | Medium   | `s3`                     | 1            |
| [AWS S3 server access logging should be enabled for important buckets](/integrations/aws/aws-s3-server-access-logging-should-be-enabled)           | Medium   | `s3`                     | 1            |
| [AWS server access logs should be retained for 90 days](/integrations/aws/aws-server-access-logs-should-be-retained-for-90-days)                   | Medium   | `logging`                | 1            |
| [AWS SQS messages age should be monitored](/integrations/aws/aws-sqs-message-age-should-be-monitored)                                              | Medium   | `sqs`                    | 1            |
| [AWS SQS messages visibility should be monitored](/integrations/aws/aws-sqs-message-visibility-should-be-monitored)                                | Medium   | `sqs`                    | 1            |
| [AWS users should not have attached IAM policies](/integrations/aws/aws-users-should-not-have-attached-iam-policies)                               | Medium   | `iam`                    | 1            |
| [Azure AKS node CPU utilization should be monitored](/integrations/azure/azure-aks-node-cpu-utilization-should-be-monitored)                       | Medium   | `kubernetes`             | 1            |
| [Azure AKS node memory working set usage should be monitored](/integrations/azure/azure-aks-node-memory-working-set-usage-should-be-monitored)     | Medium   | `kubernetes`             | 1            |
| [Azure Application Gateway healthy host count should be monitored](/integrations/azure/azure-appgw-healthy-host-monitoring)                        | Medium   | `network`                | 1            |
| [Azure Cache for Redis client connections should be monitored](/integrations/azure/azure-cache-for-redis-client-connections-should-be-monitored)   | Medium   | `cache`                  | 1            |
| [Azure Cache for Redis CPU utilization should be monitored](/integrations/azure/azure-cache-for-redis-cpu-utilization-should-be-monitored)         | Medium   | `cache`                  | 1            |
| [Azure Cache for Redis freeable memory should be monitored](/integrations/azure/azure-cache-for-redis-freeable-memory-should-be-monitored)         | Medium   | `cache`                  | 1            |
| [Azure CosmosDB latency should be monitored](/integrations/azure/azure-cosmos-db-latency-should-be-monitored)                                      | Medium   | `database`               | 1            |
| [Azure Databricks CPU utilization should be monitored](/integrations/azure/azure-databricks-cpu-utilization-should-be-monitored)                   | Medium   | `data`                   | 1            |
| [Azure Databricks health should be monitored](/integrations/azure/azure-databricks-health-should-be-monitored)                                     | Medium   | `data`                   | 1            |
| [Azure Disk backup should be enabled](/integrations/azure/azure-disk-backup-should-be-enabled)                                                     | Medium   | `compute`                | 1            |
| [Azure flow logs should be captured](/integrations/azure/azure-flow-logs-should-be-captured)                                                       | Medium   | `network`                | 1            |
| [Azure Front Door Origin health should be monitored](/integrations/azure/azure-front-door-origin-health-should-be-monitored)                       | Medium   | `network`                | 1            |
| [Azure Load Balancer health probe status should be monitored](/integrations/azure/azure-load-balancer-health-probe-status-should-be-monitored)     | Medium   | `network`                | 1            |
| [Azure Non RBAC Key Vault should have expiration set for all keys](/integrations/azure/azure-non-rbac-key-vault-keys-should-have-expiration-dates) | Medium   | `security`               | 1            |
| [Azure postgreSQL Database Server Infrastructure double encryption should be enabled](/integrations/azure/azure-pg-double-encryption)              | Medium   | `database`               | 1            |
| [Azure RBAC Key Vault should have expiration set for all keys](/integrations/azure/azure-rbac-key-vault-keys-should-have-expiration-dates)         | Medium   | `security`               | 1            |
| [Azure SQL database CPU utilization should be monitored](/integrations/azure/azure-sql-database-cpu-utilization-should-be-monitored)               | Medium   | `database`               | 1            |
| [Azure SQL database IO utilization should be monitored](/integrations/azure/azure-sql-database-io-utilization-should-be-monitored)                 | Medium   | `database`               | 1            |
| [Azure SQL database memory utilization monitored](/integrations/azure/azure-sql-database-memory-utilization-should-be-monitored)                   | Medium   | `database`               | 1            |
| [Azure storage account cross tenant replication should not be enabled](/integrations/azure/azure-storage-no-cross-tenant)                          | Medium   | `storage`                | 1            |
| [Azure virtual network flow logs should be captured](/integrations/azure/azure-virtual-network-flow-logs-should-be-captured)                       | Medium   | `network`                | 1            |
| [Azure VM CPU utilization should be monitored](/integrations/azure/azure-vm-cpu-utilization-should-be-monitored)                                   | Medium   | `compute`                | 1            |
| [Device encryption should be enabled](/integrations/microsoft-defender/device-encryption-should-be-enabled)                                        | Medium   | `devices`                | 1            |
| [DigitalOcean infrastructure should be properly configured](/integrations/digitalocean/digitalocean-infrastructure-should-be-properly-configured)  | Medium   | `security`               | 1            |
| [GCP Cloud SQL CPU utilization should be monitored](/integrations/gcp/gcp-cloud-sql-cpu-utilization-should-be-monitored)                           | Medium   | `sql`                    | 1            |
| [GCP Cloud SQL memory utilization should be monitored](/integrations/gcp/gcp-cloud-sql-memory-utilization-should-be-monitored)                     | Medium   | `sql`                    | 1            |
| [GCP Cloud Storage should be uniform bucket level access enabled](/integrations/gcp/gcp-storage-uniform-bucket-access)                             | Medium   | `storage`                | 1            |
| [GCP Compute instance CPU utilization should be monitored](/integrations/gcp/gcp-compute-instance-cpu-utilization-should-be-monitored)             | Medium   | `compute`                | 1            |
| [GCP essential contacts should be setup](/integrations/gcp/gcp-essential-contacts-should-be-configured)                                            | Medium   | `logging`                | 1            |
| [GCP KMS encryption keys should be rotated within 90 days](/integrations/gcp/gcp-kms-encryption-keys-should-be-rotated-within-90-days)             | Medium   | `kms`                    | 1            |
| [GCP Service account keys should only be GCP-Managed](/integrations/gcp/gcp-service-account-keys-should-only-be-gcp-managed)                       | Medium   | `iam`                    | 1            |
| [GCP service account user role/ token creator role should not be assigned at project level](/integrations/gcp/gcp-sa-no-project-level-role)        | Medium   | `iam`                    | 1            |
| [GCP Service account User-Managed/External keys are rotated every 90 days or fewer](/integrations/gcp/gcp-sa-key-rotation-90-days)                 | Medium   | `iam`                    | 1            |
| [GCP Sink should be configured for all log entries](/integrations/gcp/gcp-log-sink-should-be-configured-for-all-log-entries)                       | Medium   | `logging`                | 1            |
| [GCP VPC Subnet flow logs should be captured](/integrations/gcp/gcp-vpc-subnet-flow-logs-should-be-captured)                                       | Medium   | `network`                | 1            |
| [GKE Kubernetes Web UI (Dashboard) is disabled](/integrations/gcp/gke-kubernetes-web-ui-dashboard-should-be-disabled)                              | Medium   | `gke`                    | 1            |
| [GKE Metadata Server is enabled](/integrations/gcp/gke-metadata-server-should-be-enabled)                                                          | Medium   | `gke`                    | 1            |
| [Google Security Center vulnerability alert should be resolved within SLA](/integrations/gcp/gcp-scc-vuln-alerts-resolved-sla)                     | Medium   | `logging`                | 1            |
| [Human access should use federated SSO](/integrations/nebius/federated-sso-enforced)                                                               | Medium   | `iam`                    | 1            |
| [Inactive user accounts should be disabled](/integrations/nebius/inactive-accounts-disabled)                                                       | Medium   | `iam`                    | 1            |
| [OS should be up to date](/integrations/microsoft-defender/os-should-be-up-to-date)                                                                | Medium   | `devices`                | 1            |
| [Reported incident should be closed in Guard duty](/integrations/aws/reported-incidents-should-be-closed-in-guardduty)                             | Medium   | `security`               | 1            |
| [Reported incident should be closed in Microsoft defender](/integrations/azure/reported-incidents-should-be-closed-in-microsoft-defender)          | Medium   | `security`               | 1            |
| [Reported incident should be closed in security center](/integrations/gcp/gcp-incidents-closed-in-scc)                                             | Medium   | `logging`                | 1            |
| [Screen lock should be enabled on devices](/integrations/microsoft-defender/screen-lock-should-be-enabled-on-devices)                              | Medium   | `devices`                | 1            |
| [Service account keys should be rotated within 90 days](/integrations/nebius/service-account-keys-rotated)                                         | Medium   | `iam`                    | 1            |
| [User should be identified](/integrations/gcp/users-should-be-identified)                                                                          | Medium   | `iam`                    | 1            |
| [AWS groups should have at least one IAM policy](/integrations/aws/aws-groups-should-have-at-least-one-iam-policy)                                 | Low      | `iam`                    | 1            |
| [GCP Bigtable CPU utilization should be monitored](/integrations/gcp/gcp-bigtable-cpu-utilization-should-be-monitored)                             | Low      | `bigtable`               | 1            |
| [GCP Bigtable storage utilization should be monitored](/integrations/gcp/gcp-bigtable-storage-utilization-should-be-monitored)                     | Low      | `bigtable`               | 1            |
| [GCP Firestore read frequency should be monitored](/integrations/gcp/gcp-firestore-read-frequency-should-be-monitored)                             | Low      | `firestore`              | 1            |
| [GCP Firestore write frequency should be monitored](/integrations/gcp/gcp-firestore-write-frequency-should-be-monitored)                           | Low      | `firestore`              | 1            |
| [Reported incident should be closed in DSALTA](/integrations/gcp/reported-incidents-should-be-closed-in-dsalta)                                    | Low      | `governance`             | 1            |
| [Service accounts should be inventoried and owned](/integrations/nebius/service-accounts-inventoried)                                              | Low      | `iam`                    | 1            |
| [User access to Critical System should be valid](/tests/user-access-to-critical-system-should-be-valid)                                            | Info     | `access`                 | 68           |
| [All change tickets should have an assignee](/tests/all-change-tickets-should-have-an-assignee)                                                    | Info     | `change-management`      | 4            |
| [At least one change management system should be connected](/tests/at-least-one-change-management-system-should-be-connected)                      | Info     | `change-management`      | 4            |
| [Change request ticket should be resolved within 30 days](/tests/change-request-tickets-should-be-resolved-within-30-days)                         | Info     | `change-management`      | 4            |
| [Ticketing system for change management should be setup](/tests/ticketing-system-for-change-management-should-be-configured)                       | Info     | `change-management`      | 4            |
| [Branch Protection rules should be enforced for admins](/tests/branch-protection-rules-should-be-enforced-for-admins)                              | Info     | `governance`             | 2            |
| [Branch protection should be enabled on repositories](/tests/branch-protection-should-be-enabled-on-repositories)                                  | Info     | `governance`             | 2            |
| [Code changes should be reviewed by peers before merging](/tests/code-changes-should-be-reviewed-by-peers-before-merging)                          | Info     | `governance`             | 2            |
| [Code repo should be classified](/tests/code-repositories-should-be-classified)                                                                    | Info     | `governance`             | 2            |
| [Merging of code changes should require passing status-checks](/tests/merging-code-changes-should-require-passing-status-checks)                   | Info     | `governance`             | 2            |
| [Password policy should meet minimum requirements](/tests/password-policy-should-meet-minimum-requirements)                                        | Info     | `iam`                    | 2            |
| [Peer review should be enforced for code changes](/tests/peer-review-should-be-enforced-for-code-changes)                                          | Info     | `governance`             | 2            |
| [Admin accounts should have MFA enabled](/integrations/google-workspace/admin-accounts-should-have-mfa-enabled)                                    | Info     | `iam`                    | 1            |
| [At least one identity source should be connected](/integrations/nebius/identity-source-connected)                                                 | Info     | `iam`                    | 1            |
| [Branch protection should be enabled](/integrations/github/branch-protection-should-be-enabled)                                                    | Info     | `governance`             | 1            |
| [Code scanning alerts should be resolved](/integrations/github/code-scanning-alerts-should-be-resolved)                                            | Info     | `security`               | 1            |
| [Dependabot alerts should be resolved](/integrations/github/dependabot-alerts-should-be-resolved)                                                  | Info     | `vulnerability`          | 1            |
| [Dependabot alerts should be resolved within SLA](/integrations/github/dependabot-alerts-should-be-resolved-within-sla)                            | Info     | `vulnerability`          | 1            |
| [GitLab group level MFA should be enforced](/integrations/gitlab/gitlab-group-level-mfa-should-be-enforced)                                        | Info     | `access`                 | 1            |
| [HTTPS should be enabled](/integrations/cloudflare/https-should-be-enabled)                                                                        | Info     | `network`                | 1            |
| [MFA (two-factor authentication) should be enabled for all members](/integrations/heroku/mfa-should-be-enabled-for-all-members)                    | Info     | `iam`                    | 1            |
| [Secret scanning alerts should be resolved](/integrations/github/secret-scanning-alerts-should-be-resolved)                                        | Info     | `security`               | 1            |
| [Vendor discovery should be configured](/integrations/google-workspace/vendor-discovery-should-be-configured)                                      | Info     | `governance`             | 1            |
| [Offboarded users should not have active access](/tests/offboarded-users-should-not-have-active-access)                                            | Varies   | `access`                 | 65           |
| [MFA should be enabled for all users](/tests/mfa-should-be-enabled-for-all-users)                                                                  | Varies   | `access / iam`           | 9            |
| [Infra entity should be classified](/tests/infrastructure-entities-should-be-classified)                                                           | Varies   | `inventory / governance` | 3            |
