Infrastructure security
| Control | Status |
|---|---|
|
Unique production database authentication enforced The company requires authentication to production datastores to use authorized secure authentication mechanisms, such as unique SSH key. |
|
|
Unique account authentication enforced The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys. |
|
|
Production application access restricted System access restricted to authorized access only |
|
|
Production database access restricted The company restricts privileged access to databases to authorized users with a business need. |
|
|
Production network access restricted The company restricts privileged access to the production network to authorized users with a business need. |
|
|
Access revoked upon termination The company completes termination checklists to ensure that access is revoked for terminated employees within SLAs. |
|
|
Unique network system authentication enforced The company requires authentication to the "production network" to use unique usernames and passwords or authorized Secure Socket Shell (SSH) keys. |
|
|
Remote access MFA enforced The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method. |
|
|
Remote access encrypted enforced The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection. |
|
|
Log management utilized The company utilizes a log management tool to identify events that may have a potential impact on the company's ability to achieve its security objectives. |