Category: Uncategorized

  • Azure-Security

    Azure – Always use FTPS when using FTP App Service supports both FTP and FTPS for deploying your files. However, FTPS should be used instead of FTP, if at all possible. When one or both of these protocols are not in use, you should disable them.Steps to Implement (FTP)In the Azure portal, search for and… Read more

  • Platform Security Requirement-Cloud-AWS

    AWS – Allow SSH and or RDP port only to required IPs and VPN Network It is recommended to restrict access to the SSH and RDP ports to the required IP(s) and VPN network.  In addition, it is highly recommended that this access be limited to these ports as required and not include any other… Read more

  • PCI 4.0.1 Requirements

    PCI 4.0 Requirements — Effective APR 2025 TRACKER for NEW APR 2025   DOCUMENTS/EVIDENCE – Storage is kept to a minimum for SAD Stored Prior to Authorization    Any Sensitive Authentication Data (SAD) stored prior to authorization must be reviewed for retention criteria and purged at least quarterly.Documents/Evidence Required:    a) Provide the Pol/Proc that defines the… Read more

  • Databases on AWS Security requirmets-

    AWS – Enable automated backups – Sign in to the AWS Management Console and open the Amazon RDS console at https://console.aws.amazon.com/rds/.In the navigation pane, choose DB Instances, and then select the DB instance that you want to modify.Choose Instance Actions, and then choose Modify. The Modify DB Instance page appears.For Backup Retention Period, choose a… Read more

  • Cryptography Policy

    Key Wrapping Disallowed Cipher suites that are not in the Allowed and Divest list above are Disallowed. As a general guideline cipher suites that negotiate, contain or offer the following are disallowed: SSH Cryptographic Components: Allowed Encryption Algorithms (Ciphers) Key Establishment (KexAlgorithms) AES256-GCM ECDH-SHA2-NISTP521 (ECDH) AES128-GCM ECDH-SHA2-NISTP384 (ECDH)   ECDH-SHA2-NISTP256 (ECDH)   Curve25519-SHA256 (ECDHE)  … Read more

  • Web API Security requirements and Threat vectors

    Follow standard frameworks for authorization Leverage open standard frameworks such as OAuth for authorization that controls authorization to protected resources like applications or groups of files Implement API gateway , implement default deny Implement API gateways. This helps enforce policies which control security aspects such as the authentication, authorization or traffic management Validate all API… Read more

  • AWS Attack vectors

    AWS WAF Security requirmeents AWS – Ensure WebACL in the AWS WAF to determine access based on geo-location and whitelisted IPs You can use geo match conditions with other AWS WAF Classic conditions or rules to build sophisticated filtering. For example, if you want to block certain countries, but still allow specific IP addresses from… Read more

  • Threat Modelling- Pod Attack vectors

    Necessity of a rootless mode in Pod based deployment Normally pod based deployments follow a structure as mentioned above. Pods are hosted or deployed on the Node based EKS clusters. Applications that are deployed as part of containerized images are part of pods. Here, Application level vulnerabilities such as above vulnerabilities prominently are vulnerabilities that… Read more

  • Hello world!

    Welcome to WordPress. This is your first post. Edit or delete it, then start writing! Read more