| Two-factor sign-in | A.8.5 Secure authentication | an active user has not enrolled (pending invitations are counted apart) |
|---|
| Administrators | A.8.2 Privileged access rights | an administrator has not signed in for 90 days |
|---|
| API tokens | A.5.17 Authentication information | a token never expires or was not used for 90 days |
|---|
| Access review | A.5.18 Access rights | none was signed yet, the next one is due within 14 days, or it is overdue |
|---|
| Sign-in protection and sessions | A.8.5 Secure authentication | sessions stay open longer than 4 hours without activity, or more than 10 failed attempts are allowed |
|---|
| Bucket backups | A.8.13 Information backup | buckets exist without a backup target, the target is not ready, or a bucket had no good backup for 36 hours |
|---|
| Restore tests | A.8.13 Information backup | the latest test failed, or a backed-up bucket was not tested this month yet |
|---|
| Database backups | A.8.13 Information backup | information only – Scaleway backs up each instance on its own schedule |
|---|
| Audit log | A.8.15 Logging | it is kept fewer than 365 days |
|---|
| Security notifications | A.8.16 Monitoring activities | sign-in, backup and certificate events reach no channel |
|---|
| IP allowlist | A.8.20 Networks security | information only – whether the cockpit answers every address |
|---|
| Environment isolation | A.8.22 Segregation of networks | an environment where isolation is offered is not isolated |
|---|
| Certificates | A.8.24 Use of cryptography | a wildcard certificate expires within 14 days or is not ready |
|---|
| Cluster add-ons | A.8.8 Management of technical vulnerabilities | an upgrade is available or an add-on no longer fits its Kubernetes version |
|---|
| Configuration check | A.8.9 Configuration management | the last check found differences or is older than 7 days |
|---|