Reset

Showing 203 rule(s)

Rule ID Name Platform Category Severity
DOS3510 ADO DevSecOps Control - Ensure Secret Scanning (SS) AzureDevOps appsec Severitycritical
DOS3520 ADO DevSecOps Control - Ensure Software Composition Analysis (SCA) / Dependency Scanning AzureDevOps appsec Severitycritical
DOS3530 ADO DevSecOps Control - Ensure Static Application Security Testing (SAST) / Code Scanning AzureDevOps appsec Severitycritical
DOS3540 ADO DevSecOps Control - Ensure Container Image Scanning (CIS) / Container Scanning AzureDevOps appsec Severitycritical
DOS3550 ADO DevSecOps Control - Ensure Infrastructure as Code Scanning (IACS) AzureDevOps appsec Severitycritical
DOS3560 ADO DevSecOps Control - Ensure Infrastructure Scanning (IS) AzureDevOps appsec Severitycritical
DOS3570 ADO DevSecOps Control - Ensure Dynamic Application Security Testing (DAST) AzureDevOps appsec Severitycritical
DOS3580 ADO DevSecOps Control - Ensure Interactive Application Security Testing (IAST) AzureDevOps appsec Severityhigh
DOS4010 Ensure Repository Base permissions is set to 'No permission' GitHub organization Severitycritical
DOS4015 Disable Repository Forking GitHub organization Severitycritical
DOS4025 Disable Public Repository Creation - Disallow members to create public repositories GitHub organization Severitycritical
DOS4030 Restrict Repository Creation to Internal - Allow members to create internal repositories GitHub organization Severitycritical
DOS4035 Restrict Repository Creation to Private - Allow members to create private repositories GitHub organization Severitycritical
DOS4040 Restrict GitHub Pages Creation - Disallow members to publish sites GitHub organization Severityhigh
DOS4210 Require two-factor authentication in your organization GitHub organization Severitycritical
DOS4220 Organization Credential Authorizations - Should record the authorizing login GitHub organization Severityhigh
DOS4225 Organization Credential Authorizations - Should specify a credential type GitHub organization Severityhigh
DOS4230 Organization Credential Authorizations - Should have a descriptive title GitHub organization Severitymedium
DOS4240 Organization Member - Should have two-factor authentication enabled GitHub organization Severitycritical
DOS4245 Organization Member - Should have a login name GitHub organization Severitymedium