From 69d006c783adc798a829d8cd5b4a25f41d658d8a Mon Sep 17 00:00:00 2001 From: gearnode Date: Tue, 14 Jan 2025 20:11:13 +0100 Subject: [PATCH] Add network controls Signed-off-by: gearnode --- ...ct_public_access_on_your_infrastructure.md | 70 +++++++++++++++++++ .../network/COR.NET.002_penetration_test.md | 27 +++++++ .../COR.NET.002_web_application_firewall.md | 50 +++++++++++++ 3 files changed, 147 insertions(+) create mode 100644 controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md create mode 100644 controls/core/network/COR.NET.002_penetration_test.md create mode 100644 controls/core/network/COR.NET.002_web_application_firewall.md diff --git a/controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md b/controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md new file mode 100644 index 000000000..970eabe89 --- /dev/null +++ b/controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md @@ -0,0 +1,70 @@ +--- +id: "COR.NET.001" +category: "core/network" +revision-version: 1 +revision-date: "2024-01-12" +estimate-time: "30m" +necessity: "mandatory" +frameworks: + - name: "soc2" + sections: ["CC6.1", "CC6.6", "CC6.7"] +--- + +# Restrict public access on your infrastructure + +## Purpose + +Public access to your company's infrastructure is a serious security risk. By +configuring your cloud provider to restrict public access, you can reduce the +risk of unauthorized access to your sensitive data and systems. + +## Implementation + +- Ensure your cloud storage buckets are private (it should be the case by + default) + 1. **Go to the Google Cloud Console,** navigate to **Cloud Storage**. + 2. In **Permissions**, enable **Uniform Bucket-Level Access** to enforce + bucket-level permissions (and not individual object level). + 3. Remove any **AllUsers** or **allAuthenticatedUsers** roles, as these allow + public access. + 4. Assign only required roles (e.g., `Storage Admin` or + `Storage Object Viewer`) to specific users or groups. If you need a bucket + to have public access for its purpose (e.g. CDN buckets) : + 5. Document why this bucket needs to be public in the evidence section + 6. Disable **Uniform Bucket-Level Access** and proceed at the bucket level. + For each: + 1. Select your bucket + 2. Under **Bucket Permissions**, remove any **AllUsers** or + **allAuthenticatedUsers** roles +- Remove the default network The default network in GCP rely on a set of + rules/access that can’t be disabled and are “unsafe”. That is why it is better + to create your own network. + + + 1. Once the default network is no longer used, go to [VPC networks](https://console.cloud.google.com/networking/networks/list) on your Google Cloud Console + 2. Click the network named `default`. + 3. Click DELETE VPC NETWORK at the top of the page. +- Restrict public SSH access If you need to enable access to your system, + leverage **Google Cloud Identity-Aware Proxy (IAP)** as a secure alternative + to direct SSH. IAP will let you access your VMs via SSH without exposing them + publicly, it eliminates the need for public IPS or open SSH ports. + 1. In **GCP Console**, go to **Identity-Aware Proxy** and enable it for the + project. + 2. Grant the user or group with **IAP-secured Tunnel User** (network access) + and **Compute Instance Admin** (SSH permissions) roles. + 1. It works even for external users as long as they have a google account. + To access the VMs, user need to run a command locally via the **gcloud + CLI** to tunnel SSH traffic through IAP: + ```bash + gcloud compute ssh --tunnel-through-iap + ``` + +## Evidence + +- Screenshot showing your storage bucket configuration. +- Screenshot showing your networks. diff --git a/controls/core/network/COR.NET.002_penetration_test.md b/controls/core/network/COR.NET.002_penetration_test.md new file mode 100644 index 000000000..f5ff5b279 --- /dev/null +++ b/controls/core/network/COR.NET.002_penetration_test.md @@ -0,0 +1,27 @@ +--- +id: "COR.NET.003" +category: "core/network" +revision-version: 1 +revision-date: "2024-01-12" +estimate-time: "30m" +necessity: "optional" +frameworks: + - name: "soc2" + sections: ["CC3.2", "CC4.1", "CC8.1"] +--- + +# Run a penetration test + +## Purpose + +It is a good way to safeguard your company’s data. It is a real-life simulation +of attack scenarios on your company: it enables you to identify potential +vulnerabilities that can be fixed before being exploited. + +## Implementation + +Schedule a penetration test with a third party. + +## Evidence + +Your penetration test report. diff --git a/controls/core/network/COR.NET.002_web_application_firewall.md b/controls/core/network/COR.NET.002_web_application_firewall.md new file mode 100644 index 000000000..f7c750fc0 --- /dev/null +++ b/controls/core/network/COR.NET.002_web_application_firewall.md @@ -0,0 +1,50 @@ +--- +id: "COR.NET.002" +category: "core/network" +revision-version: 1 +revision-date: "2024-01-12" +estimate-time: "30m" +necessity: "optional" +frameworks: + - name: "soc2" + sections: ["CC6.1", "CC6.6"] +--- + +# Set-up a WAF + +## Purpose + +A web application protection service acts as a security shield that: + +Filters malicious traffic (SQL injections, XSS attacks) Masks your server's real +IP address Blocks DDoS attacks and malicious bots Controls request rates to +prevent abuse + +This ensures your applications stay secure and available while legitimate +traffic flows normally. + +## Implementation + +### Cloudflare + +1. **Sign up for Cloudflare**: Go to [Cloudflare](https://www.cloudflare.com/) + and create an account. +2. **Add your domain**: Enter your website’s domain and let Cloudflare scan + existing DNS records. +3. **Update your DNS**: Change your domain's nameservers to Cloudflare’s + nameservers as provided in your Cloudflare dashboard. +4. **Configure your security settings**: + - **Enable the Web Application Firewall (WAF)**: Set up rules to block + threats like SQL injections and XSS attacks. + - **Enable DDoS Protection**: Configure DDoS settings to prevent service + interruptions. +5. **Optional - Set up Access controls**: + - Use **IP Access Rules** to allow or block specific IPs. + - Configure **Rate Limiting** to prevent excessive requests that could signal + attacks. +6. **Review and Test**: Ensure that your website operates smoothly, and verify + that rules are correctly blocking or allowing traffic. + +## Evidence + +- Screenshot of your WAF configuration.