← Inspection rules

SEC-006 / v1.2.0 / 2026-10-02

Inspect deployed exposure boundaries

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Cloud, data platforms, administration, and file transfer, including delegated assets.

Where to look first

  • IaC, deployed visibility, network policies
  • Admin interfaces, data storage, delegated asset inventory

Inspection steps

  1. Compare intended exposure with deployed settings; inspect anonymous access and broad network permissions.
  2. Test rejection only on authorized assets without retrieving data. Without live access, mark deployed state unverified.

Remediation direction

  • Restrict unnecessary exposure; establish drift detection and ownership.

Evidence required for completion

  • Record deployed configuration and rejection of unintended access sources.

Limits and unverified scope

  • IaC alone misses manual drift. A deliberately public service is not inherently a defect.