← Inspection rules
SEC-006 / v1.2.0 / 2026-10-02
Inspect deployed exposure boundaries
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Cloud, data platforms, administration, and file transfer, including delegated assets.
Where to look first
- IaC, deployed visibility, network policies
- Admin interfaces, data storage, delegated asset inventory
Inspection steps
- Compare intended exposure with deployed settings; inspect anonymous access and broad network permissions.
- Test rejection only on authorized assets without retrieving data. Without live access, mark deployed state unverified.
Remediation direction
- Restrict unnecessary exposure; establish drift detection and ownership.
Evidence required for completion
- Record deployed configuration and rejection of unintended access sources.
Limits and unverified scope
- IaC alone misses manual drift. A deliberately public service is not inherently a defect.