🔧 NavajaSuiza

Security Audit Checklist

Comprehensive security audit checklist based on CIS and NIST frameworks.

Security Audit Checklist

Assess web application security with OWASP-aligned controls. Click each item to cycle through Pass / Fail / Not Assessed and get a risk report.

HTTPS / TLS encryption enforced everywhere
Transport • Risk weight: 9/9
? N/A
Strong authentication (MFA, password policy)
Access Control • Risk weight: 9/9
? N/A
Input validation on all forms and APIs
Input Handling • Risk weight: 8/9
? N/A
SQL injection prevention (parameterized queries)
Injection • Risk weight: 9/9
? N/A
XSS prevention (output encoding, CSP)
Injection • Risk weight: 8/9
? N/A
CSRF protection on state-changing requests
Session • Risk weight: 7/9
? N/A
Security headers configured (CSP, X-Frame-Options, etc.)
Headers • Risk weight: 6/9
? N/A
Dependencies scanned for known vulnerabilities
Supply Chain • Risk weight: 7/9
? N/A
Rate limiting on authentication and APIs
Availability • Risk weight: 6/9
? N/A
Secrets management (no hardcoded keys)
Configuration • Risk weight: 8/9
? N/A
Security logging and monitoring
Monitoring • Risk weight: 6/9
? N/A
Data encryption at rest
Data Protection • Risk weight: 7/9
? N/A
Principle of least privilege (RBAC)
Access Control • Risk weight: 7/9
? N/A
Backups tested and encrypted
Resilience • Risk weight: 6/9
? N/A

Tool Information

Category
Scale משפטית ותאימות
Type
Processed in browser
Tags

📤 Share This Tool

Security Audit Checklist - Gratis Online | NavajaSuiza Digital