Skip to content

Akamai encryption, keys & secrets security checks

Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.

On Akamai, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.

Checks (5)

severity: high HSTS Not Enabled fix difficulty: easy #

Enable HTTP Strict Transport Security (HSTS) header on the Akamai property

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. In the rule tree, add a behavior under the default rule or HTTPS match
  5. Search for "Modify Outgoing Response Header" or "HTTP Strict Transport Security" behavior
  6. Set the Strict-Transport-Security header with max-age of at least 31536000
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: medium HSTS Max-Age Too Short fix difficulty: easy #

Increase the HSTS max-age directive to at least 31536000 seconds (one year)

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. Locate the HSTS or Modify Outgoing Response Header behavior in the rule tree
  5. Update the max-age value in the Strict-Transport-Security header to 31536000 or higher
  6. Optionally add includeSubDomains and preload directives if appropriate
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: low HTTP/2 Not Enabled fix difficulty: easy #

Enable HTTP/2 on the Akamai property to improve performance and security

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. In the rule tree, click "Add Behavior" and search for "HTTP/2"
  5. Add the HTTP/2 behavior and ensure it is enabled
  6. Verify the property's edge hostname uses an SSL/TLS-enabled certificate (HTTP/2 requires TLS)
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: high Origin Not Using TLS fix difficulty: medium #

Configure the origin server to use HTTPS so traffic between Akamai and origin is encrypted

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Properties (Property Manager)
  3. Select the affected property and click "Edit New Version"
  4. Locate the "Origin Server" behavior in the rule tree
  5. Under "Forward Protocol", change the protocol from HTTP to HTTPS
  6. Ensure the origin server has a valid TLS certificate installed; configure verification settings
  7. Activate the updated property version to staging then production

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: medium Edge Hostname Using Shared Cert fix difficulty: hard #

Replace the shared certificate with a dedicated TLS certificate for the edge hostname

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to CDN > Edge Hostnames
  3. Locate the edge hostname using a shared certificate
  4. Click "Edit" and change the certificate option from "Shared Certificate" to "Enhanced TLS" or "Standard TLS"
  5. Select or provision a dedicated certificate for the hostname (via CPS - Certificate Provisioning System)
  6. Save the updated edge hostname configuration
  7. Update any associated property activations if required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

More Akamai checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial