Skip to main content

CCC-Complete (Behavioural) 0.1

Test results for this specific product, vendor, and version combination

VendorFINOS
ProductCCC-Complete (Behavioural)
Version0.1

Download Raw Results

Download the original OCSF, Gemara, or HTML result files used to generate this page

File NameDownload
combined
finos-ccc-integration-secret-main
summary
azureSecrets

Test Summary

Aggregate summary of all tests for this configuration result

Resources In Configuration1
Count of Tests8
Passing Tests4
Failing Tests4
Catalogs Tested
CCC.SecMgmt

Control Catalog Summary

Summary of test results grouped by control catalog and resource

Control CatalogResourcesTotal TestsPassingFailingTested RequirementsMissing RequirementsUnused Core Requirements
CCC.SecMgmt
finos-ccc-integratio...
844
All covered
None

Test Mapping Summary

Summary of test mappings showing how event codes map to test requirements

Control CatalogTest RequirementMapped Tests (Event Code | Total | Passing | Failing)
CCC.SecMgmt
CCC.SecMgmt.CN01.AR01
Attempt to use an outdated version of a secret after its rotation period has passed and verify that access is denied.
Current secret version is readable
220
Stale secret version retrieve is denied
202
CCC.SecMgmt
CCC.SecMgmt.CN02.AR01
Attempt to retrieve a secret from an unauthorized region and verify that access is denied.
Authorized region read succeeds
202
Unauthorized region read is denied
220

Resource Summary

Summary of all resources mentioned in OCSF results

Resource NameResource TypeControl CatalogsTotal TestsPassingFailing
finos-ccc-integration-secret-main
secrets
CCC.SecMgmt
844

Test Results

OCSF test results filtered for entries with CCC compliance mappings

StatusFindingResource NameResource TypeMessageTest Requirements
PASS
Current secret version is readable
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretVersion" using arguments "{uid}" and "latest" ✓ "{result}" is not an error ✓ I refer to "{result}" as "currentSecret" ✓ I attach "{currentSecret}" to the test output as "Current Secret Version" ✓ "{currentSecret.Denied}" is "false"
finos-ccc-integration-secret-main
secrets
Current secret version is readable
FAIL
Stale secret version retrieve is denied
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretVersion" using arguments "{uid}" and "{stale-version-id}" ✗ "{result}" is an error - Error: expected {result} to be an error, got *secrets.SecretValue
finos-ccc-integration-secret-main
secrets
Stale secret version retrieve is denied
FAIL
Authorized region read succeeds
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretInRegion" using arguments "{uid}" and "{authorized-region}" ✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: access denied: Get "https://finos-ccc-integration-missing-westus2.vault.azure.net/secrets/finos-ccc-integration-secret-main/?api-version=2025-07-01": dial tcp: lookup finos-ccc-integration-missing-westus2.vault.azure.net on 127.0.0.53:53: no such host ⊘ I refer to "{result}" as "authorizedRead" (skipped) ⊘ I attach "{authorizedRead}" to the test output as "Authorized Region Read" (skipped) ⊘ "{authorizedRead.Denied}" is "false" (skipped)
finos-ccc-integration-secret-main
secrets
Authorized region read succeeds
PASS
Unauthorized region read is denied
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretInRegion" using arguments "{uid}" and "{unauthorized-region}" ✓ "{result}" is an error
finos-ccc-integration-secret-main
secrets
Unauthorized region read is denied
PASS
Current secret version is readable
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretVersion" using arguments "{uid}" and "latest" ✓ "{result}" is not an error ✓ I refer to "{result}" as "currentSecret" ✓ I attach "{currentSecret}" to the test output as "Current Secret Version" ✓ "{currentSecret.Denied}" is "false"
finos-ccc-integration-secret-main
secrets
Current secret version is readable
FAIL
Stale secret version retrieve is denied
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretVersion" using arguments "{uid}" and "{stale-version-id}" ✗ "{result}" is an error - Error: expected {result} to be an error, got *secrets.SecretValue
finos-ccc-integration-secret-main
secrets
Stale secret version retrieve is denied
FAIL
Authorized region read succeeds
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretInRegion" using arguments "{uid}" and "{authorized-region}" ✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: access denied: Get "https://finos-ccc-integration-missing-westus2.vault.azure.net/secrets/finos-ccc-integration-secret-main/?api-version=2025-07-01": dial tcp: lookup finos-ccc-integration-missing-westus2.vault.azure.net on 127.0.0.53:53: no such host ⊘ I refer to "{result}" as "authorizedRead" (skipped) ⊘ I attach "{authorizedRead}" to the test output as "Authorized Region Read" (skipped) ⊘ "{authorizedRead.Denied}" is "false" (skipped)
finos-ccc-integration-secret-main
secrets
Authorized region read succeeds
PASS
Unauthorized region read is denied
✓ a cloud api for "{config}" in "api" ✓ I call "{api}" with "GetServiceAPI" using argument "secrets" ✓ I refer to "{result}" as "svc" ✓ I call "{svc}" with "RetrieveSecretInRegion" using arguments "{uid}" and "{unauthorized-region}" ✓ "{result}" is an error
finos-ccc-integration-secret-main
secrets
Unauthorized region read is denied