<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://tesserohq.com/</loc></url><url><loc>https://tesserohq.com/about/</loc></url><url><loc>https://tesserohq.com/frameworks/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/a-strong-password-policy-is-configured/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/active-access-keys-are-rotated-at-least-every-90-days/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/activity-log-alerts-exist-for-critical-changes-nsg-security-policy-key-vault/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/amazon-guardduty-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/audit-log-retention-is-set-to-the-maximum-365-days/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/automatic-rotation-is-enabled-on-kms-customer-keys/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/autonomous-database-network-access-is-restricted-private-endpoint-acls/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/aws-config-is-enabled-in-all-regions/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/azure-policy-assigns-guardrails-for-required-configurations/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/azure-sql-auditing-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/block-volumes-are-encrypted-default-or-cmk/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/buckets-use-customer-managed-encryption-keys-where-required/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/budget-alerts-detect-anomalous-spend-abuse-indicator/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/cloudtrail-is-enabled-in-all-regions-with-a-multi-region-trail/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/cloudtrail-log-file-validation-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/cloudtrail-logs-are-encrypted-with-a-kms-cmk/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/cloudwatch-metric-filters-alarms-exist-for-critical-events/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/compartment-structure-and-iam-boundaries-isolate-workloads/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/compute-instances-have-no-unintended-public-ips/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/credentials-unused-for-90-days-are-disabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/customer-secret-keys-api-keys-are-rotated-regularly-90-days/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/database-systems-use-encryption-tde/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/default-security-group-of-every-vpc-restricts-all-traffic/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/default-security-list-of-each-vcn-restricts-traffic/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/diagnostic-settings-ship-activity-logs-to-log-analytics-storage-with-retention/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/ebs-volume-encryption-by-default-is-enabled-per-region/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/ec2-instances-enforce-imdsv2-token-required-metadata/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/ecr-repositories-have-image-scanning-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/eks-clusters-log-control-plane-and-restrict-public-api-endpoint/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/guest-user-access-and-invitations-are-restricted/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/iam-policies-follow-least-privilege-no-broad-manage-all-resources/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/key-vault-network-access-is-restricted-firewall-private-endpoint/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/key-vaults-have-soft-delete-and-purge-protection-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/lambda-functions-hold-no-secrets-in-plaintext-env-vars-and-use-least-privilege-r/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/legacy-basic-authentication-is-blocked/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/membership-of-the-administrators-group-is-minimal/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/mfa-is-enabled-for-all-iam-users-with-console-access/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/mfa-is-enforced-for-all-iam-users-especially-administrators/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/mfa-is-enforced-for-all-users-especially-privileged-roles/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/microsoft-defender-for-cloud-is-on-the-standard-paid-tier-for-key-resource-types/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/microsoft-defender-for-sql-threat-detection-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-access-keys-exist-on-the-root-account/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-iam-identity-has-unrestricted-administrator-policies-beyond-a-justified-few/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-individual-s3-bucket-is-publicly-readable-writable/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-nsg-allows-unrestricted-inbound-rdp-3389-from-the-internet/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-nsg-allows-unrestricted-inbound-ssh-22-from-the-internet/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-object-storage-bucket-has-public-access/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-security-group-allows-unrestricted-0-0-0-0-0-ingress-to-ssh-22-or-rdp-3389/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/no-security-group-exposes-database-ports-3306-5432-1433-27017-to-0-0-0-0-0/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/notifications-events-alert-on-iam-network-and-policy-changes/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/nsg-flow-logs-are-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/number-of-global-administrators-is-limited-typically-2-4/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/oracle-cloud-guard-is-enabled-at-tenancy-root/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/permissions-are-granted-via-groups-roles-not-directly-to-users/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/privileged-identity-management-pim-provides-just-in-time-elevation/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/public-facing-ec2-instances-are-intentional-and-minimal/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/rds-instances-are-encrypted-at-rest/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/rds-instances-are-not-publicly-accessible/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/resource-locks-protect-critical-resources-from-deletion/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/root-account-is-not-used-for-day-to-day-activity/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/root-account-mfa-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/s3-block-public-access-is-enabled-at-the-account-level/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/s3-default-encryption-is-enabled-on-all-buckets/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/secure-transfer-https-only-is-required/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/security-lists-do-not-allow-unrestricted-rdp-3389-from-0-0-0-0-0/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/security-lists-do-not-allow-unrestricted-ssh-22-from-0-0-0-0-0/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/sql-server-firewall-does-not-allow-0-0-0-0-all-internet/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/storage-account-network-rules-default-to-deny-with-explicit-allow-lists/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/storage-accounts-disallow-public-blob-access/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/storage-blob-soft-delete-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/strong-iam-password-policy-is-enforced/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/transparent-data-encryption-tde-is-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/vault-keys-have-rotation-configured/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/vcn-flow-logs-are-enabled/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/versioning-is-enabled-on-sensitive-buckets/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/vm-os-and-data-disks-are-encrypted-ade-cmk-or-platform-encryption/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/vms-use-managed-disks-not-unmanaged-page-blobs/</loc></url><url><loc>https://tesserohq.com/frameworks/cloud-security/vpc-flow-logs-are-enabled-on-all-vpcs/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/access-privileged-activity-logging/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/application-access-rbac/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/application-security-testing-pen-test/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/asset-configuration-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/backup-failure-monitoring/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/backup-policy-execution/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/backup-restoration-testing/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/backup-storage-protection/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/batch-monitoring-failure-handling/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/business-continuity-plan/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/capacity-performance-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/centralised-identity-sso/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/change-authorisation/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/change-management-policy/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/change-request-documentation/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/cloud-iam-console-gcp/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/cloud-provider-governance-gcp/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/code-review-peer-approval/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/cryptographic-key-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/data-centre-environmental-controls/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/data-classification-handling/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/data-conversion-migration/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/data-retention-secure-disposal/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/database-access-controls/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/database-schema-change-control/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/deployment-pipeline-ci-cd/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/developer-access-to-production/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/disaster-recovery-plan/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/dr-testing/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/emergency-changes/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/encryption-at-rest/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/encryption-in-transit/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/endpoint-protection-edr/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/environment-segregation/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/generic-shared-service-accounts/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/go-live-implementation-approval/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/incident-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/infrastructure-iac-changes/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/it-governance-oversight/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/it-information-security-policies/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/it-organisation-segregation/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/it-risk-assessment/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/job-scheduling-control/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/logging-standard-retention/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/multi-factor-authentication-mfa/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/network-security-firewall/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/operating-system-server-access/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/outsourcing-register-mas-compliance/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/password-authentication-policy/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/patch-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/periodic-user-access-review/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/physical-access-or-cloud-soc/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/post-implementation-review/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/privileged-access-management-pam/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/privileged-administrator-access/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/problem-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/project-governance-stage-gates/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/regulatory-compliance-monitoring/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/remote-access-vpn/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/requirements-design-approval/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/rollback-back-out-plans/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/sdlc-methodology/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/secrets-api-key-token-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/secure-development-standards/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/security-alerting-anomaly-monitoring/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/security-awareness-training/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/segregation-of-duties-sod/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/service-level-performance-monitoring/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/session-management-timeout/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/soc-report-review-soc-1-2/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/sod-in-changes-dev-deployer/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/system-infrastructure-monitoring/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/testing-uat-before-production/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/third-party-access-management/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/time-synchronisation-ntp/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/user-access-de-provisioning-leavers/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/user-access-modification-movers/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/user-access-provisioning/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/vendor-third-party-risk-assessment/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/version-control-scm/</loc></url><url><loc>https://tesserohq.com/frameworks/itgc/vulnerability-management/</loc></url><url><loc>https://tesserohq.com/pricing/</loc></url><url><loc>https://tesserohq.com/privacy/</loc></url><url><loc>https://tesserohq.com/product/</loc></url><url><loc>https://tesserohq.com/security/</loc></url><url><loc>https://tesserohq.com/terms/</loc></url></urlset>