Connecting the Integration
DigitalOcean is an infrastructure cloud hosting provider that offers cloud computing and infrastructure services.
Secureframe scans various DigitalOcean resources and configurations to ensure compliance and automatically gathers evidence for your audit.
To integrate DigitalOcean with Secureframe, navigate to Integrations and search for "DigitalOcean" on the "Available Integrations" page. (If you have the Custom Integration feature, click on "Add native connection"). Click "Connect" and follow the steps in the connection form.
Secureframe integrates with both DigitalOcean Projects and Spaces. To connect a Space, a Project must also be connected. If connecting a Space after connecting the related Project, re-connect with the same Project API token and and specify the Spaces key configuration.
Projects
Projects are a group of DigitalOcean resources (like Droplets, Spaces, and load balancers). You can create projects that align with the applications, environments, and clients that you host on DigitalOcean.
Secureframe requires a Personal Access Token to integrate with DigitalOcean Projects.
Personal Access Tokens support at least read and optional write scopes while creating a token on API Tokens page.
Secureframe DOES NOT require write scope to integrate with DigitalOcean.
Users should also specify an expiration period for thier Personal Access Token. (options: 30/60/90 days, 1 year, Never expire). To prevent service interruptions, it's suggested to use tokens that Never expire for Secureframe integrations.
Spaces
Spaces is an S3-compatible object storage service, and are ideal for storing static, unstructured data like audio, video, and images as well as large amounts of text.
Secureframe requires a Spaces Key to integrate with DigitalOcean Spaces.
Creating a Spaces key is a straightforward action. To generate Spaces access keys, from the control panel, click API (additional information).
Currently, Spaces keys are both read and write; however, there is no Secureframe functionality utilizing write functionality. DigitalOcean does not currently support read-only keys.
Secureframe will scan Spaces and relevant resources only if a Spaces key is provided in the connection form.
Supported Regions
The regions supported through the Secureframe integration include:
Datacenter | Region |
NYC1 | New York City, United States |
NYC3 | New York City, United States |
AMS3 | Amsterdam, the Netherlands |
SFO2 | San Francisco, United States |
SFO3 | San Francisco, United States |
SGP1 | Singapore |
LON1 | London, United Kingdom |
FRA1 | Frankfurt, Germany |
TOR1 | Toronto, Canada |
BLR1 | Bangalore, India |
SYD1 | Sydney, Australia |
Permissions, Fields, Controls, and Automated Tests
Click the provided link or navigate to the “Integration” page.
Select the “Available” tab.
Search for the integration.
Click “View Details”.
Additional Information
Due to limitations in DigitalOcean's API, user integration data typically populated in Vendor Access is not supported.
If you encounter any issues or have any concerns, we kindly request you to reach out to our dedicated support group for prompt assistance. Our support team is highly trained and committed to providing you with the best possible solutions to ensure a seamless experience.
Frequently Asked Questions (FAQ)
Why is my DigitalOcean Database cluster failing a patching or version test?
This is a Secureframe-defined configuration test mapped to related framework requirements. Secureframe reads the database engine and version from DigitalOcean, then evaluates whether that version is past end of life.
End-of-life dates are based on endoflife.date for the engine (for example, MySQL). When an engine version is past its published end-of-life date, the cluster fails the test.
Who maintains this test logic, and can customers customize accepted versions?
Secureframe maintains the test logic. The engine and version come from DigitalOcean metadata. End-of-life status is evaluated using Secureframe’s version mappings sourced from endoflife.date.
Customers cannot customize which database versions are accepted for this test.
What should I do if DigitalOcean still offers a version Secureframe flags as unsupported?
Upgrade to a supported database version when DigitalOcean makes an upgrade path available. That is the preferred remediation.
If an upgrade is not yet available, complete a risk assessment and document the decision in Risk Management. Use treatment decision Accept when formally accepting the residual risk, or Mitigate when you are implementing compensating or additional controls. Record the rationale and any compensating controls in the Treatment plan.
You can attach the risk assessment and compensating-control evidence to the failing test with Pass with upload. Prefer this documented risk treatment approach over Ignore evidence for this test or Mark out of scope when the database remains in audit scope.
