The 24 1Password security checks Black Cat runs
Black Cat SSPM evaluates 24 security policies against your 1Password configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect 1Password — what access Black Cat needs, and why.
Identity, MFA & sign-in
3 checks · highest severity: critical
Access control & privilege
15 checks · highest severity: high
Configuration hardening
4 checks · highest severity: critical
Identity, MFA & sign-in (3)
- MFA Disabled severity: critical
- MFA Status Unknown severity: medium
- Sign-in Without MFA severity: high
Access control & privilege (15)
- Suspended User Activity severity: high
- Suspended User Not Removed severity: low
- Dormant User severity: medium
- Failed Sign-in Attempt severity: high
- Sign-in From Untrusted Location severity: medium
- Failed Sign-in From Untrusted Location severity: high
- Service Account Token Created severity: medium
- Sign-in From Unknown Country severity: medium
- Failed Sign-in Without MFA severity: medium
- Sign-in With No Client Recorded severity: low
- Sign-in With No IP Recorded severity: low
- Failed Sign-in From Unknown Country severity: high
- Resource Created severity: low
- Suspended User With MFA Disabled severity: medium
- User With No Recorded Activity severity: medium
Configuration hardening (4)
- SSO Policy Modified severity: high
- SSO Disabled severity: critical
- Signing Key Changed severity: high
- Firewall Rule Changed severity: medium
Other checks (2)
severity: critical Vault Exported fix difficulty: hard #
Investigate unauthorized 1Password vault export, contain the incident, and assess data exposure scope
- Navigate to 1Password Admin > Reports > Activity and locate the export event
- Identify the user, timestamp, vault name, and destination of the export
- Contact the user immediately to determine if the export was authorized
- If unauthorized suspend the account and escalate to the security team
- Assess the scope of exposed credentials and notify affected service owners
- Rotate any credentials that were present in the exported vault
- File an incident report and review data handling policies
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: info Master Password Changed fix difficulty: easy #
Verify the 1Password master password change was user-initiated and document it in the change log
- Navigate to 1Password Admin > Reports > Activity
- Confirm the event actor matches the account owner
- Contact the user to verify they initiated the password change
- If the change was not user-initiated suspend the account immediately
- Reset credentials and require a new master password if compromise is suspected
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1