Skip to content

The 24 1Password security checks Black Cat runs

Black Cat SSPM evaluates 24 security policies against your 1Password configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect 1Password — what access Black Cat needs, and why.

Identity, MFA & sign-in (3)

Access control & privilege (15)

Configuration hardening (4)

Other checks (2)

severity: critical Vault Exported fix difficulty: hard #

Investigate unauthorized 1Password vault export, contain the incident, and assess data exposure scope

  1. Navigate to 1Password Admin > Reports > Activity and locate the export event
  2. Identify the user, timestamp, vault name, and destination of the export
  3. Contact the user immediately to determine if the export was authorized
  4. If unauthorized suspend the account and escalate to the security team
  5. Assess the scope of exposed credentials and notify affected service owners
  6. Rotate any credentials that were present in the exported vault
  7. File an incident report and review data handling policies

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: info Master Password Changed fix difficulty: easy #

Verify the 1Password master password change was user-initiated and document it in the change log

  1. Navigate to 1Password Admin > Reports > Activity
  2. Confirm the event actor matches the account owner
  3. Contact the user to verify they initiated the password change
  4. If the change was not user-initiated suspend the account immediately
  5. Reset credentials and require a new master password if compromise is suspected

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial