1Password configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On 1Password, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the 1Password connector needs.
Checks (4)
severity: high SSO Policy Modified fix difficulty: hard #
Verify the 1Password SSO policy change was authorized and revert if not approved
- Navigate to 1Password Admin > Reports > Activity and locate the SSO policy change event
- Identify who made the change and when
- Verify the change was approved through the change management process
- If unauthorized revert the SSO policy to its previous configuration
- Review current SSO settings under Integrations to confirm expected state
- Escalate to the security team if the change origin is unclear
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: critical SSO Disabled fix difficulty: hard #
Re-enable 1Password SSO immediately if disabled without authorization and review the audit trail
- Review the audit event to identify who disabled SSO
- Verify if this was an authorized change
- Re-enable SSO immediately if unauthorized
- Review SSO provider configuration for issues that may have prompted disabling
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Signing Key Changed fix difficulty: hard #
Verify the 1Password signing key change was authorized and escalate to security if not
- Review the audit event details for who changed the signing key
- Verify the change was authorized via change management process
- If unauthorized contact security team immediately
- Reset account if compromise suspected
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Firewall Rule Changed fix difficulty: medium #
Verify the 1Password firewall rule change was authorized and revert if it weakens security posture
- Navigate to 1Password Admin > Reports > Activity and locate the firewall rule change event
- Identify who made the change and what rule was added, modified, or removed
- Verify the change was approved through the change management process
- Review current firewall rules under Settings > Security > Firewall
- Revert any unauthorized or overly permissive rules immediately
- Document the change and its justification in the change log
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10