The 30 Akamai security checks Black Cat runs
Black Cat SSPM evaluates 30 security policies against your Akamai configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Akamai — what access Black Cat needs, and why.
Access control & privilege
6 checks · highest severity: high
Encryption, keys & secrets
5 checks · highest severity: high
Network security
3 checks · highest severity: high
Configuration hardening
15 checks · highest severity: critical
Access control & privilege (6)
- User Account Locked severity: medium
- User Inactive severity: medium
- User All Groups Access severity: high
- API Client Credentials Near Expiry severity: high
- API Client Inactive severity: low
- Custom Role With Admin Permissions severity: high
Encryption, keys & secrets (5)
- HSTS Not Enabled severity: high
- HSTS Max-Age Too Short severity: medium
- HTTP/2 Not Enabled severity: low
- Origin Not Using TLS severity: high
Network security (3)
- DNSSEC Not Enabled severity: high
- TSIG Not Enabled severity: medium
- SOA Serial Stale severity: low
Configuration hardening (15)
- Group With No Contracts severity: low
- WAF In Alert-Only Mode severity: critical
- Rate Controls Disabled severity: high
- Slow POST Protection Disabled severity: high
- IP Firewall Not Configured severity: medium
- Geo Firewall Not Configured severity: medium
- WAF Policy Alert-Only Mode severity: high
- Rate Control Threshold Too Permissive severity: medium
- Bot Management Disabled severity: high
- Edge Hostname IPv4 Only severity: low
- SureRoute Not Enabled severity: low
- Property No Origin Failover severity: medium
- Property Caching Disabled severity: low
- CP Code Unused severity: low
- Account Protection Disabled severity: high
Other checks (1)
severity: critical User MFA Not Enabled fix difficulty: easy #
Enable multi-factor authentication for the flagged Akamai Control Center user
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > Users
- Locate the user and click their name to open the user profile
- Under "Authentication", enable Multi-Factor Authentication
- Select the preferred MFA method (TOTP authenticator app or SMS)
- Save changes and instruct the user to complete MFA enrollment on next login
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4