The 28 Atlassian security checks Black Cat runs
Black Cat SSPM evaluates 28 security policies against your Atlassian configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Atlassian — what access Black Cat needs, and why.
Access control & privilege
17 checks · highest severity: critical
Data sharing & exposure
6 checks · highest severity: high
Access control & privilege (17)
- Inactive User severity: medium
- Suspended User With Access severity: medium
- User Dual Admin Role severity: medium
- External User With Product Access severity: medium
- API Token Older Than 90 Days severity: high
- User With Multiple API Tokens severity: medium
- SSO Not Configured severity: high
- Session Duration Excessive severity: medium
- Jira Project Permissive Default Roles severity: medium
- API Token No Label severity: low
- External Users Policy Disabled severity: high
- Org Admin Product Access severity: medium
- User Account Closed severity: medium
- API Token Generic Label severity: medium
- Empty Group severity: low
- Admin Without MFA severity: critical
- Product Access Admin severity: medium
Data sharing & exposure (6)
- Jira Project Public Access severity: high
- Confluence Space Anonymous Access severity: high
- Confluence Space Public Links severity: medium
- Archived Confluence Space With Anonymous Access severity: medium
Other checks (5)
severity: high User Without MFA fix difficulty: medium #
Enforce two-step verification for all Atlassian users in authentication policies
- Navigate to admin.atlassian.com > Security > Authentication policies
- Enable two-step verification enforcement
- Notify the affected user to enroll in MFA
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Two-Step Verification Not Enforced fix difficulty: medium #
Enforce two-step verification for all users in Atlassian authentication policies
- Navigate to admin.atlassian.com > Security > Authentication policies
- Edit the default authentication policy
- Enable 'Enforce two-step verification'
- Notify users about the new requirement
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high IP Allowlist Policy Disabled fix difficulty: medium #
Enable IP allowlist policy to restrict access to trusted network ranges
- Navigate to admin.atlassian.com and select the organization
- Go to Security > IP allowlist
- Add your corporate IP ranges and enable the policy
- Verify that all legitimate users and integrations can still access the organization
Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9
severity: medium Mobile App Policy Disabled fix difficulty: medium #
Enable mobile app management policy to control mobile device access to organization data
- Navigate to admin.atlassian.com and select the organization
- Go to Security > Mobile app policy
- Enable the policy and configure device management settings
- Set requirements for app version, OS version, and biometric authentication
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Data Residency Policy Disabled fix difficulty: hard #
Enable the data residency policy to pin data storage location for regulatory compliance
- Navigate to admin.atlassian.com > Security > Policies
- Locate the Data residency policy
- Enable the policy and select your required data region
- Verify that the selected region meets your compliance requirements (GDPR, SOC 2, etc.)
- Allow time for data migration if switching regions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.7