Skip to content

The 28 Atlassian security checks Black Cat runs

Black Cat SSPM evaluates 28 security policies against your Atlassian configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Atlassian — what access Black Cat needs, and why.

Access control & privilege (17)

Data sharing & exposure (6)

Other checks (5)

severity: high User Without MFA fix difficulty: medium #

Enforce two-step verification for all Atlassian users in authentication policies

  1. Navigate to admin.atlassian.com > Security > Authentication policies
  2. Enable two-step verification enforcement
  3. Notify the affected user to enroll in MFA

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Two-Step Verification Not Enforced fix difficulty: medium #

Enforce two-step verification for all users in Atlassian authentication policies

  1. Navigate to admin.atlassian.com > Security > Authentication policies
  2. Edit the default authentication policy
  3. Enable 'Enforce two-step verification'
  4. Notify users about the new requirement

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high IP Allowlist Policy Disabled fix difficulty: medium #

Enable IP allowlist policy to restrict access to trusted network ranges

  1. Navigate to admin.atlassian.com and select the organization
  2. Go to Security > IP allowlist
  3. Add your corporate IP ranges and enable the policy
  4. Verify that all legitimate users and integrations can still access the organization

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: medium Mobile App Policy Disabled fix difficulty: medium #

Enable mobile app management policy to control mobile device access to organization data

  1. Navigate to admin.atlassian.com and select the organization
  2. Go to Security > Mobile app policy
  3. Enable the policy and configure device management settings
  4. Set requirements for app version, OS version, and biometric authentication

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Data Residency Policy Disabled fix difficulty: hard #

Enable the data residency policy to pin data storage location for regulatory compliance

  1. Navigate to admin.atlassian.com > Security > Policies
  2. Locate the Data residency policy
  3. Enable the policy and select your required data region
  4. Verify that the selected region meets your compliance requirements (GDPR, SOC 2, etc.)
  5. Allow time for data migration if switching regions

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.7

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial