Skip to content

The 24 Box security checks Black Cat runs

Black Cat SSPM evaluates 24 security policies against your Box configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Box — what access Black Cat needs, and why.

Access control & privilege (7)

Data sharing & exposure (12)

Other checks (5)

severity: medium User Exempt from Device Limits fix difficulty: easy #

Remove device limit exemptions from users who do not have a documented business need

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Users
  3. Locate the flagged user and open their account settings
  4. Under the Security tab, find the device limits exemption setting
  5. Remove the exemption unless there is a documented business justification
  6. Review and update your device trust policy to reflect approved exemptions

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: medium No Device Pins Configured fix difficulty: hard #

Configure device pins to enforce device trust and restrict access from unmanaged devices

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Device Trust
  3. Enable the Device Trust feature for your enterprise
  4. Configure the device pin policy to require device registration before accessing Box
  5. Set the enforcement mode to block unregistered devices
  6. Communicate the device registration requirement to all users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: low Empty Group fix difficulty: easy #

Remove or repopulate empty Box groups that may retain inherited folder permissions

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Users & Groups > Groups
  3. Locate the empty group flagged in the finding
  4. Check whether the group is assigned to any folders or collaboration policies
  5. If the group is no longer needed, delete it
  6. If the group is still needed, add the appropriate members

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Excessive Applications Installed fix difficulty: medium #

Audit and remove unused or unnecessary Box application integrations

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Apps > Custom Apps Manager
  3. Review the full list of installed applications
  4. Identify apps that are no longer actively used or have no documented business purpose
  5. Revoke access for unused apps by selecting the app and clicking Revoke Access
  6. Establish an app governance process to periodically review installed integrations

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: high Retention Policies Configured But None Active fix difficulty: medium #

Activate at least one retention policy to enforce data retention requirements

  1. Sign in to the Box Admin Console as an administrator
  2. Navigate to Admin Console > Governance > Retention Policies
  3. Review all defined retention policies and their current status
  4. Identify policies that should be active and reactivate them
  5. Assign reactivated policies to the appropriate folders or content types
  6. Verify that the policies are enforcing retention on the correct content

Vendor docs ↗

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial