The 24 Box security checks Black Cat runs
Black Cat SSPM evaluates 24 security policies against your Box configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Box — what access Black Cat needs, and why.
Access control & privilege
7 checks · highest severity: critical
Data sharing & exposure
12 checks · highest severity: high
Access control & privilege (7)
- Excessive Admin Users severity: high
- Inactive User Account severity: medium
- External Collaboration Not Restricted severity: high
- Platform Access Only Admin severity: high
- User Exempt from Login Verification severity: high
- User Account Deactivated But Not Removed severity: medium
- Admin Exempt From Login Verification severity: critical
Data sharing & exposure (12)
- No Collaboration Whitelist Entries severity: medium
- Broad Inbound Collaboration Whitelist severity: medium
- Bidirectional Collaboration Whitelist severity: high
- No Retention Policies Defined severity: high
- Retired Retention Policy severity: medium
- Short Retention Period severity: medium
- Modifiable Retention Policy severity: medium
- Permanent Delete Disposition Action severity: medium
- No Indefinite Retention Policies severity: medium
- Group Allows External Collaborator Invitations severity: medium
- Outbound Collaboration Whitelist Entry severity: medium
- Excessive Collaboration Whitelist Entries severity: medium
Other checks (5)
severity: medium User Exempt from Device Limits fix difficulty: easy #
Remove device limit exemptions from users who do not have a documented business need
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Users
- Locate the flagged user and open their account settings
- Under the Security tab, find the device limits exemption setting
- Remove the exemption unless there is a documented business justification
- Review and update your device trust policy to reflect approved exemptions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: medium No Device Pins Configured fix difficulty: hard #
Configure device pins to enforce device trust and restrict access from unmanaged devices
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Device Trust
- Enable the Device Trust feature for your enterprise
- Configure the device pin policy to require device registration before accessing Box
- Set the enforcement mode to block unregistered devices
- Communicate the device registration requirement to all users
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: low Empty Group fix difficulty: easy #
Remove or repopulate empty Box groups that may retain inherited folder permissions
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Groups
- Locate the empty group flagged in the finding
- Check whether the group is assigned to any folders or collaboration policies
- If the group is no longer needed, delete it
- If the group is still needed, add the appropriate members
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Excessive Applications Installed fix difficulty: medium #
Audit and remove unused or unnecessary Box application integrations
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Apps > Custom Apps Manager
- Review the full list of installed applications
- Identify apps that are no longer actively used or have no documented business purpose
- Revoke access for unused apps by selecting the app and clicking Revoke Access
- Establish an app governance process to periodically review installed integrations
Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: high Retention Policies Configured But None Active fix difficulty: medium #
Activate at least one retention policy to enforce data retention requirements
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Review all defined retention policies and their current status
- Identify policies that should be active and reactivate them
- Assign reactivated policies to the appropriate folders or content types
- Verify that the policies are enforcing retention on the correct content