Box data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Box, Black Cat runs 12 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Box connector needs.
Checks (12)
severity: medium No Collaboration Whitelist Entries fix difficulty: medium #
Define a collaboration whitelist to restrict external sharing to approved domains only
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Enterprise Settings > Content & Sharing
- Under External Collaboration, locate the collaboration whitelist settings
- Enable the whitelist and add approved external domains
- Set the whitelist policy to restrict collaboration to whitelisted domains only
- Communicate the approved domain list to users and update it as needed
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Broad Inbound Collaboration Whitelist fix difficulty: medium #
Review and tighten inbound collaboration whitelist entries to limit external user access
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Enterprise Settings > Content & Sharing
- Under External Collaboration, review all whitelist entries with inbound or bidirectional access
- For each inbound entry, confirm that external users from that domain require access to your Box content
- Change inbound entries to outbound-only where external read access is not required
- Remove any domains that no longer have a business justification
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Bidirectional Collaboration Whitelist fix difficulty: medium #
Replace bidirectional collaboration whitelist entries with directional entries to reduce data exfiltration risk
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Enterprise Settings > Content & Sharing
- Under External Collaboration, identify all whitelist entries set to bidirectional
- Assess whether both inbound and outbound collaboration are genuinely required for each domain
- Change bidirectional entries to outbound-only unless inbound access has a documented business need
- Document the justification for any bidirectional entries that are retained
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high No Retention Policies Defined fix difficulty: medium #
Create retention policies to ensure data is retained for the required compliance period
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Click Create Retention Policy
- Define the policy name, retention period, and disposition action
- Assign the policy to the appropriate folders or content types
- Review and confirm the policy settings before activating
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1
severity: medium Retired Retention Policy fix difficulty: medium #
Review and replace retired retention policies to ensure continued compliance coverage
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Locate the retired retention policy flagged in the finding
- Assess what content was previously covered by this policy
- Create a new active retention policy with appropriate settings to replace it
- Assign the new policy to the same folders or content types as the retired policy
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1
severity: medium Short Retention Period fix difficulty: medium #
Extend the retention period for policies set below the minimum recommended duration of 30 days
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Locate the retention policy with the short retention period
- Review the compliance requirements that apply to the content covered by this policy
- Edit the retention policy and increase the retention length to meet compliance requirements
- Save the updated policy and verify it is applied to the correct content
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1
severity: medium Modifiable Retention Policy fix difficulty: hard #
Convert modifiable retention policies to non-modifiable to prevent tampering with retained content
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Locate the modifiable retention policy flagged in the finding
- Review whether the policy covers content subject to compliance requirements
- Create a new non-modifiable retention policy with the same settings
- Reassign the content from the modifiable policy to the new non-modifiable policy
- Retire the original modifiable policy once the transition is complete
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1
severity: medium Permanent Delete Disposition Action fix difficulty: medium #
Change the disposition action to remove from policy instead of permanently deleting, to allow for legal holds
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Locate the retention policy with the permanently_delete disposition action
- Review whether the content covered by this policy may be subject to legal hold requirements
- Edit the policy and change the disposition action to Remove from Policy or another non-destructive option
- Save the updated policy settings
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1
severity: medium No Indefinite Retention Policies fix difficulty: medium #
Create at least one indefinite retention policy to preserve critical business records for compliance
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Governance > Retention Policies
- Click Create Retention Policy
- Set the policy type to Indefinite
- Assign the policy to folders containing critical business records or compliance-sensitive content
- Document the content categories covered by the indefinite retention policy
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.c DORA (SaaS Security) DORA-12.1
severity: medium Group Allows External Collaborator Invitations fix difficulty: easy #
Disable the collaborator invitation permission on groups to prevent uncontrolled external sharing
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Users & Groups > Groups
- Locate the flagged group
- Edit the group settings and disable the option allowing members to invite collaborators
- Save the updated group settings
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Outbound Collaboration Whitelist Entry fix difficulty: medium #
Review outbound collaboration whitelist entries to ensure data sharing to external domains is justified
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Enterprise Settings > Content & Sharing
- Under External Collaboration, review all whitelist entries with outbound access
- Verify each outbound domain has a documented business justification for data sharing
- Remove any domains that no longer require outbound collaboration access
- Consider restricting outbound sharing to inbound-only where read access is sufficient
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Excessive Collaboration Whitelist Entries fix difficulty: medium #
Reduce the number of collaboration whitelist entries to minimize the external sharing surface
- Sign in to the Box Admin Console as an administrator
- Navigate to Admin Console > Enterprise Settings > Content & Sharing
- Under External Collaboration, review the full list of whitelisted domains
- Identify domains that are no longer active partners or vendors
- Remove outdated or unnecessary whitelist entries
- Establish a periodic review process for external collaboration domains
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12