The 6 ChatGPT Enterprise security checks Black Cat runs
Black Cat SSPM evaluates 6 security policies against your ChatGPT Enterprise configuration on every scan, classifies each finding by risk, and provides remediation steps. All of them are listed below.
How to connect ChatGPT Enterprise — what access Black Cat needs, and why.
Other checks (6)
severity: medium Disabled Member Present fix difficulty: easy #
Remove or fully deprovision disabled ChatGPT Enterprise members
- Open chatgpt.com/admin > Members
- Remove the disabled member, or complete deprovisioning in your IdP/SCIM source
- Confirm the member no longer appears in the workspace
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Non-SCIM-Managed User fix difficulty: medium #
Bring manually-added members under SCIM/IdP provisioning
- Configure SCIM provisioning from your IdP to ChatGPT Enterprise
- Re-provision the affected member through the IdP so they carry an externalId
- Remove any locally-created duplicate account
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium GPT With Unreviewed Third-Party Actions fix difficulty: medium #
Review third-party actions on publicly shared custom GPTs
- Open chatgpt.com/admin > GPTs
- Review each third-party action's domain and requested scope on the GPT
- Remove unreviewed actions, or restrict the GPT's sharing to private/workspace
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Secret Detected In ChatGPT Conversation fix difficulty: medium #
Rotate the exposed credential, then remove the conversation from ChatGPT Enterprise
- Rotate the exposed credential immediately at its issuing provider
- Open chatgpt.com/admin
- Locate and remove the flagged conversation via the ChatGPT admin console
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: low Empty Group fix difficulty: easy #
Remove unused empty groups
- Open chatgpt.com/admin > Groups
- Delete the group if it is no longer needed, or assign members
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Workspace Allows Unapproved Connectors fix difficulty: medium #
Restrict the workspace to an approved connector allowlist
- Open chatgpt.com/admin > Settings > Connectors
- Disable "Allow unapproved connectors" for the workspace
- Add any connectors members need to the approved allowlist explicitly
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10