Skip to content

The 28 Datadog security checks Black Cat runs

Black Cat SSPM evaluates 28 security policies against your Datadog configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Datadog — what access Black Cat needs, and why.

Access control & privilege (20)

Data sharing & exposure (3)

Logging & audit (3)

Other checks (2)

severity: low Unused API Key fix difficulty: easy #

Revoke or rotate API keys that have not been used recently

  1. Navigate to Organization Settings > API Keys
  2. Review the "Last Used" column to identify keys with no recent activity
  3. For each unused key, verify with the owning team whether it is still needed
  4. If no longer needed, click the key name and select "Revoke" to permanently delete it
  5. If the key is still needed but stale, rotate it by revoking and creating a new key
  6. Update any integrations or scripts that referenced the revoked key with the new key value

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8

severity: medium API Key Exceeds Maximum Age fix difficulty: medium #

Rotate API keys older than 365 days to reduce the risk of long-lived credential exposure

  1. Navigate to Organization Settings > API Keys
  2. Identify the flagged key by name and note which integrations use it
  3. Create a new API key with an appropriate descriptive name
  4. Update all integrations, scripts, or CI/CD pipelines that reference the old key with the new key value
  5. Verify the new key is working correctly in all affected systems
  6. Revoke the old API key to invalidate it permanently

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial