The 28 Datadog security checks Black Cat runs
Black Cat SSPM evaluates 28 security policies against your Datadog configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Datadog — what access Black Cat needs, and why.
Access control & privilege
20 checks · highest severity: critical
Data sharing & exposure
3 checks · highest severity: high
Logging & audit
3 checks · highest severity: high
Access control & privilege (20)
- SSO Disabled severity: high
- SSO Not Enforced severity: high
- Admin Redundancy severity: high
- Excessive Admins severity: medium
- External Admin severity: high
- Unverified User severity: medium
- Disabled User Present severity: low
- External User Access severity: low
- Dashboard Permissions Open severity: medium
- Dashboard Read-Only Without Role Restriction severity: low
- External Admin Service Account severity: high
- Service Account Admin Privileges severity: high
- Service Account Custom Role severity: low
- Application Key Write Scopes severity: low
- Application Key Has No Scopes severity: medium
- External Service Account severity: medium
- Admin User Not Verified severity: critical
- Disabled Admin User severity: medium
- Application Key Excessive Scopes severity: medium
- API Key Critical Age severity: high
Data sharing & exposure (3)
- Dashboard Public Sharing severity: high
- Dashboard Public URL severity: medium
Logging & audit (3)
- Audit Logging Disabled severity: high
- Audit Log Retention Period severity: medium
- Audit Retention Below Critical Threshold severity: high
Other checks (2)
severity: low Unused API Key fix difficulty: easy #
Revoke or rotate API keys that have not been used recently
- Navigate to Organization Settings > API Keys
- Review the "Last Used" column to identify keys with no recent activity
- For each unused key, verify with the owning team whether it is still needed
- If no longer needed, click the key name and select "Revoke" to permanently delete it
- If the key is still needed but stale, rotate it by revoking and creating a new key
- Update any integrations or scripts that referenced the revoked key with the new key value
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8
severity: medium API Key Exceeds Maximum Age fix difficulty: medium #
Rotate API keys older than 365 days to reduce the risk of long-lived credential exposure
- Navigate to Organization Settings > API Keys
- Identify the flagged key by name and note which integrations use it
- Create a new API key with an appropriate descriptive name
- Update all integrations, scripts, or CI/CD pipelines that reference the old key with the new key value
- Verify the new key is working correctly in all affected systems
- Revoke the old API key to invalidate it permanently
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8