The 23 Cisco Duo security checks Black Cat runs
Black Cat SSPM evaluates 23 security policies against your Cisco Duo configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Cisco Duo — what access Black Cat needs, and why.
Identity, MFA & sign-in
11 checks · highest severity: high
Access control & privilege
4 checks · highest severity: high
Configuration hardening
8 checks · highest severity: high
Identity, MFA & sign-in (11)
- User Not Enrolled in MFA severity: high
- User in MFA Bypass Status severity: high
- User Has Only SMS/Phone Factors severity: medium
- Dormant User severity: medium
- Disabled User Still Has Factors severity: low
- Locked Out User severity: low
- Dormant Administrator severity: medium
- Orphan Phone Device severity: low
- Landline Phone Factor severity: low
- Unactivated Phone Device severity: low
- Orphan Hardware/OTP Token severity: low
Access control & privilege (4)
- Admin With Privileged Role and No Admin-Unit Restriction severity: high
- Owner-Role Administrator severity: low
- Admin API Integration With Write Permission severity: medium
- Admin API Integration Can Manage Admins severity: high
Configuration hardening (8)
- Admin API Integration Without IP Restriction severity: high
- Integration Without Enforced Enrollment Policy severity: medium
- Inactive User Expiration Not Configured severity: medium
- No Lockout For Unenrolled Users severity: medium
- Weak Password Complexity severity: low
- Short Minimum Password Length severity: low
- Fraud Notification Email Disabled severity: low
- No Authentication Lockout Threshold severity: medium