Dust AI data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Dust AI, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Dust AI connector needs.
Checks (3)
severity: high Open Space With Connected Data fix difficulty: medium #
Restrict broadly-accessible spaces that expose connected company data
- Open the space in Dust and review its access (kind/groups)
- Convert a global/open space to a regular space scoped to specific groups
- Re-scan to confirm the space is no longer broadly accessible
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Agent Shared Broadly fix difficulty: easy #
Review agents shared at workspace or global scope for over-exposure
- Open the agent in Dust and review its sharing scope
- Restrict the agent to a private or group scope if broad reach is not required
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Sensitive Data Source In Open Space fix difficulty: medium #
Move sensitive connectors out of broadly-accessible spaces
- Identify the space containing the sensitive data source
- Restrict the space access or relocate the data source to a scoped space
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11