Skip to content

The 36 GitHub security checks Black Cat runs

Black Cat SSPM evaluates 36 security policies against your GitHub configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect GitHub — what access Black Cat needs, and why.

Access control & privilege (21)

Configuration hardening (13)

Other checks (2)

severity: critical Org 2FA Not Required fix difficulty: easy #

Require two-factor authentication for all GitHub organization members

  1. Navigate to GitHub Organization Settings > Authentication security
  2. Enable 'Require two-factor authentication for everyone'
  3. Set a grace period for existing members to enable 2FA
  4. Remind members they lose access to organization resources until they enable 2FA
  5. Outside collaborators that do not comply are removed and must be re-invited after enabling 2FA

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Member Without 2FA fix difficulty: easy #

Contact GitHub organization members who have not enabled 2FA and direct them to enroll

  1. Contact the organization member to enable 2FA on their GitHub account
  2. Direct them to GitHub Settings > Password and authentication > Two-factor authentication
  3. Verify they regain access to organization resources after enabling 2FA

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial