GitLab identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On GitLab, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the GitLab connector needs.
Checks (4)
severity: critical Group 2FA Not Enforced fix difficulty: easy #
Enforce two-factor authentication for all members of the GitLab group
- Navigate to GitLab Group Settings > General > Permissions and group features
- Enable 'Require all users in this group to set up two-factor authentication'
- Set an appropriate grace period for existing members
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Group 2FA Grace Period Too Long fix difficulty: easy #
Reduce the GitLab group 2FA grace period to 48 hours or less
- Navigate to Group > Settings > General > Permissions
- Reduce 2FA grace period to 48 hours or less
- Save changes
- Notify members about the shorter enforcement window
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Member Without 2FA fix difficulty: easy #
Contact GitLab group members who have not enrolled in 2FA and direct them to set it up
- Contact the group member to enable 2FA on their GitLab account
- Direct them to GitLab User Settings > Account > Two-Factor Authentication
- Verify enrollment after the grace period
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: critical Group Owner Without 2FA fix difficulty: easy #
Ensure all group owners have two-factor authentication enabled immediately
- Contact the group owner to enable 2FA on their GitLab account
- Direct them to User Settings > Account > Two-Factor Authentication
- Verify enrollment within 24 hours
- Consider temporarily reducing their access level until 2FA is enabled
Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4