Skip to content

The 27 Grafana Cloud security checks Black Cat runs

Black Cat SSPM evaluates 27 security policies against your Grafana Cloud configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Grafana Cloud — what access Black Cat needs, and why.

Access control & privilege (16)

Encryption, keys & secrets (8)

Other checks (3)

severity: medium Token Expiring Within 14 Days fix difficulty: easy #

Rotate the token before it expires to avoid service disruption

  1. Navigate to grafana.com/orgs/<org>/access-policies
  2. Locate the access policy associated with the expiring token
  3. Create a new token under the same access policy with an appropriate expiration
  4. Update the consuming service to use the new token
  5. Verify the service is functioning with the new token
  6. The old token will auto-expire on its expiration date

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Stale Access Policy Not Updated in 180 Days fix difficulty: easy #

Review the access policy to ensure its scopes and realms still match current requirements

  1. Navigate to grafana.com/orgs/<org>/access-policies
  2. Locate the policy that has not been updated in over 180 days
  3. Review its scopes and remove any that are no longer needed
  4. Verify realm bindings still match the intended stack targets
  5. If the policy is no longer needed, delete it and revoke associated tokens
  6. Update the policy description to reflect its current purpose

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: info Access Policy Without Display Name fix difficulty: easy #

Add a descriptive display name to the access policy for operational clarity

  1. Navigate to grafana.com/orgs/<org>/access-policies
  2. Locate the policy with no display name set
  3. Click Edit on the policy
  4. Enter a clear, descriptive display name reflecting the policy's purpose
  5. Save the policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC8.1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial