Grafana data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Grafana, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Grafana connector needs.
Checks (3)
severity: medium Overly Permissive Dashboard fix difficulty: easy #
Restrict dashboard permissions to specific roles or teams rather than granting broad access
- Sign in to Grafana as an Org Admin or dashboard owner
- Open the dashboard in question
- Click the share/settings icon and navigate to the Permissions tab
- Remove or tighten any entries granting "Everyone" or broad role-level Edit/Admin permissions
- Add specific team or user permissions with the minimum required role (Viewer for consumers, Editor only when needed)
- Save the permission changes and verify access is correctly scoped
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Public Dashboard fix difficulty: easy #
Disable public sharing on the dashboard to require authentication for access
- Sign in to Grafana as an Org Admin or dashboard owner
- Open the flagged dashboard
- Click the Share icon in the top toolbar
- Select the "Public dashboard" tab
- Toggle "Public dashboard" to Off (disabled)
- Confirm the change; the public URL will immediately stop serving data
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Overly Permissive Folder fix difficulty: easy #
Restrict folder permissions to specific roles or teams instead of broad organization-wide access
- Sign in to Grafana as an Org Admin
- Navigate to Dashboards > Browse in the left sidebar
- Locate the flagged folder and click its settings (gear icon)
- Open the Permissions tab
- Remove or narrow any entries granting "Everyone" or broad role-level Edit/Admin access
- Add explicit team or user entries with the minimum required role
- Save changes and verify that only intended users can access the folder contents
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12