Skip to content

Grafana data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Grafana, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Grafana connector needs.

Checks (3)

severity: medium Overly Permissive Dashboard fix difficulty: easy #

Restrict dashboard permissions to specific roles or teams rather than granting broad access

  1. Sign in to Grafana as an Org Admin or dashboard owner
  2. Open the dashboard in question
  3. Click the share/settings icon and navigate to the Permissions tab
  4. Remove or tighten any entries granting "Everyone" or broad role-level Edit/Admin permissions
  5. Add specific team or user permissions with the minimum required role (Viewer for consumers, Editor only when needed)
  6. Save the permission changes and verify access is correctly scoped

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Public Dashboard fix difficulty: easy #

Disable public sharing on the dashboard to require authentication for access

  1. Sign in to Grafana as an Org Admin or dashboard owner
  2. Open the flagged dashboard
  3. Click the Share icon in the top toolbar
  4. Select the "Public dashboard" tab
  5. Toggle "Public dashboard" to Off (disabled)
  6. Confirm the change; the public URL will immediately stop serving data

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Overly Permissive Folder fix difficulty: easy #

Restrict folder permissions to specific roles or teams instead of broad organization-wide access

  1. Sign in to Grafana as an Org Admin
  2. Navigate to Dashboards > Browse in the left sidebar
  3. Locate the flagged folder and click its settings (gear icon)
  4. Open the Permissions tab
  5. Remove or narrow any entries granting "Everyone" or broad role-level Edit/Admin access
  6. Add explicit team or user entries with the minimum required role
  7. Save changes and verify that only intended users can access the folder contents

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More Grafana checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial