The 27 LastPass security checks Black Cat runs
Black Cat SSPM evaluates 27 security policies against your LastPass configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect LastPass — what access Black Cat needs, and why.
Access control & privilege
13 checks · highest severity: high
Configuration hardening
11 checks · highest severity: critical
Access control & privilege (13)
- Dormant Account severity: medium
- Admin Dormant severity: high
- Never Logged In Account severity: low
- Admin Never Logged In severity: high
- Disabled Account Not Removed severity: low
- User Not Assigned to Any Group severity: low
- Disabled Account With Admin Privileges severity: high
- Recently Created Admin Account severity: medium
Configuration hardening (11)
- Weak Master Password severity: high
- Very Weak Master Password severity: critical
- Empty Vault User severity: low
- Stale Master Password severity: high
- Master Password Never Changed severity: high
- Admin Stale Master Password severity: critical
- Admin With Weak Master Password severity: critical
- Admin Master Password Never Changed severity: critical
Other checks (3)
severity: critical MFA Not Enabled fix difficulty: easy #
Enable multifactor authentication for LastPass users who have MFA disabled
- Navigate to LastPass Admin > Policies
- Enable the "Require multifactor authentication" policy
- Set an enforcement deadline for non-compliant users
- Notify affected users to enroll in MFA
- Verify compliance via the Users report after the deadline
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: critical Admin Without MFA fix difficulty: easy #
Require MFA for all LastPass admin accounts that currently have it disabled
- Navigate to LastPass Admin > Users
- Filter by admin role and identify users without MFA
- Navigate to Policies and enforce MFA requirement for admins
- Notify each admin to enroll in MFA immediately
- Suspend admin access for accounts that remain non-compliant
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Shared Folder Credential Export Permission fix difficulty: easy #
Disable the credential export (give) permission for shared folder members who do not need it
- Navigate to LastPass Admin > Shared Folders
- Open the affected shared folder
- Review members with the give permission enabled
- Disable give permission for members who do not need to export credentials
- Document which users require export capability and why
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12