Notion configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Notion, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Notion connector needs.
Checks (3)
severity: medium Stale Page fix difficulty: easy #
Review and archive or delete pages that have not been edited in over 180 days
- Open the flagged Notion page
- Review the content to determine if it is still relevant
- If outdated, move the page to an Archive section or delete it
- If still relevant, update the content and last-edited timestamp
- Consider establishing a periodic content review process
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Orphaned Page Without Parent fix difficulty: easy #
Investigate orphaned pages without a parent and move or delete them
- Locate the flagged page in Notion
- Determine if the page was accidentally disconnected from its parent
- Move the page to an appropriate parent page or section
- If the page is no longer needed, archive or delete it
- Review workspace structure to prevent future orphaned content
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Stale Database fix difficulty: easy #
Review and archive or delete databases that have not been edited in over 180 days
- Open the flagged Notion database
- Review the content and determine if it is still actively used
- If outdated, move the database to an Archive section or delete it
- If still relevant, update the content and verify the data is current
- Consider establishing a periodic database review process
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10