The 29 OpenAI security checks Black Cat runs
Black Cat SSPM evaluates 29 security policies against your OpenAI configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect OpenAI — what access Black Cat needs, and why.
Access control & privilege
19 checks · highest severity: high
Configuration hardening
9 checks · highest severity: high
Access control & privilege (19)
- Stale API Key severity: high
- API Key Non-User Owner severity: medium
- Admin Key Sprawl severity: medium
- Stale Admin Key severity: high
- Admin Key Non-User Owner severity: high
- Excessive Organization Owners severity: medium
- Owner Redundancy Missing severity: high
- Disabled User Not Removed severity: low
- Excessive Service Accounts severity: low
- Excessive Project API Keys severity: medium
- Project With Only Service Accounts severity: medium
- Orphaned Service Account severity: low
- Stale Service Account severity: medium
- Empty Group severity: low
- Group Not SCIM-Managed severity: medium
- Stale Expired Invite severity: low
- Invite Grants Owner Role severity: high
- Stale Pending Invite severity: low
- Overpermissive Custom Role severity: medium
Configuration hardening (9)
- Project Without Rate Limits severity: medium
- Active Project Without Users severity: medium
- Usage Anomaly severity: medium
- Excessive API Request Volume severity: medium
- Disproportionate Output Tokens severity: low
- Usage Category Anomaly severity: medium
- Certificate Expiring Soon severity: high
- Inactive Certificate severity: medium
- Certificate Without Project Scope severity: low
Other checks (1)
severity: info Sensitive Audit Event fix difficulty: medium #
Investigate sensitive OpenAI audit events and revoke access if the action was unauthorized
- Log in to the OpenAI platform and review the audit log event
- Investigate the sensitive action and verify it was authorized
- If unauthorized, revoke the user's access and rotate any affected credentials
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC5.3 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1