OpenAI configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On OpenAI, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenAI connector needs.
Checks (9)
severity: medium Project Without Rate Limits fix difficulty: easy #
Configure rate limits on OpenAI projects that have no usage restrictions
- Log in to the OpenAI platform and navigate to Projects
- Select the project without rate limits
- Navigate to the project's Settings > Limits
- Configure appropriate rate limits for the project
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Active Project Without Users fix difficulty: easy #
Assign responsible users to active OpenAI projects that have no members or archive them
- Navigate to Settings > Projects
- Identify active project without users
- Determine if project is still needed
- Assign responsible users or archive the project
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Usage Anomaly fix difficulty: medium #
Investigate OpenAI usage anomalies and set rate limits or spending caps to prevent recurrence
- Log in to the OpenAI platform and navigate to Usage
- Review the usage pattern and identify the anomalous spike
- Investigate which API key or project caused the anomaly
- Set rate limits or spending caps to prevent future anomalies
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC5.3 CIS Controls v8 CIS-04.1 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Excessive API Request Volume fix difficulty: medium #
Implement OpenAI project-level rate limits for users with abnormally high API request volumes
- Navigate to Usage dashboard
- Identify high-usage user
- Review API call patterns for anomalies
- Contact user to understand usage
- Implement project-level rate limits if needed
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Disproportionate Output Tokens fix difficulty: medium #
Investigate OpenAI users generating disproportionate output tokens for potential data extraction
- Navigate to Usage dashboard
- Filter by the flagged user
- Compare input vs output token ratios
- Investigate potential data extraction patterns
- Review prompts for misconfiguration
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Usage Category Anomaly fix difficulty: medium #
Investigate OpenAI usage categories spiking far above their average
- Log in to the OpenAI platform and navigate to Usage
- Identify the usage category with the anomalous spike
- Investigate which project or key drove the spike
- Set rate limits or spending caps to prevent recurrence
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Certificate Expiring Soon fix difficulty: medium #
Renew or replace the OpenAI certificate before it expires
- Log in to the OpenAI platform and navigate to Organization Settings > Certificates
- Identify the certificate nearing expiry
- Upload a renewed certificate and activate it
- Remove the expired certificate
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Inactive Certificate fix difficulty: easy #
Activate or remove inactive OpenAI certificates so mTLS is enforced
- Log in to the OpenAI platform and navigate to Organization Settings > Certificates
- Review the inactive certificate
- Activate it to enforce mTLS, or remove it if no longer needed
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Certificate Without Project Scope fix difficulty: medium #
Scope organization-wide OpenAI certificates to specific projects
- Log in to the OpenAI platform and navigate to Organization Settings > Certificates
- Review the org-wide certificate
- Re-scope the certificate to only the projects that require it
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10