Skip to content

The 27 OVH Cloud security checks Black Cat runs

Black Cat SSPM evaluates 27 security policies against your OVH Cloud configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect OVH Cloud — what access Black Cat needs, and why.

Access control & privilege (17)

Configuration hardening (7)

Other checks (3)

severity: critical Storage Container Public fix difficulty: medium #

Set the Object Storage container to private to prevent unauthenticated public access

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Public Cloud > Storage > Object Storage and select the flagged container
  3. Click "Edit container" or the container settings icon
  4. Change the container visibility from "Public" to "Private"
  5. Save the change and verify that unauthenticated access to the container URL is denied
  6. Update any application or CDN configuration that relied on public container access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Instance Has Public IP fix difficulty: hard #

Remove public IP from the instance and route access through a private network or bastion host

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Public Cloud > Compute > Instances and select the flagged instance
  3. Review the instance's network interfaces and detach the public IP address
  4. Ensure the instance is connected to a private vRack network for internal communication
  5. Set up a bastion host or VPN gateway for administrative access if needed
  6. Validate that all required services are accessible through the private network

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: high API Credential No IP Restriction fix difficulty: easy #

Add IP restrictions to API credentials to limit access to known source addresses

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Account > Security > API Credentials
  3. Select the credential flagged as having no IP restriction
  4. Click "Edit" and add the IP addresses or CIDR ranges that should be allowed to use this credential
  5. Save the changes and verify the credential still works from your expected source IPs
  6. Test that requests from non-allowed IPs are rejected

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial