Skip to content

The 39 Salesforce security checks Black Cat runs

Black Cat SSPM evaluates 39 security policies against your Salesforce configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Salesforce — what access Black Cat needs, and why.

Identity, MFA & sign-in (15)

Access control & privilege (21)

Other checks (3)

severity: high Public Sharing Model fix difficulty: medium #

Restrict org-wide default sharing to Private or Public Read Only for sensitive objects

  1. Go to Setup > Security > Sharing Settings
  2. In the "Organization-Wide Defaults" table, locate the flagged object
  3. Click "Edit" next to the object
  4. Change the "Default Internal Access" from "Public Read/Write" to "Private" or "Public Read Only"
  5. Click "Save" — Salesforce will recalculate sharing rules, which may take time for large orgs
  6. Review and update any sharing rules under Setup > Security > Sharing Settings to grant access where legitimately needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: critical External Access Read Write fix difficulty: medium #

Restrict external (community/guest) access for objects currently set to Read/Write to prevent unauthorized CRM data modification

  1. Go to Setup > Security > Sharing Settings
  2. In the "Organization-Wide Defaults" table, locate the flagged object
  3. Click "Edit" next to the object
  4. Change the "Default External Access" from "Public Read/Write" to "Private" or "Public Read Only"
  5. Click "Save" — sharing rule recalculation may take time for large orgs
  6. Review Experience Cloud site sharing rules and guest user profiles to ensure community users retain only the minimum required access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low Unused Permission Set fix difficulty: easy #

Delete or archive permission sets with no assignees to reduce configuration sprawl

  1. Go to Setup > Users > Permission Sets
  2. Click the flagged permission set
  3. Verify no users are assigned under "Manage Assignments"
  4. If the permission set is no longer needed, click "Delete"
  5. Document any permission sets retained for future use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial