Skip to content

The 27 Sentry security checks Black Cat runs

Black Cat SSPM evaluates 27 security policies against your Sentry configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Sentry — what access Black Cat needs, and why.

Access control & privilege (18)

Data sharing & exposure (7)

Other checks (2)

severity: high Member Without 2FA fix difficulty: easy #

Require all active members to enroll in two-factor authentication

  1. Sign in to Sentry as an organization owner or admin
  2. Navigate to Settings > Security (https://sentry.io/organizations/<org>/settings/security/)
  3. Enable "Require Two-Factor Authentication" to enforce 2FA for all members
  4. Notify affected members to set up an authenticator app or hardware key before the deadline
  5. Members without 2FA will be locked out until they complete enrollment
  6. Verify enrollment status in Settings > Members after the enforcement deadline

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: critical Admin Without 2FA fix difficulty: easy #

Immediately enforce two-factor authentication on all admin-level accounts

  1. Sign in to Sentry as an organization owner
  2. Navigate to Settings > Members (https://sentry.io/organizations/<org>/settings/members/)
  3. Identify all admin, manager, and owner accounts lacking 2FA
  4. Contact each affected admin directly and require 2FA enrollment before next login
  5. Enable "Require Two-Factor Authentication" in Settings > Security to prevent future gaps
  6. Consider temporarily downgrading admins who cannot enroll promptly until 2FA is active

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial