Slack governance & compliance security checks
Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.
On Slack, Black Cat runs 13 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Slack connector needs.
Checks (13)
severity: low Message Edit Unrestricted fix difficulty: easy #
Set a time limit on how long members can edit messages
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Message editing and deletion", find the editing time window
- Select a limited editing window (e.g., 5 minutes or 30 minutes)
- Click "Save" to enforce the message edit restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Slackbot Responses Unrestricted fix difficulty: easy #
Restrict Slackbot custom response creation to workspace admins
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to Customize Slack (accessible via the workspace name menu)
- Select the "Slackbot" tab
- Under "Who can add and edit custom responses", select "Admins only"
- Save the setting to prevent members from adding custom responses
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Everyone Notify General fix difficulty: easy #
Restrict @channel and @everyone mentions in
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Channel posting", locate the
- Set "Who can post to
- Click "Save" to restrict the broadcast notification capability
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Archive Channel Unrestricted fix difficulty: easy #
Restrict channel archiving to workspace admins only
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Channel management", find "Who can archive channels"
- Set this to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Remove Public Channel Unrestricted fix difficulty: easy #
Restrict deletion of public channels to workspace admins only
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Channel management", find "Who can delete public channels"
- Set this to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Workflow Creation Unrestricted fix difficulty: easy #
Restrict Workflow Builder creation to workspace admins only
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Workflow Builder", find the creation permission setting
- Set "Who can create workflows" to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Remove Private Channel Unrestricted fix difficulty: easy #
Restrict deletion of private channels to workspace admins only
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Channel management", find "Who can delete private channels"
- Set this to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low User Groups Unrestricted fix difficulty: easy #
Restrict user group creation and management to workspace admins
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "User groups", find the creation permission setting
- Set "Who can create and manage user groups" to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Notify Channel Unrestricted fix difficulty: easy #
Restrict @channel and @here usage to workspace admins
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Notifications", find "@channel and @here" usage restrictions
- Set "Who can use @channel and @here" to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Display Name Not Validated fix difficulty: easy #
Require members to use their real (full) names as display names
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Settings
- Under "Display name", find the name format setting
- Enable "Require members to use their real names"
- Click "Save" to enforce the display name policy
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Default Channels Excessive fix difficulty: easy #
Reduce default channels to only the essential ones for new members
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Settings
- Under "Default channels", review the list of channels new members auto-join
- Remove non-essential channels, keeping only
- Click "Save" to update the default channel list
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Inactive Channel fix difficulty: easy #
Archive inactive channels with no recent activity
- Navigate to the inactive channel in Slack
- Click the channel name at the top to open channel details
- Select "Settings" or the gear icon and choose "Archive channel"
- Confirm the archival; the channel will be preserved for search but inactive
- Alternatively, an admin can archive channels in bulk via admin settings > Manage Channels
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low App No Description fix difficulty: easy #
Ensure all installed apps have descriptive names and documented purpose
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Manage Apps
- Locate the flagged app with a missing or inadequate description
- Review the app's permissions and determine if it is still needed
- If the app is unrecognised or undocumented, click "Revoke" or "Remove" to uninstall it
- If the app is legitimate, update its configuration or internal documentation to record its purpose
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4