Skip to content

The 29 Terraform Cloud security checks Black Cat runs

Black Cat SSPM evaluates 29 security policies against your Terraform Cloud configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Terraform Cloud — what access Black Cat needs, and why.

Access control & privilege (12)

Encryption, keys & secrets (3)

Configuration hardening (11)

Other checks (3)

severity: critical Workspace Global Remote State fix difficulty: medium #

Restrict remote state sharing to specific workspaces instead of all workspaces

  1. Log in to Terraform Cloud and open the workspace
  2. Navigate to Settings > Remote state sharing
  3. Disable "Share state globally"
  4. Add only the specific workspaces that need access to this workspace's state
  5. Save the setting

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Workspace Auto Apply Enabled fix difficulty: easy #

Disable auto-apply to require manual approval before infrastructure changes are applied

  1. Log in to Terraform Cloud and open the workspace
  2. Navigate to Settings > General
  3. Under "Apply method", select "Manual apply"
  4. Save the setting; future plans will require explicit confirmation before applying

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.e.1 DORA (SaaS Security) DORA-9.10

severity: medium Workspace Destroy Plan Allowed fix difficulty: easy #

Disable destroy plan permission to prevent accidental infrastructure deletion

  1. Log in to Terraform Cloud and open the workspace
  2. Navigate to Settings > Destruction and Deletion
  3. Disable "Allow destroy plans"
  4. Save the setting; destroy plans will require this setting to be re-enabled first

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.e.1 DORA (SaaS Security) DORA-9.10

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial