The 19 Workday security checks Black Cat runs
Black Cat SSPM evaluates 19 security policies against your Workday configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Workday — what access Black Cat needs, and why.
Identity, MFA & sign-in
12 checks · highest severity: critical
Access control & privilege
3 checks · highest severity: high
Identity, MFA & sign-in (12)
- Workday User Without MFA Required severity: high
- Workday Dormant User Account severity: medium
- Terminated User With Active Account severity: critical
- User Without Manager Assigned severity: low
- Weak Password Policy severity: high
- SSO Not Enabled severity: high
- MFA Not Enforced severity: critical
- Excessive Session Timeout severity: medium
- No Account Lockout Policy severity: high
- Delegated Auth Certificate Expiring Soon severity: high
- Delegated Auth Allows Local Fallback severity: medium
- Account Lockout Duration Too Short severity: medium
Access control & privilege (3)
- Security Group With Excessive Members severity: medium
- Empty Security Group severity: low
- Security Group With Broad Domain Access severity: high
Other checks (4)
severity: critical Audit Logging Disabled fix difficulty: easy #
Enable user activity logging for the tenant
- Navigate to Workday > Tenant Setup > Security
- Enable 'User Activity Logging'
- Configure log retention as required by your compliance policy
Satisfies: ISO 27001:2022 A.8.15 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1
severity: medium No IP Restrictions Configured fix difficulty: medium #
Configure trusted IP ranges to restrict Workday access
- Identify your corporate IP ranges and VPN exit points
- Navigate to Workday > Tenant Setup > Security
- Add trusted IP ranges
- Test access before enforcing restrictions
Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9
severity: medium Stale Integration System fix difficulty: easy #
Review and disable unused integrations
- Check if the integration is still needed
- If unused, set the integration to Inactive
- Revoke any associated credentials
Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12
severity: medium Integration With Excessive Scope fix difficulty: medium #
Reduce integration functional areas to minimum required
- Review the integration's functional area assignments
- Remove areas not required for the integration's purpose
Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.3 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12