Skip to content

The 19 Workday security checks Black Cat runs

Black Cat SSPM evaluates 19 security policies against your Workday configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Workday — what access Black Cat needs, and why.

Identity, MFA & sign-in (12)

Access control & privilege (3)

Other checks (4)

severity: critical Audit Logging Disabled fix difficulty: easy #

Enable user activity logging for the tenant

  1. Navigate to Workday > Tenant Setup > Security
  2. Enable 'User Activity Logging'
  3. Configure log retention as required by your compliance policy

Satisfies: ISO 27001:2022 A.8.15 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: medium No IP Restrictions Configured fix difficulty: medium #

Configure trusted IP ranges to restrict Workday access

  1. Identify your corporate IP ranges and VPN exit points
  2. Navigate to Workday > Tenant Setup > Security
  3. Add trusted IP ranges
  4. Test access before enforcing restrictions

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: medium Stale Integration System fix difficulty: easy #

Review and disable unused integrations

  1. Check if the integration is still needed
  2. If unused, set the integration to Inactive
  3. Revoke any associated credentials

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

severity: medium Integration With Excessive Scope fix difficulty: medium #

Reduce integration functional areas to minimum required

  1. Review the integration's functional area assignments
  2. Remove areas not required for the integration's purpose

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.3 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial