The 31 Zoom security checks Black Cat runs
Black Cat SSPM evaluates 31 security policies against your Zoom configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Zoom — what access Black Cat needs, and why.
Access control & privilege
8 checks · highest severity: high
Configuration hardening
20 checks · highest severity: high
Access control & privilege (8)
- Inactive User severity: medium
- Excessive Admins severity: medium
- SSO Not Enforced severity: high
- Encryption Not Required For Third-Party Endpoints severity: high
- Password Embedded In Join Link severity: high
- Join Before Host Allowed severity: medium
- No Password For Instant Meetings severity: high
- No Password For PMI Meetings severity: high
Configuration hardening (20)
- No Meeting Password Required severity: high
- Waiting Room Disabled severity: medium
- Unauthenticated Join Allowed severity: medium
- Local Recording Enabled severity: medium
- Cloud Recording No Auto-Delete severity: low
- Weak Password Policy severity: high
- Chat File Transfer Enabled severity: low
- Automatic Recording Enabled severity: medium
- Auto Save Meeting Chats severity: low
- Continuous Meeting Chat Enabled severity: low
- Email Notification On Join Before Host Disabled severity: low
- Far End Camera Control Enabled severity: medium
- Host Video On By Default severity: low
- Guest Participant Identification Disabled severity: medium
- Participant Video On By Default severity: low
- Join/Leave Sound Disabled severity: low
- Remote Control Enabled severity: medium
- Request To Unmute Not Required severity: low
- Screen Sharing Allowed For All Participants severity: medium
Other checks (3)
severity: high User Without MFA fix difficulty: easy #
Enable two-factor authentication for the user in Zoom User Management
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to User Management > Users
- Select the affected user and open their profile
- Go to Settings > Security
- Enable Two-factor Authentication and save
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: critical Admin Without MFA fix difficulty: easy #
Immediately enable two-factor authentication for the admin account in Zoom User Management
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to User Management > Users
- Locate the admin account and open their profile
- Go to Settings > Security
- Enable Two-factor Authentication and save
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Live Streaming Enabled fix difficulty: easy #
Disable meeting live streaming to external platforms unless required
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Account Management > Account Settings > In Meeting (Advanced)
- Disable the Allow live streaming meetings toggle
- Save changes
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12