Skip to content

The 31 Zoom security checks Black Cat runs

Black Cat SSPM evaluates 31 security policies against your Zoom configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Zoom — what access Black Cat needs, and why.

Access control & privilege (8)

Configuration hardening (20)

Other checks (3)

severity: high User Without MFA fix difficulty: easy #

Enable two-factor authentication for the user in Zoom User Management

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to User Management > Users
  3. Select the affected user and open their profile
  4. Go to Settings > Security
  5. Enable Two-factor Authentication and save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: critical Admin Without MFA fix difficulty: easy #

Immediately enable two-factor authentication for the admin account in Zoom User Management

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to User Management > Users
  3. Locate the admin account and open their profile
  4. Go to Settings > Security
  5. Enable Two-factor Authentication and save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Live Streaming Enabled fix difficulty: easy #

Disable meeting live streaming to external platforms unless required

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > In Meeting (Advanced)
  3. Disable the Allow live streaming meetings toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial