Anthropic configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Anthropic, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.
Checks (7)
severity: low Archived Workspace Not Deleted fix difficulty: easy #
Delete archived Anthropic workspaces that are no longer needed
- Navigate to Console > Workspaces
- Find the archived workspace
- Review if any API keys still reference this workspace
- Delete the workspace if confirmed no longer needed
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Stale Workspace fix difficulty: medium #
Archive or clean up Anthropic workspaces showing no recent activity
- Navigate to Console > Workspaces
- Find old workspace
- Review recent API key usage and member activity
- Archive if inactive or document continued use
- Clean up unused API keys within
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Usage Spike Detected fix difficulty: medium #
Investigate Anthropic usage spikes exceeding 3x the average token consumption
- Navigate to Anthropic Console > Usage
- Review token usage for the affected workspace and model
- Identify the source of increased usage
- Adjust rate limits or API keys if unauthorized usage is detected
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Workspace Default Rate Limits fix difficulty: medium #
Configure custom rate limits for Anthropic workspaces instead of inheriting organization defaults
- Navigate to Anthropic Console > Workspaces
- Select the affected workspace
- Configure custom rate limits appropriate for the workspace usage
- Save the rate limit configuration
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Web Search Tool Usage fix difficulty: medium #
Review API usage that includes web search tool requests to ensure prompts are not exposing sensitive data
- Navigate to Anthropic Console > Usage
- Identify API keys and workspaces generating web search requests
- Review whether web search tool usage is authorized
- Disable web search tool access if not required
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Claude Code High Session Count fix difficulty: easy #
Review users with unusually high Claude Code session counts to verify authorized usage
- Navigate to Anthropic Console > Usage > Claude Code
- Review the user's session activity
- Verify the session count aligns with expected usage
- Consider workspace scoping or rate limiting if usage is excessive
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Rate Limit High Requests Per Minute fix difficulty: medium #
Review and reduce overly permissive Anthropic rate limits exceeding 4000 requests per minute
- Navigate to Anthropic Console > Workspaces or Organization settings
- Review the rate limit configuration for the affected scope
- Reduce requests_per_minute to an appropriate level
- Monitor usage to ensure the new limit is sufficient
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10