Datadog data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Datadog, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Datadog connector needs.
Checks (3)
severity: high Dashboard Public Sharing fix difficulty: easy #
Disable public dashboard widget sharing at the organization level
- Navigate to Organization Settings > Public Sharing
- Locate the "Enabled Sharing" toggle for public widget sharing
- Toggle it off to prevent any dashboard from being shared publicly
- Save the configuration
- Review existing shared dashboards and revoke any active public URLs
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Dashboard Public URL fix difficulty: easy #
Revoke the public URL for the flagged dashboard to prevent unauthenticated access
- Open the flagged dashboard in Datadog
- Click the Settings (gear) icon in the top-right corner of the dashboard
- Navigate to the Sharing section
- Locate the active public URL entry
- Click "Revoke" or "Delete" to invalidate the public link
- Confirm the revocation and verify the URL no longer loads the dashboard
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Dashboard Publicly Shared and Writable fix difficulty: easy #
Set publicly shared dashboards to read-only or revoke the public URL
- Open the flagged dashboard in Datadog
- Click the Settings (gear) icon in the top-right corner
- Either revoke the public URL under the Sharing section
- Or set the dashboard to read-only under the Permissions section
- Save the updated settings
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12