Skip to content

OpenAI configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On OpenAI, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenAI connector needs.

Checks (9)

severity: medium Project Without Rate Limits fix difficulty: easy #

Configure rate limits on OpenAI projects that have no usage restrictions

  1. Log in to the OpenAI platform and navigate to Projects
  2. Select the project without rate limits
  3. Navigate to the project's Settings > Limits
  4. Configure appropriate rate limits for the project
  5. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Active Project Without Users fix difficulty: easy #

Assign responsible users to active OpenAI projects that have no members or archive them

  1. Navigate to Settings > Projects
  2. Identify active project without users
  3. Determine if project is still needed
  4. Assign responsible users or archive the project

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Usage Anomaly fix difficulty: medium #

Investigate OpenAI usage anomalies and set rate limits or spending caps to prevent recurrence

  1. Log in to the OpenAI platform and navigate to Usage
  2. Review the usage pattern and identify the anomalous spike
  3. Investigate which API key or project caused the anomaly
  4. Set rate limits or spending caps to prevent future anomalies

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC5.3 CIS Controls v8 CIS-04.1 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Excessive API Request Volume fix difficulty: medium #

Implement OpenAI project-level rate limits for users with abnormally high API request volumes

  1. Navigate to Usage dashboard
  2. Identify high-usage user
  3. Review API call patterns for anomalies
  4. Contact user to understand usage
  5. Implement project-level rate limits if needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Disproportionate Output Tokens fix difficulty: medium #

Investigate OpenAI users generating disproportionate output tokens for potential data extraction

  1. Navigate to Usage dashboard
  2. Filter by the flagged user
  3. Compare input vs output token ratios
  4. Investigate potential data extraction patterns
  5. Review prompts for misconfiguration

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Usage Category Anomaly fix difficulty: medium #

Investigate OpenAI usage categories spiking far above their average

  1. Log in to the OpenAI platform and navigate to Usage
  2. Identify the usage category with the anomalous spike
  3. Investigate which project or key drove the spike
  4. Set rate limits or spending caps to prevent recurrence

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Certificate Expiring Soon fix difficulty: medium #

Renew or replace the OpenAI certificate before it expires

  1. Log in to the OpenAI platform and navigate to Organization Settings > Certificates
  2. Identify the certificate nearing expiry
  3. Upload a renewed certificate and activate it
  4. Remove the expired certificate

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Inactive Certificate fix difficulty: easy #

Activate or remove inactive OpenAI certificates so mTLS is enforced

  1. Log in to the OpenAI platform and navigate to Organization Settings > Certificates
  2. Review the inactive certificate
  3. Activate it to enforce mTLS, or remove it if no longer needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Certificate Without Project Scope fix difficulty: medium #

Scope organization-wide OpenAI certificates to specific projects

  1. Log in to the OpenAI platform and navigate to Organization Settings > Certificates
  2. Review the org-wide certificate
  3. Re-scope the certificate to only the projects that require it

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More OpenAI checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial