The 15 PingOne security checks Black Cat runs
Black Cat SSPM evaluates 15 security policies against your PingOne configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
authentication
Require MFA in the PingOne sign-on (authentication) policy
Require MFA in the environment-default PingOne sign-on policy
identity
Remove or review disabled PingOne accounts that remain provisioned
Disable or remove PingOne accounts that have never signed on or are long-inactive
Review or remove PingOne groups with no members
mfa
Enforce MFA enrollment for PingOne users
Enable MFA at the PingOne environment level
oauth
Remove implicit and ROPC (password) grant types from PingOne applications
Require client authentication on confidential PingOne applications
Replace wildcard and insecure redirect URIs with exact HTTPS URIs
Remove stale disabled PingOne application registrations
password policy
Strengthen the PingOne password policy minimum length
Enable password history to prevent reuse in PingOne
Review password expiry settings against your password rotation policy
Require multiple character classes in the PingOne password policy