Skip to content

Slack governance & compliance security checks

Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.

On Slack, Black Cat runs 13 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Slack connector needs.

Checks (13)

severity: low Message Edit Unrestricted fix difficulty: easy #

Set a time limit on how long members can edit messages

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Message editing and deletion", find the editing time window
  4. Select a limited editing window (e.g., 5 minutes or 30 minutes)
  5. Click "Save" to enforce the message edit restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Slackbot Responses Unrestricted fix difficulty: easy #

Restrict Slackbot custom response creation to workspace admins

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to Customize Slack (accessible via the workspace name menu)
  3. Select the "Slackbot" tab
  4. Under "Who can add and edit custom responses", select "Admins only"
  5. Save the setting to prevent members from adding custom responses

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Everyone Notify General fix difficulty: easy #

Restrict @channel and @everyone mentions in

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Channel posting", locate the
  4. Set "Who can post to
  5. Click "Save" to restrict the broadcast notification capability

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Archive Channel Unrestricted fix difficulty: easy #

Restrict channel archiving to workspace admins only

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Channel management", find "Who can archive channels"
  4. Set this to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Remove Public Channel Unrestricted fix difficulty: easy #

Restrict deletion of public channels to workspace admins only

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Channel management", find "Who can delete public channels"
  4. Set this to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Workflow Creation Unrestricted fix difficulty: easy #

Restrict Workflow Builder creation to workspace admins only

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Workflow Builder", find the creation permission setting
  4. Set "Who can create workflows" to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Remove Private Channel Unrestricted fix difficulty: easy #

Restrict deletion of private channels to workspace admins only

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Channel management", find "Who can delete private channels"
  4. Set this to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low User Groups Unrestricted fix difficulty: easy #

Restrict user group creation and management to workspace admins

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "User groups", find the creation permission setting
  4. Set "Who can create and manage user groups" to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Notify Channel Unrestricted fix difficulty: easy #

Restrict @channel and @here usage to workspace admins

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Notifications", find "@channel and @here" usage restrictions
  4. Set "Who can use @channel and @here" to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Display Name Not Validated fix difficulty: easy #

Require members to use their real (full) names as display names

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Settings
  3. Under "Display name", find the name format setting
  4. Enable "Require members to use their real names"
  5. Click "Save" to enforce the display name policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Default Channels Excessive fix difficulty: easy #

Reduce default channels to only the essential ones for new members

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Settings
  3. Under "Default channels", review the list of channels new members auto-join
  4. Remove non-essential channels, keeping only
  5. Click "Save" to update the default channel list

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Inactive Channel fix difficulty: easy #

Archive inactive channels with no recent activity

  1. Navigate to the inactive channel in Slack
  2. Click the channel name at the top to open channel details
  3. Select "Settings" or the gear icon and choose "Archive channel"
  4. Confirm the archival; the channel will be preserved for search but inactive
  5. Alternatively, an admin can archive channels in bulk via admin settings > Manage Channels

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low App No Description fix difficulty: easy #

Ensure all installed apps have descriptive names and documented purpose

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Manage Apps
  3. Locate the flagged app with a missing or inadequate description
  4. Review the app's permissions and determine if it is still needed
  5. If the app is unrecognised or undocumented, click "Revoke" or "Remove" to uninstall it
  6. If the app is legitimate, update its configuration or internal documentation to record its purpose

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More Slack checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial