Skip to content

incident.io governance & compliance security checks

Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.

On incident.io, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.

Checks (7)

severity: medium Alert Source Unowned fix difficulty: easy #

Assign an owning team to every Incident.io alert source that currently has no owner

  1. Sign in to Incident.io and navigate to Alerts > Alert sources
  2. Locate the alert source flagged by this policy
  3. Click "Edit" on the alert source configuration
  4. In the ownership field, select the responsible team
  5. Save the change and confirm the alert source now displays an owning team

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Alert Route No Conditions fix difficulty: medium #

Add filtering conditions to alert routes to prevent all alerts from being handled identically

  1. Sign in to Incident.io and navigate to Alerts > Alert routes
  2. Open the alert route flagged by this policy
  3. Click "Edit" and navigate to the conditions section
  4. Add at least one condition to scope which alerts this route handles (e.g., by source, severity, or label)
  5. Save the route and review whether other routes need similar scoping to avoid overlaps
  6. Test with a sample alert to confirm conditions filter correctly

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Escalation Path No Team Assignment fix difficulty: easy #

Assign an owning team to every escalation path to establish clear accountability for on-call coverage

  1. Sign in to Incident.io and navigate to On-call > Escalation paths
  2. Open the escalation path flagged by this policy
  3. Click "Edit" and locate the team assignment field
  4. Select the team responsible for incidents routed through this path
  5. Save the change and confirm the escalation path displays its owning team
  6. Repeat for all escalation paths currently without a team assignment

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Schedule No Team Assignment fix difficulty: easy #

Assign an owning team to every on-call schedule to prevent orphaned rotations with no accountable owner

  1. Sign in to Incident.io and navigate to On-call > Schedules
  2. Open the schedule flagged by this policy
  3. Click "Edit" and locate the team assignment field
  4. Select the team that owns and operates this on-call rotation
  5. Save the change and confirm the schedule now shows an owning team
  6. Repeat for all schedules currently without a team assignment

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Active Workflow Never Updated fix difficulty: easy #

Review and update version-1 active workflows to confirm they still reflect current operational requirements

  1. Sign in to Incident.io and navigate to Workflows
  2. Open the workflow flagged by this policy
  3. Review the trigger, conditions, and steps to confirm they are still correct
  4. Make any necessary updates to bring the workflow in line with current processes
  5. Save the workflow — this will increment the version number beyond 1
  6. Document the review outcome in an internal runbook or comment field

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC8.1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Schedule Missing Timezone fix difficulty: easy #

Set an explicit timezone on every on-call schedule to ensure handoffs and notifications fire at the correct local time

  1. Sign in to Incident.io and navigate to On-call > Schedules
  2. Open the schedule flagged by this policy
  3. Click "Edit" and locate the timezone field
  4. Select the timezone that matches the primary location of the on-call team
  5. Save the change and review the schedule timeline to confirm shift times are now correct
  6. Notify affected on-call members of the updated handoff times

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Schedule No Holiday Configuration fix difficulty: easy #

Configure holiday awareness on on-call schedules so responders are not unknowingly scheduled during public holidays

  1. Sign in to Incident.io and navigate to On-call > Schedules
  2. Open the schedule flagged by this policy
  3. Click "Edit" and locate the holidays configuration section
  4. Enable holiday awareness and select the relevant country or region for your team
  5. Save the change and review upcoming holidays on the schedule timeline
  6. Communicate the holiday policy to all on-call team members

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More incident.io checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial