incident.io governance & compliance security checks
Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.
On incident.io, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.
Checks (7)
severity: medium Alert Source Unowned fix difficulty: easy #
Assign an owning team to every Incident.io alert source that currently has no owner
- Sign in to Incident.io and navigate to Alerts > Alert sources
- Locate the alert source flagged by this policy
- Click "Edit" on the alert source configuration
- In the ownership field, select the responsible team
- Save the change and confirm the alert source now displays an owning team
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Alert Route No Conditions fix difficulty: medium #
Add filtering conditions to alert routes to prevent all alerts from being handled identically
- Sign in to Incident.io and navigate to Alerts > Alert routes
- Open the alert route flagged by this policy
- Click "Edit" and navigate to the conditions section
- Add at least one condition to scope which alerts this route handles (e.g., by source, severity, or label)
- Save the route and review whether other routes need similar scoping to avoid overlaps
- Test with a sample alert to confirm conditions filter correctly
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Escalation Path No Team Assignment fix difficulty: easy #
Assign an owning team to every escalation path to establish clear accountability for on-call coverage
- Sign in to Incident.io and navigate to On-call > Escalation paths
- Open the escalation path flagged by this policy
- Click "Edit" and locate the team assignment field
- Select the team responsible for incidents routed through this path
- Save the change and confirm the escalation path displays its owning team
- Repeat for all escalation paths currently without a team assignment
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Schedule No Team Assignment fix difficulty: easy #
Assign an owning team to every on-call schedule to prevent orphaned rotations with no accountable owner
- Sign in to Incident.io and navigate to On-call > Schedules
- Open the schedule flagged by this policy
- Click "Edit" and locate the team assignment field
- Select the team that owns and operates this on-call rotation
- Save the change and confirm the schedule now shows an owning team
- Repeat for all schedules currently without a team assignment
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Active Workflow Never Updated fix difficulty: easy #
Review and update version-1 active workflows to confirm they still reflect current operational requirements
- Sign in to Incident.io and navigate to Workflows
- Open the workflow flagged by this policy
- Review the trigger, conditions, and steps to confirm they are still correct
- Make any necessary updates to bring the workflow in line with current processes
- Save the workflow — this will increment the version number beyond 1
- Document the review outcome in an internal runbook or comment field
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC8.1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Schedule Missing Timezone fix difficulty: easy #
Set an explicit timezone on every on-call schedule to ensure handoffs and notifications fire at the correct local time
- Sign in to Incident.io and navigate to On-call > Schedules
- Open the schedule flagged by this policy
- Click "Edit" and locate the timezone field
- Select the timezone that matches the primary location of the on-call team
- Save the change and review the schedule timeline to confirm shift times are now correct
- Notify affected on-call members of the updated handoff times
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Schedule No Holiday Configuration fix difficulty: easy #
Configure holiday awareness on on-call schedules so responders are not unknowingly scheduled during public holidays
- Sign in to Incident.io and navigate to On-call > Schedules
- Open the schedule flagged by this policy
- Click "Edit" and locate the holidays configuration section
- Enable holiday awareness and select the relevant country or region for your team
- Save the change and review upcoming holidays on the schedule timeline
- Communicate the holiday policy to all on-call team members
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4