Skip to content

incident.io logging & audit security checks

Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.

On incident.io, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.

Checks (11)

severity: high Single Responder Escalation fix difficulty: medium #

Add additional responders to each escalation path node to remove single points of failure

  1. Sign in to Incident.io and navigate to On-call > Escalation paths
  2. Open the escalation path flagged by this policy
  3. Locate any node that contains only a single responder
  4. Click edit on that node and add at least one additional responder or schedule
  5. Save the escalation path and verify all nodes have multiple coverage options

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Single Rotation Schedule fix difficulty: medium #

Add at least one additional rotation to on-call schedules that have only a single rotation

  1. Sign in to Incident.io and navigate to On-call > Schedules
  2. Open the schedule flagged by this policy
  3. Click "Add rotation" to create a second rotation
  4. Configure responders, handoff times, and coverage hours for the new rotation
  5. Save the schedule and confirm at least two rotations are active

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: high Schedule Without Active Shift fix difficulty: medium #

Ensure every on-call schedule has at least one active shift to maintain continuous incident coverage

  1. Sign in to Incident.io and navigate to On-call > Schedules
  2. Open the schedule flagged by this policy
  3. Review the schedule timeline to identify gaps in shift coverage
  4. Assign responders or extend existing rotations to cover the gap
  5. Save the schedule and verify the current time falls within an active shift

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Workflow Disabled or Error fix difficulty: medium #

Fix or remove Incident.io workflows that are in a disabled or error state

  1. Sign in to Incident.io and navigate to Workflows
  2. Filter by status to locate workflows in a disabled or error state
  3. Open the affected workflow and review any error messages shown
  4. Correct the misconfiguration (e.g., invalid action, missing integration) or remove the workflow if obsolete
  5. Re-enable the workflow and confirm it transitions to an active state

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: low Workflow Ignores Step Errors fix difficulty: easy #

Disable continue-on-step-error in Incident.io workflow settings to ensure reliable workflow execution

  1. Sign in to Incident.io and navigate to Workflows
  2. Open the workflow flagged by this policy
  3. Click "Edit" and locate the error-handling or advanced settings section
  4. Disable the "continue on step error" option
  5. Save the workflow and verify that step failures will now halt execution for investigation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: low Alert Source No Auto-Resolve fix difficulty: easy #

Enable auto-resolve on Incident.io alert sources to prevent alerts from remaining open indefinitely

  1. Sign in to Incident.io and navigate to Alerts > Alert sources
  2. Locate the alert source flagged by this policy
  3. Click "Edit" on the alert source configuration
  4. Enable the "auto-resolve" option and set an appropriate resolution timeout
  5. Save the change and confirm auto-resolve is active for the alert source

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: high Alert Route No Escalation Path fix difficulty: easy #

Attach an escalation path to every alert route so that triggered alerts reach on-call responders

  1. Sign in to Incident.io and navigate to Alerts > Alert routes
  2. Open the alert route flagged by this policy
  3. Click "Edit" and locate the escalation path field
  4. Select an appropriate escalation path from the dropdown
  5. Save the change and verify the route now shows an escalation path
  6. Trigger a test alert to confirm the escalation path is invoked correctly

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: low Alert Route No Grouping fix difficulty: easy #

Configure alert grouping on alert routes to reduce noise during alert storms

  1. Sign in to Incident.io and navigate to Alerts > Alert routes
  2. Open the alert route flagged by this policy
  3. Click "Edit" and locate the grouping configuration section
  4. Enable grouping and select the field(s) to group by (e.g., alert source, labels)
  5. Set an appropriate grouping window (e.g., 5 minutes)
  6. Save the route and monitor alert volume to confirm grouping reduces individual pages

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: high Escalation Path No Current Responders fix difficulty: medium #

Ensure every escalation path has at least one active responder so that incidents are never silently dropped

  1. Sign in to Incident.io and navigate to On-call > Escalation paths
  2. Open the escalation path flagged by this policy
  3. Review each node in the path for assigned responders or schedules
  4. Add at least one active responder or link a schedule that currently has coverage
  5. If the path is unused, consider archiving or deleting it to avoid confusion
  6. Save the changes and verify the path shows at least one current responder

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Alert Source Auto-Resolve Timeout Too Long fix difficulty: easy #

Reduce the auto-resolve timeout on alert sources that exceed 24 hours to prevent stale alerts lingering unresolved

  1. Sign in to Incident.io and navigate to Alerts > Alert sources
  2. Open the alert source flagged by this policy
  3. Click "Edit" and locate the auto-resolve timeout setting
  4. Set the timeout to 1440 minutes (24 hours) or less, based on the expected alert lifecycle
  5. Save the change and confirm the new timeout is displayed correctly
  6. Review other alert sources for similar misconfigurations

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.3 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Escalation Path Shallow fix difficulty: easy #

Add additional escalation levels to ensure incidents are re-escalated when the first responder does not acknowledge

  1. Sign in to Incident.io and navigate to On-call > Escalation Paths
  2. Open the escalation path flagged by this policy
  3. Click "Edit" and add at least one additional escalation level with a different responder or team
  4. Configure appropriate timeout intervals between levels (e.g., 5-10 minutes)
  5. Save and verify the updated path shows multiple escalation levels

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

More incident.io checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial