incident.io logging & audit security checks
Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.
On incident.io, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.
Checks (11)
severity: high Single Responder Escalation fix difficulty: medium #
Add additional responders to each escalation path node to remove single points of failure
- Sign in to Incident.io and navigate to On-call > Escalation paths
- Open the escalation path flagged by this policy
- Locate any node that contains only a single responder
- Click edit on that node and add at least one additional responder or schedule
- Save the escalation path and verify all nodes have multiple coverage options
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Single Rotation Schedule fix difficulty: medium #
Add at least one additional rotation to on-call schedules that have only a single rotation
- Sign in to Incident.io and navigate to On-call > Schedules
- Open the schedule flagged by this policy
- Click "Add rotation" to create a second rotation
- Configure responders, handoff times, and coverage hours for the new rotation
- Save the schedule and confirm at least two rotations are active
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: high Schedule Without Active Shift fix difficulty: medium #
Ensure every on-call schedule has at least one active shift to maintain continuous incident coverage
- Sign in to Incident.io and navigate to On-call > Schedules
- Open the schedule flagged by this policy
- Review the schedule timeline to identify gaps in shift coverage
- Assign responders or extend existing rotations to cover the gap
- Save the schedule and verify the current time falls within an active shift
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Workflow Disabled or Error fix difficulty: medium #
Fix or remove Incident.io workflows that are in a disabled or error state
- Sign in to Incident.io and navigate to Workflows
- Filter by status to locate workflows in a disabled or error state
- Open the affected workflow and review any error messages shown
- Correct the misconfiguration (e.g., invalid action, missing integration) or remove the workflow if obsolete
- Re-enable the workflow and confirm it transitions to an active state
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: low Workflow Ignores Step Errors fix difficulty: easy #
Disable continue-on-step-error in Incident.io workflow settings to ensure reliable workflow execution
- Sign in to Incident.io and navigate to Workflows
- Open the workflow flagged by this policy
- Click "Edit" and locate the error-handling or advanced settings section
- Disable the "continue on step error" option
- Save the workflow and verify that step failures will now halt execution for investigation
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: low Alert Source No Auto-Resolve fix difficulty: easy #
Enable auto-resolve on Incident.io alert sources to prevent alerts from remaining open indefinitely
- Sign in to Incident.io and navigate to Alerts > Alert sources
- Locate the alert source flagged by this policy
- Click "Edit" on the alert source configuration
- Enable the "auto-resolve" option and set an appropriate resolution timeout
- Save the change and confirm auto-resolve is active for the alert source
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: high Alert Route No Escalation Path fix difficulty: easy #
Attach an escalation path to every alert route so that triggered alerts reach on-call responders
- Sign in to Incident.io and navigate to Alerts > Alert routes
- Open the alert route flagged by this policy
- Click "Edit" and locate the escalation path field
- Select an appropriate escalation path from the dropdown
- Save the change and verify the route now shows an escalation path
- Trigger a test alert to confirm the escalation path is invoked correctly
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: low Alert Route No Grouping fix difficulty: easy #
Configure alert grouping on alert routes to reduce noise during alert storms
- Sign in to Incident.io and navigate to Alerts > Alert routes
- Open the alert route flagged by this policy
- Click "Edit" and locate the grouping configuration section
- Enable grouping and select the field(s) to group by (e.g., alert source, labels)
- Set an appropriate grouping window (e.g., 5 minutes)
- Save the route and monitor alert volume to confirm grouping reduces individual pages
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: high Escalation Path No Current Responders fix difficulty: medium #
Ensure every escalation path has at least one active responder so that incidents are never silently dropped
- Sign in to Incident.io and navigate to On-call > Escalation paths
- Open the escalation path flagged by this policy
- Review each node in the path for assigned responders or schedules
- Add at least one active responder or link a schedule that currently has coverage
- If the path is unused, consider archiving or deleting it to avoid confusion
- Save the changes and verify the path shows at least one current responder
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Alert Source Auto-Resolve Timeout Too Long fix difficulty: easy #
Reduce the auto-resolve timeout on alert sources that exceed 24 hours to prevent stale alerts lingering unresolved
- Sign in to Incident.io and navigate to Alerts > Alert sources
- Open the alert source flagged by this policy
- Click "Edit" and locate the auto-resolve timeout setting
- Set the timeout to 1440 minutes (24 hours) or less, based on the expected alert lifecycle
- Save the change and confirm the new timeout is displayed correctly
- Review other alert sources for similar misconfigurations
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.3 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Escalation Path Shallow fix difficulty: easy #
Add additional escalation levels to ensure incidents are re-escalated when the first responder does not acknowledge
- Sign in to Incident.io and navigate to On-call > Escalation Paths
- Open the escalation path flagged by this policy
- Click "Edit" and add at least one additional escalation level with a different responder or team
- Configure appropriate timeout intervals between levels (e.g., 5-10 minutes)
- Save and verify the updated path shows multiple escalation levels
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2