The 25 PagerDuty security checks Black Cat runs
Black Cat SSPM evaluates 25 security policies against your PagerDuty configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect PagerDuty — what access Black Cat needs, and why.
Access control & privilege
6 checks · highest severity: high
Logging & audit
7 checks · highest severity: critical
Configuration hardening
7 checks · highest severity: high
Third-party & OAuth apps
3 checks · highest severity: medium
Access control & privilege (6)
- Excessive Admins severity: high
- Single Account Owner severity: medium
- Unassigned User severity: medium
- User Pending Invitation severity: low
- Team Without Manager severity: medium
- Service Not Assigned to Team severity: medium
Logging & audit (7)
- Service Without Escalation Policy severity: critical
- Possibly Abandoned Service severity: low
- Service Without Auto-Resolve severity: medium
- Single User Escalation Rule severity: high
- Escalation Policy Without Schedule severity: medium
- Escalation Policy Without Loops severity: high
- Single User Schedule severity: medium
Configuration hardening (7)
- User Without Notification Rules severity: high
- User Without Contact Methods severity: high
- Empty Team severity: medium
- Service Without Integrations severity: medium
- Service Without Acknowledgement Timeout severity: medium
- Escalation Policy Without Services severity: low
- Schedule Not Linked to Escalation Policy severity: low
Third-party & OAuth apps (3)
- Extension Disabled severity: medium
- Webhook External URL severity: medium
- Webhook Inactive severity: low
Other checks (2)
severity: high SSO Disabled fix difficulty: medium #
Enable SSO in PagerDuty account settings to enforce centralized identity authentication
- Sign in to PagerDuty as an Account Owner or Global Admin
- Navigate to Account > Account Settings > Single Sign-On
- Click "Set Up SSO" and choose your identity provider (Okta, Azure AD, etc.)
- Enter the SSO configuration details (Entity ID, SSO URL, certificate)
- Save the configuration and test SSO login before enforcing it
- Optionally enable "Require SSO" to block password-based logins
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Advanced Permissions Disabled fix difficulty: medium #
Enable Advanced Permissions in PagerDuty to enforce granular role-based access control
- Sign in to PagerDuty as an Account Owner
- Navigate to Account > Account Settings
- Locate the "Advanced Permissions" section
- Click "Enable Advanced Permissions"
- Review the role assignments for all users and adjust as needed
- Save the changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4