PagerDuty access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On PagerDuty, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.
Checks (6)
severity: high Excessive Admins fix difficulty: easy #
Reduce the number of PagerDuty admin accounts to three or fewer to limit blast radius
- Sign in to PagerDuty as an Account Owner or Global Admin
- Navigate to People > Users
- Filter by role "Admin" or "Global Admin" to list all admin accounts
- For each admin who does not require full admin access, click their name
- Change their role to a lower-privilege role (e.g. Manager or Responder)
- Save the updated role assignment
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Single Account Owner fix difficulty: easy #
Designate at least one additional Account Owner in PagerDuty to ensure administrative redundancy
- Sign in to PagerDuty as the current Account Owner
- Navigate to People > Users
- Select a trusted administrator to promote
- Click on their name to open the user detail page
- Change the role to "Account Owner"
- Save the change and confirm the new owner can log in
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Unassigned User fix difficulty: easy #
Assign unassigned PagerDuty users to an appropriate team or deactivate them if no longer needed
- Sign in to PagerDuty as an Account Owner or Global Admin
- Navigate to People > Users and find the unassigned user
- If the user is still active, navigate to People > Teams and add them to the relevant team
- If the user is no longer needed, open the user detail page and click "Deactivate User"
- Confirm the deactivation
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low User Pending Invitation fix difficulty: easy #
Follow up on pending PagerDuty invitations or remove stale user accounts that were never activated
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to People > Users and find users with pending invitations
- Contact the user to remind them to accept the invitation
- If the user no longer needs access, click their name and select "Delete User"
- Confirm the deletion
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Team Without Manager fix difficulty: easy #
Assign a manager to each PagerDuty team to ensure accountability and oversight
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to People > Teams and click on the team without a manager
- Click on the "Members" section
- Select an appropriate team member and change their role to "Manager"
- Save the team configuration
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Service Not Assigned to Team fix difficulty: easy #
Assign each PagerDuty service to a team for clear ownership and access control
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Services > Service Directory and click on the unassigned service
- Select the "Settings" tab
- Under "Teams", click "Add Team" and select the appropriate team
- Save the service configuration
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2