PagerDuty logging & audit security checks
Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.
On PagerDuty, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.
Checks (7)
severity: critical Service Without Escalation Policy fix difficulty: easy #
Attach an escalation policy to each PagerDuty service to ensure incidents are routed correctly
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Services > Service Directory
- Click on the service that is missing an escalation policy
- Select the "Settings" tab
- Under "Assign and Notify", choose an existing escalation policy from the dropdown
- Save the service configuration
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: low Possibly Abandoned Service fix difficulty: easy #
Review inactive PagerDuty services and either reactivate them or decommission them
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Services > Service Directory and locate the inactive service
- Review whether the service is still needed by consulting the owning team
- If no longer needed, open the service and click "Delete Service"
- If still needed, update the service and ensure it has an active escalation policy and recent activity
- Document the decision for future audits
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Service Without Auto-Resolve fix difficulty: easy #
Enable an auto-resolve timeout on each PagerDuty service to prevent indefinitely open incidents
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Services > Service Directory and click the affected service
- Select the "Settings" tab
- Under "Incident Settings", locate the "Auto-resolve" option
- Set a timeout value (e.g. 4 hours) appropriate for the service
- Save the service configuration
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: high Single User Escalation Rule fix difficulty: easy #
Add additional responders or on-call schedules to escalation policies that rely on a single user
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to People > Escalation Policies
- Click on the escalation policy with only one responder
- On the affected escalation rule, click "Add Target" to add more users or a schedule
- Assign an on-call schedule as the primary target for better coverage
- Save the escalation policy
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Escalation Policy Without Schedule fix difficulty: medium #
Replace direct user assignments in escalation policies with on-call schedules for reliable coverage
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to People > Escalation Policies and click the affected policy
- For each rule that targets individual users, click "Add Target"
- Select an existing on-call schedule or create a new one under People > On-Call Schedules
- Remove direct user assignments from the rule once a schedule is added
- Save the escalation policy
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: high Escalation Policy Without Loops fix difficulty: easy #
Set the repeat count on escalation policies to at least 1 so alerts re-escalate if unacknowledged
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to People > Escalation Policies
- Click on the escalation policy missing loop configuration
- Locate the "Repeat this policy" setting at the bottom of the escalation policy editor
- Set the number of loops to at least 1
- Save the escalation policy
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2
severity: medium Single User Schedule fix difficulty: easy #
Add additional users to single-user on-call schedules to eliminate single points of failure
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to People > On-Call Schedules
- Click on the schedule with only one user
- Click "Edit Schedule" and add one or more users to the rotation layer
- Configure a rotation type (daily, weekly, etc.) appropriate for the team
- Save and verify the schedule shows correct on-call coverage
Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2