Skip to content

PagerDuty logging & audit security checks

Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.

On PagerDuty, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.

Checks (7)

severity: critical Service Without Escalation Policy fix difficulty: easy #

Attach an escalation policy to each PagerDuty service to ensure incidents are routed correctly

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Services > Service Directory
  3. Click on the service that is missing an escalation policy
  4. Select the "Settings" tab
  5. Under "Assign and Notify", choose an existing escalation policy from the dropdown
  6. Save the service configuration

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: low Possibly Abandoned Service fix difficulty: easy #

Review inactive PagerDuty services and either reactivate them or decommission them

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Services > Service Directory and locate the inactive service
  3. Review whether the service is still needed by consulting the owning team
  4. If no longer needed, open the service and click "Delete Service"
  5. If still needed, update the service and ensure it has an active escalation policy and recent activity
  6. Document the decision for future audits

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Service Without Auto-Resolve fix difficulty: easy #

Enable an auto-resolve timeout on each PagerDuty service to prevent indefinitely open incidents

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Services > Service Directory and click the affected service
  3. Select the "Settings" tab
  4. Under "Incident Settings", locate the "Auto-resolve" option
  5. Set a timeout value (e.g. 4 hours) appropriate for the service
  6. Save the service configuration

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: high Single User Escalation Rule fix difficulty: easy #

Add additional responders or on-call schedules to escalation policies that rely on a single user

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to People > Escalation Policies
  3. Click on the escalation policy with only one responder
  4. On the affected escalation rule, click "Add Target" to add more users or a schedule
  5. Assign an on-call schedule as the primary target for better coverage
  6. Save the escalation policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Escalation Policy Without Schedule fix difficulty: medium #

Replace direct user assignments in escalation policies with on-call schedules for reliable coverage

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to People > Escalation Policies and click the affected policy
  3. For each rule that targets individual users, click "Add Target"
  4. Select an existing on-call schedule or create a new one under People > On-Call Schedules
  5. Remove direct user assignments from the rule once a schedule is added
  6. Save the escalation policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: high Escalation Policy Without Loops fix difficulty: easy #

Set the repeat count on escalation policies to at least 1 so alerts re-escalate if unacknowledged

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to People > Escalation Policies
  3. Click on the escalation policy missing loop configuration
  4. Locate the "Repeat this policy" setting at the bottom of the escalation policy editor
  5. Set the number of loops to at least 1
  6. Save the escalation policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Single User Schedule fix difficulty: easy #

Add additional users to single-user on-call schedules to eliminate single points of failure

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to People > On-Call Schedules
  3. Click on the schedule with only one user
  4. Click "Edit Schedule" and add one or more users to the rotation layer
  5. Configure a rotation type (daily, weekly, etc.) appropriate for the team
  6. Save and verify the schedule shows correct on-call coverage

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.7 CIS Controls v8 CIS-17 NIST CSF 2.0 RS.MA GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

More PagerDuty checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial