PagerDuty third-party & OAuth apps security checks
OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.
On PagerDuty, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.
Checks (3)
severity: medium Extension Disabled fix difficulty: easy #
Re-enable or remove disabled PagerDuty extensions to keep integrations in a known and auditable state
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Integrations > Extensions
- Locate the disabled extension
- If the extension is still needed, click on it and re-enable or reconfigure it
- If the extension is no longer needed, click "Delete" to remove it
- Confirm the change and verify the extension status
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12
severity: medium Webhook External URL fix difficulty: easy #
Update PagerDuty webhook subscriptions to use HTTPS delivery URLs to ensure encrypted transport
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to Integrations > Generic Webhooks (V3) or the relevant webhook subscription
- Click on the webhook subscription with a non-HTTPS URL
- Edit the delivery URL to use an HTTPS endpoint
- Save the webhook subscription
- Test the webhook to confirm events are delivered successfully
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12
severity: low Webhook Inactive fix difficulty: easy #
Re-enable or remove inactive PagerDuty webhook subscriptions to keep integrations in a known state
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to Integrations > Generic Webhooks (V3) or the relevant webhook section
- Locate the inactive webhook subscription
- If the webhook is still needed, click on it and re-enable it; verify the delivery URL is reachable
- If the webhook is no longer needed, click "Delete" to remove it
- Confirm the change and test delivery if re-enabling
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12