Skip to content

PagerDuty access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On PagerDuty, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.

Checks (6)

severity: high Excessive Admins fix difficulty: easy #

Reduce the number of PagerDuty admin accounts to three or fewer to limit blast radius

  1. Sign in to PagerDuty as an Account Owner or Global Admin
  2. Navigate to People > Users
  3. Filter by role "Admin" or "Global Admin" to list all admin accounts
  4. For each admin who does not require full admin access, click their name
  5. Change their role to a lower-privilege role (e.g. Manager or Responder)
  6. Save the updated role assignment

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Single Account Owner fix difficulty: easy #

Designate at least one additional Account Owner in PagerDuty to ensure administrative redundancy

  1. Sign in to PagerDuty as the current Account Owner
  2. Navigate to People > Users
  3. Select a trusted administrator to promote
  4. Click on their name to open the user detail page
  5. Change the role to "Account Owner"
  6. Save the change and confirm the new owner can log in

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Unassigned User fix difficulty: easy #

Assign unassigned PagerDuty users to an appropriate team or deactivate them if no longer needed

  1. Sign in to PagerDuty as an Account Owner or Global Admin
  2. Navigate to People > Users and find the unassigned user
  3. If the user is still active, navigate to People > Teams and add them to the relevant team
  4. If the user is no longer needed, open the user detail page and click "Deactivate User"
  5. Confirm the deactivation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low User Pending Invitation fix difficulty: easy #

Follow up on pending PagerDuty invitations or remove stale user accounts that were never activated

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to People > Users and find users with pending invitations
  3. Contact the user to remind them to accept the invitation
  4. If the user no longer needs access, click their name and select "Delete User"
  5. Confirm the deletion

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Team Without Manager fix difficulty: easy #

Assign a manager to each PagerDuty team to ensure accountability and oversight

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to People > Teams and click on the team without a manager
  3. Click on the "Members" section
  4. Select an appropriate team member and change their role to "Manager"
  5. Save the team configuration

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Service Not Assigned to Team fix difficulty: easy #

Assign each PagerDuty service to a team for clear ownership and access control

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Services > Service Directory and click on the unassigned service
  3. Select the "Settings" tab
  4. Under "Teams", click "Add Team" and select the appropriate team
  5. Save the service configuration

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More PagerDuty checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial