Skip to content

PagerDuty third-party & OAuth apps security checks

OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.

On PagerDuty, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.

Checks (3)

severity: medium Extension Disabled fix difficulty: easy #

Re-enable or remove disabled PagerDuty extensions to keep integrations in a known and auditable state

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Integrations > Extensions
  3. Locate the disabled extension
  4. If the extension is still needed, click on it and re-enable or reconfigure it
  5. If the extension is no longer needed, click "Delete" to remove it
  6. Confirm the change and verify the extension status

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

severity: medium Webhook External URL fix difficulty: easy #

Update PagerDuty webhook subscriptions to use HTTPS delivery URLs to ensure encrypted transport

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to Integrations > Generic Webhooks (V3) or the relevant webhook subscription
  3. Click on the webhook subscription with a non-HTTPS URL
  4. Edit the delivery URL to use an HTTPS endpoint
  5. Save the webhook subscription
  6. Test the webhook to confirm events are delivered successfully

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

severity: low Webhook Inactive fix difficulty: easy #

Re-enable or remove inactive PagerDuty webhook subscriptions to keep integrations in a known state

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to Integrations > Generic Webhooks (V3) or the relevant webhook section
  3. Locate the inactive webhook subscription
  4. If the webhook is still needed, click on it and re-enable it; verify the delivery URL is reachable
  5. If the webhook is no longer needed, click "Delete" to remove it
  6. Confirm the change and test delivery if re-enabling

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-9.12

More PagerDuty checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial