Fixing what was found.
WHY THIS IS THE WHOLE POINT
Assessment without remediation is expenditure with no benefit.
WHAT TO ESTABLISH
An owner for every finding A target date A tracking record
WHY OWNERS
Findings owned by nobody are not fixed.
WHAT TO DO IMMEDIATELY
Address anything critical and externally exploitable.
WHY IMMEDIATELY
The weakness exists now and others may find it.
WHAT TO ESTABLISH ABOUT INTERIM MEASURES
What reduces exposure before a full fix.
WHAT THOSE MIGHT BE
Restricting access Disabling a feature Additional monitoring Taking a system offline
WHY THEY MATTER
Full remediation takes time and exposure continues meanwhile.
WHAT TO ADDRESS BEYOND THE SPECIFIC FINDING
Whether the same issue exists elsewhere.
WHY
Testers examine a sample, and the same mistake is usually repeated.
WHAT TO ASK OF EACH FINDING
Why did this exist Where else would that cause apply What would prevent it recurring
WHAT ROOT CAUSES USUALLY ARE
No process for patching Default configurations never changed Security not considered in development No review before deployment Systems nobody owns
WHAT TO ADDRESS
Those, rather than only the instances.
WHAT TO DO ABOUT FINDINGS YOU WILL NOT FIX
Record the decision and the reasoning.
WHY
Accepted risk should be a decision, documented, rather than an omission.
WHO SHOULD ACCEPT IT
Someone with authority to accept the consequence.
WHAT TO ARRANGE
A retest, verifying fixes.
WHY
Fixes frequently do not work or introduce new issues.
WHAT TO TRACK
Findings, status and time to resolution.