Acting on Findings Print

  • 0

Fixing what was found.

WHY THIS IS THE WHOLE POINT

Assessment without remediation is expenditure with no benefit.

WHAT TO ESTABLISH

An owner for every finding A target date A tracking record

WHY OWNERS

Findings owned by nobody are not fixed.

WHAT TO DO IMMEDIATELY

Address anything critical and externally exploitable.

WHY IMMEDIATELY

The weakness exists now and others may find it.

WHAT TO ESTABLISH ABOUT INTERIM MEASURES

What reduces exposure before a full fix.

WHAT THOSE MIGHT BE

Restricting access Disabling a feature Additional monitoring Taking a system offline

WHY THEY MATTER

Full remediation takes time and exposure continues meanwhile.

WHAT TO ADDRESS BEYOND THE SPECIFIC FINDING

Whether the same issue exists elsewhere.

WHY

Testers examine a sample, and the same mistake is usually repeated.

WHAT TO ASK OF EACH FINDING

Why did this exist Where else would that cause apply What would prevent it recurring

WHAT ROOT CAUSES USUALLY ARE

No process for patching Default configurations never changed Security not considered in development No review before deployment Systems nobody owns

WHAT TO ADDRESS

Those, rather than only the instances.

WHAT TO DO ABOUT FINDINGS YOU WILL NOT FIX

Record the decision and the reasoning.

WHY

Accepted risk should be a decision, documented, rather than an omission.

WHO SHOULD ACCEPT IT

Someone with authority to accept the consequence.

WHAT TO ARRANGE

A retest, verifying fixes.

WHY

Fixes frequently do not work or introduce new issues.

WHAT TO TRACK

Findings, status and time to resolution.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot