Discover with context
Combine authenticated scanning, application testing, cloud inventory and external attack-surface review. Record environment, exposure, service owner and data sensitivity with the finding.
Prioritise what can cause harm
Use severity as one input. Add evidence of exploitation, internet exposure, privilege, asset importance and compensating controls. Known exploitation should have a clear escalation path.
Close with evidence
A ticket marked complete is not proof. Retest the affected condition, record the corrected version or configuration and preserve accepted-risk decisions with an expiry date.
Measures that help
- Time to assign an accountable owner.
- Age of exposed, exploited findings.
- Percentage of closures independently verified.
- Exceptions that passed their review date.
