Skip to main content

Remediation and SLAs

Severity says how bad a finding is. An SLA says when it has to be fixed. Without one, a findings queue is a list sorted by severity that nobody has a reason to work down in any particular order.

Policies, rules, and overrides​

Three layers, and the distinction matters:

LayerScope
PolicyOne per organization. Can be enabled or disabled as a whole
RulesThe ordered list inside a policy that assigns deadlines
Business unit overridesA different ordered list for one business unit

A business unit with an override uses its own rules. This is how a team with a stricter regulatory obligation gets tighter deadlines than the rest of the organization without forcing everyone else to the same standard.

How a rule matches​

A rule is a set of conditions plus a target. The conditions are:

ConditionMeaning
severityCritical, High, Medium, Low, Informational
exploitableA known exploit exists for this
internet_facingThe affected asset is reachable from outside
categoryThe kind of finding

and the target is target_hours - how long from discovery until the finding is due.

This is the part worth internalising: a deadline is not set by severity alone. A High that is both exploitable and internet-facing can carry a shorter deadline than a Critical that is neither, and that is usually the right answer. Severity describes the flaw; these conditions describe your exposure to it.

Which rule wins​

Rules are ordered by priority, and the first one that matches sets the deadline. Later rules are not consulted, and the rule that matched is recorded on the finding, so you can always see which one applied.

That ordering is the whole design, and it is also the thing to be careful with. Put the specific rules first and the general ones last:

1. Critical + exploitable + internet-facing → 24 hours
2. Critical → 7 days
3. High + internet-facing → 7 days
4. High → 30 days
5. Medium → 90 days

Reverse rules 1 and 2 and rule 1 becomes unreachable: every Critical matches the plain Critical rule first, and the 24-hour rule never fires. There is no warning for this - the rule simply never applies.

Write the general rule last, always

A rule with fewer conditions matches more findings. If it sits above a more specific rule, it shadows it permanently.

Due dates are computed, not stored​

A finding's sla_due_date, sla_days_overdue and sla_rule_name are derived when the finding is read, not written when it is created.

The practical consequence: changing a rule re-dates existing findings immediately. Tighten a Critical deadline from 7 days to 24 hours and everything already open is re-evaluated against the new rule, so findings can become overdue the moment you save.

That is usually what you want - a policy should describe your current standard, not the standard in force when each finding happened to be discovered - but it makes rule changes worth doing deliberately rather than experimentally on a live policy.

Breaching an SLA​

Nothing is hidden or auto-closed when a deadline passes. The finding stays open and starts accruing overdue days, which is what reporting and dashboards surface.

Accepting risk does not stop the clock

A due date is computed from when the finding was opened, and that computation does not consider status. Risk Acceptance Approved is an open status, so an accepted finding keeps its due date and keeps accruing overdue days exactly as before.

Only reaching a closed status - fixed and confirmed, or archived because the asset is gone - takes a finding out of the open set.

So if your overdue count exceeds the work you believe is outstanding, accepted risks are the usual reason. Filter on status explicitly rather than assuming acceptance removed them from the count.

Accepting risk is still worth doing: it records a decision, with a name against it, and the difference between an accepted finding and a forgotten one is exactly that. It just does not change the arithmetic.

See Findings, severity, and risk for the full status list and which group each belongs to.

Setting realistic targets​

An SLA policy nobody meets is worse than none - it trains people to ignore the overdue count, and then it tells you nothing.

Start from what your team can actually sustain and tighten from there. Two deadlines you will genuinely hit are more useful than five you will not.

Next​