What is the difference between Mitigation status and Remediation status?
New: Flaw has never been found
Open: Flaw was found in the current and previous scan
Closed: Flaw was not found in the current scan
Re-Open: Flaw was found in the current scan but was Closed in the previous scan.
Mitigation is the act of documenting and accepting the risk of a flaw. It can be done for many reasons, but the most common is due to factors outside of the scope of the scan (ex. network environment), making the potential for said risk moot. There are four possible values:
None: There have been no mitigations associated with this flaw
Proposed: A mitigation has been documented and is awaiting review
Approved: The proposed mitigation has been reviewed and deemed acceptable
Rejected: The proposed mitigation has been reviewed and deemed unaccaptable
As you can see, these concepts are independent of each other. This means that a flaw that has a mitigation associated with it is most likely going to continue to be found, as the purpose of a mitigation is to accept the risk of a flaw rather than remove the flaw.
Topics (1)
Related Articles
How to: Download Manual Penetration Test Reports 903Number of Views Updating Veracode Level 377Number of Views How to grant vendors access to view scan results in the platform? 451Number of Views What It Means to Remediate vs Mitigate a Flaw? 1.49KNumber of Views SCA component report.xls location 8Number of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)