Planning Your Remediation

Turning findings into a prioritized action plan


You have scan results. Now the real work begins. This guide helps you build a practical remediation plan that is realistic for your team and moves your security posture forward without overwhelming anyone.

Core Principle: Don't try to fix everything at once. Establish a prioritized, sustainable approach that steadily reduces risk over time.


Step 1: Prioritize by Risk

Fix First (Critical Path)

  • Very High and High severity findings in your most business-critical applications
  • Findings that are currently causing policy failure
  • Findings in code that is publicly exposed or internet-facing

Fix Next (Important)

  • Medium severity findings in business-critical applications
  • Very High / High findings in internal or lower-criticality applications

Fix Later (Backlog)

  • Low and Very Low severity findings
  • Findings in applications with lower business impact

Docs: About Security Policies


Step 2: Assign Ownership

Findings without owners don't get fixed. Group findings by application or codebase, assign to the team that owns the code, and surface work in your existing ticketing workflow.


Step 3: Set Realistic Timelines

Severity Suggested Fix Timeline
Very High Address within 30 days
High Address within 60 days
Medium Address within the next quarterly cycle
Low / Very Low Address opportunistically during regular code maintenance

Step 4: Handle What You Can't Fix Right Now

Not every finding can be fixed immediately. For findings you're not ready to remediate, Veracode provides mitigation options:

  • Mitigated by Design — Your architecture already addresses the risk.
  • OS/Platform Mitigated — A platform control mitigates the risk.
  • Potential False Positive — You believe the finding is not a real vulnerability.
  • Accept the Risk — Acknowledged risk with a justification on record.

A user with the Mitigation Approver role must approve all mitigation proposals before they count toward policy compliance.


Step 5: Track Progress with Analytics

Use Veracode Analytics to track remediation progress over time. Key metrics to monitor:

  • Policy compliance rate — Percentage of applications passing policy.
  • MTTR — Average time to fix findings by severity — declining trend is the goal.
  • Open findings by severity — Should trend down over time.
  • New vs. closed — Are you getting ahead or falling behind?

Docs: Veracode Analytics


Communicating Progress to Leadership


Learning Paths

Go deeper with these step-by-step learning paths on Veracode Docs:


← Back to the Getting Started Guide | ← Back to the Onboarding Hub