Planning Your Remediation
Turning findings into a prioritized action plan
You have scan results. Now the real work begins. This guide helps you build a practical remediation plan that is realistic for your team and moves your security posture forward without overwhelming anyone.
Core Principle: Don't try to fix everything at once. Establish a prioritized, sustainable approach that steadily reduces risk over time.
Step 1: Prioritize by Risk
Fix First (Critical Path)
- Very High and High severity findings in your most business-critical applications
- Findings that are currently causing policy failure
- Findings in code that is publicly exposed or internet-facing
Fix Next (Important)
- Medium severity findings in business-critical applications
- Very High / High findings in internal or lower-criticality applications
Fix Later (Backlog)
- Low and Very Low severity findings
- Findings in applications with lower business impact
Docs: About Security Policies
Step 2: Assign Ownership
Findings without owners don't get fixed. Group findings by application or codebase, assign to the team that owns the code, and surface work in your existing ticketing workflow.
Step 3: Set Realistic Timelines
| Severity | Suggested Fix Timeline |
|---|---|
| Very High | Address within 30 days |
| High | Address within 60 days |
| Medium | Address within the next quarterly cycle |
| Low / Very Low | Address opportunistically during regular code maintenance |
Step 4: Handle What You Can't Fix Right Now
Not every finding can be fixed immediately. For findings you're not ready to remediate, Veracode provides mitigation options:
- Mitigated by Design — Your architecture already addresses the risk.
- OS/Platform Mitigated — A platform control mitigates the risk.
- Potential False Positive — You believe the finding is not a real vulnerability.
- Accept the Risk — Acknowledged risk with a justification on record.
A user with the Mitigation Approver role must approve all mitigation proposals before they count toward policy compliance.
- Docs: Propose Mitigations
Step 5: Track Progress with Analytics
Use Veracode Analytics to track remediation progress over time. Key metrics to monitor:
- Policy compliance rate — Percentage of applications passing policy.
- MTTR — Average time to fix findings by severity — declining trend is the goal.
- Open findings by severity — Should trend down over time.
- New vs. closed — Are you getting ahead or falling behind?
Docs: Veracode Analytics
Communicating Progress to Leadership
- Customizable Report — Generate a PDF summary of policy status and findings. docs.veracode.com/r/c_results_reports
- Analytics dashboards — Share dashboards showing trends over time.
- Reporting REST API — Pull data programmatically. docs.veracode.com/r/Reporting_REST_API
Learning Paths
Go deeper with these step-by-step learning paths on Veracode Docs:
← Back to the Getting Started Guide | ← Back to the Onboarding Hub
.png)