You can improve your rating by remediating findings that have a negative impact on your rating during calculation. Negatively-impacting findings are graded BAD, WARN, or FAIR, including all findings in the Compromised Systems and User Behavior risk categories and the Critical Vulnerability Management (CVM) risk vector.
Identify findings to remediate
The Bitsight platform offers many rich features which can be used to focus remediation efforts as detailed in the table below.
- Findings Table
Findings are the culmination of observed internet traffic and configurations. They’re recorded in the Bitsight platform as events and records.
Findings ➔ Findings Table
- Risk Remediation Plan
A Risk Remediation Plan is a prioritized list of findings you can fix to improve certain risk vector grades. This plan is designed to help you identify and remediate high-impact findings to reach an “A” grade.
Action Plans ➔ Risk Remediation
- Forecasting
The Forecasting page is an analytics tool that observes patterns and projects possible future ratings by extracting information from existing data sets.
Action Plans ➔ Forecasting
- Subsidiary Improvement
Subsidiary Improvement provides a guideline for remediation that maximizes the potential impact on the parent rating if findings within its subsidiaries were remediated.
Action Plans ➔ Subsidiary Improvement
- Remediation Strategy Panel
The Remediation Strategy panel highlights findings that have had the highest impact on your rating over the last 60 days. Use this to determine which risk vectors have the largest possible improvement if remediated.
Organization ➔ Company Details
Once a finding is remediated, request a user-initiated findings rescan to update it in the platform. See What To Do After Remediation.
Maintain your rating
To maintain your rating, ensure that remediated assets continue to implement security best practices.
For example, you should consistently:
- Ensure security measures are in place to prevent security incidents
- Renew SSL Certificates before expiration
- Use secure network protocols for sensitive data transmission
- Avoid using deprecated encryption cipher suites
- Upgrade or patch software with known or recently-discovered vulnerabilities
- Keep end user devices up-to-date (i.e. operating system, web browser)
Frequently asked questions
Bitsight calculates ratings daily with a proprietary algorithm that examines two classes of externally observable data: security events and configuration. It assesses security effectiveness across four risk categories: Compromised Systems, Diligence, User Behavior, and Public Disclosures. The algorithm then aggregates the weighted letter grades for each risk vector and normalizes the result for the company.
In the SPM app, go to Findings ➔ Findings Table and use any of these methods:
- Hover over a finding and select Rescan.
- Open the finding details sheet and select Options ➔ Request Rescan.
- Check off up to 250 eligible findings, select Rescan at the top of the table, review the request, and select Submit.
- Invite a company to the Client and Vendor Access Program and ask them to request a rescan for their own organization.
After you submit a request, the Rescan Status column shows progress. You can request up to 1,000 rescans per day, and up to 250 findings at a time.
Bitsight Ratings update daily as new observations arrive and as older events decay or reach the end of their lifetime. The displayed rating rounds down in 10-point increments, so small changes in the underlying rating can move the displayed rating without changing any individual risk vector grade.
- October 28, 2024: Renamed Rating Improvement to Forecasting; Updated navigation for Findings Table, Forecasting, & Remediation Strategy panel.
- February 7, 2023: Published.
Comments
Please sign in to leave a comment.