The Diligence risk category assesses the steps a company has taken to prevent attacks, their best practice implementation, and risk mitigation (e.g., server configurations) to determine if the security practices of an organization are on par with industry-wide best practices.
You can also retrieve Diligence finding details through the Bitsight API, using the endpoint GET Diligence Finding Details.
What do the finding details mean?
The findings list shows the following fields. The fields shown vary by risk vector. See the next section for articles that cover each risk vector.
- Assigned To
The user assigned to remediate the finding.
- Grade
-
The finding grade.
Finding grades show N/A for the following risk vectors:- All risk vectors in the Compromised Systems risk category
- All risk vectors in the User Behavior risk category
- Critical Vulnerability Management (CVM), a risk vector in the Diligence risk category
- Web Application Headers, a risk vector in the Diligence risk category, since October 2025
A finding grade of N/A on these risk vectors is expected and does not indicate an error. For the meaning of each finding grade, see the article How does Bitsight calculate Security Ratings?
- Rescan
The rescan status.
- Remediations
The name of the issue(s) a finding has, details about the issue(s), and remediation instructions information if applicable.
- Remediation Status
-
Your current progress on remediating findings.
- ↻ No Status = No user has ever assigned a status to the finding.
- Open = The finding needs review.
- To Do = The finding is in the backlog to remediate
- Work In Progress = Remediation is in progress.
- Resolved = You consider the finding remediated or want to mark it as remediated
- Risk Accepted = The finding is low priority because the risk is at an acceptable level
- Status History
-
A history of Issue Tracking changes for a finding:
- Remediation Status
- Assigned To
- Status Updated (UTC)
- Updated By
This section will not appear if the status has never been updated.
- Status Updated
The date when the Remediation Status or Assigned To fields were last changed.
Where can I find details for a specific risk vector?
- SPF Domains
- DKIM Records
- TLS/SSL Certificates
- TLS/SSL Configurations
- Open Ports
- Web Application Headers
- Critical Vulnerability Mangement (CVM)
- Insecure Systems
- Server Software
- Desktop Software
- Mobile Software
- DNSSEC
- Domain Squatting
- October 29, 2024: Findings Table navigation instructions moved from Risks to a new Findings section in the menu.
- April 8, 2021: Published.
Comments
Please sign in to leave a comment.