Running a Risk Remediation Plan Jessica Running Risk Remediation generates a plan for all users on your account.Rerunning a risk remediation plan (RRP) generates a new plan on the plan details page and replaces the previous one. You can access and download historical plans by selecting See Historical Plans on the plan details page. Historical plans are available for one year after calculation. RRPs cannot be run if a risk vector has less than five findings or only has Neutral findings. Plans are calculated based on the presence of findings that positively or negatively impact your risk vector grade. Learn more about which hosts and assets are included in your infrastructure: How to Evaluate a Host for Web Application Headers Inclusion Web Application Header Finding Considerations TLS/SSL Configurations Finding Considerations How To Run the First Risk Remediation PlanThis action runs your first RRP. Once run, RRPs are visible to all users in your organization. In the SPM App, select Action Plans from the navigation menu. Select Risk Remediation. Choose which risk vector to run a plan for, then select Run Risk Remediation Plan. How To Rerun a Risk Remediation PlanPeriodically check your RRP to keep track of which findings you still need to fix. If a new finding occurs, rerun the RRP to get an updated version of the steps needed to improve your risk vector grade. From the RRP overview page, select View details. Select Rerun Plan. How to Run a Custom Risk Remediation Plan From the Risk Remediation plan overview page, select View Details. Choose Change Plan in upper right hand corner, and Create New Plan. Add plan details, sharing privileges, and select the findings you wish to exclude from this version of the plan. Select Save Settings, which will run the plan. This may take a few minutes. View updated plan. You may also compare the base plan, schedule the plan, or run a forecast off of the new plan. A custom plan defaults to only being viewable by you, unless shared with users from your company in Plan Settings.TroubleshootingYou can only run an RRP for your My Company and companies you subscribe to with My Subsidiary subscriptions. If you receive the error "You do not have permission for that entity," please make sure that you are subscribed to the company using a My Subsidiary subscription. April 3, 2026: Added instructions on how to run a custom risk remediation plan. June 22, 2022: Published. Related articles Action Plans: Risk Remediation Risk Remediation Plan Details by Risk Vector Scheduling a Risk Remediation Plan How is the Web Application Headers Risk Vector Assessed? TLS/SSL Finding Remediation & Remediation Verification Feedback 0 comments Please sign in to leave a comment.