The Risk Remediation supports multiple risk vectors. Each plan provides risk vector-specific details to enable your remediation efforts.
- TLS/SSL Certificates
- TLS/SSL Configurations
- Web Application Security
- Critical Vulnerability Management
- Desktop Software
- Mobile Software
- DMARC
TLS/SSL Certificates
Lists issues found in your TLS/SSL certificates. Potential findings include expired certificates, self-signed certificates, insecure signature algorithms, and large numbers of DNS names.
Finding Details for TLS/SSL Certificates:
- Certificate Serial Number
Unique identifier of the specific certificate with issues.
- [Date] Last Seen Date
Date the finding was most recently observed.
- Finding Grade
The finding grade (
Bad,Warn,Fair,Good) as of the date the RRP was generated.- Finding Identifier
The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding.
- Grade [Group]
The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.
- Issues
Open issues that affect the finding grade.
This is not applicable to TLS/SSL Certificate findings. Refer to the Certificate Serial Number to identify TLS/SSL Certificate findings.
Reference the Knowledge Base articles below for further information on the TLS/SSL Certificates risk vector, findings, and remediation.
- TLS/SSL Certificates Risk Vector
- How is the TLS/SSL Certificates Risk Vector Assessed?
- TLS/SSL Certificate Findings
- TLS/SSL Finding Remediation & Remediation Verification
TLS/SSL Configurations
Lists issues found in your TLS/SSL configurations. Potential findings include insecure protocols, missing or non-standard certificates, and other issues in your TLS/SSL configurations.
Finding Details for TLS/SSL Certificates:
- [Date] Last Seen Date
Date the finding was most recently observed.
- Finding Grade
The finding grade (
Bad,Warn,Fair,Good) as of the date the RRP was generated.- Finding Identifier
The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding.
- Grade [Group]
The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.
- Issues
Open issues that affect the finding grade.
Reference the Knowledge Base articles below for further information on the TLS/SSL Configurations risk vector, findings, and remediation.
- TLS/SSL Configurations Risk Vector
- How is the TLS/SSL Configurations Risk Vector Assessed?
- TLS/SSL Configuration Findings
- TLS/SSL Finding Remediation & Remediation Verification
Web Application Security
Performs multiple assessments related to web application security. It provides information about components with known vulnerabilities, broken authentication and access control, sensitive data exposure, cross-site scripting prevention mechanisms, and security misconfigurations.
- Web Application Security Risk Vector
- How is the Web Application Security Risk Vector Assessed?
- Web Application Security Findings
Finding details for Web Application Security:
- [Date] First Seen Date
Date the finding was first observed.
- [Date] Last Seen Date
Date the finding was most recently observed.
- Evidence Key
Asset (domain:port) associated with the finding to remediate.
- Failed Evidence Count
The amount of failed evidence associated with the finding.
- Finding Grade
The finding grade (
Bad,Warn,Fair,Neutral,Good) as of the date the RRP was generated.- Total Evidence Count
The total amount of evidence associated with the finding.
- Web App Security Test
Name of the web application security test.
Critical Vulnerability Management
The Critical Vulnerability Management Risk Remediation Plan (RRP) is available in two formats: a downloadable .csv or PDF and an interactive report within the Bitsight platform. The RRP considers a subset of unremediated findings to be fixed to calculate the projected grade. Please note that due to the nature of this risk vector, remediated findings will continue to impact your grade over time.
Both formats list:
- remediation scenarios
- group vulnerabilities by severity and duration
- and project the future Critical Vulnerability Management grade based on each scenario.
The PDF report offers an additional metric not currently available in the platform view: a "Total Findings Remediated Today" cumulative column within the scenarios.
The Critical Vulnerability Management RRP provides an idea of trajectory and timescale based on different remediation scenarios. Due to the long lifetime period associated with this risk vector, grades improve slowly over time. This RRP can be leveraged to see how remediating the highest-impact Critical Vulnerabilities Management findings today would affect your grade over the its lifetime (90 days), assuming all findings in a scenario are remediated and no new findings are observed.
Finding details for Critical Vulnerability Management:
- Finding Identifier
The numerical ID associated the finding.
- Vulnerability Severity
The Bitsight severity of the vulnerabilities associated with the findings. Groups are sorted from top to bottom based on severity. Learn more here
- Vulnerability
The flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s security policy.
- Duration
The amount of time a vulnerability was seen unpatched. Duration ranges are dynamically defined based on quartiles, meaning each Duration range has a similar number of findings across all vulnerability severities.
- Last Seen Date
Date the vulnerability was last seen.
- 1 Day
The projected grade improvement timeline if the scenario criteria are met..
- 30 Days
The projected grade improvement timeline if the scenario criteria are met..
- 60 Days
The projected grade improvement timeline if the scenario criteria are met..
- 91 Days
The projected grade improvement timeline if the scenario criteria are met..
Desktop Software
Lists unsupported operating systems and browsers identified on desktop devices in your network that access the Internet. Potential findings include supported or unsupported operating systems and browsers.
Finding Details for Desktop Software:
- [Date] First Seen Date
Date the finding was first observed.
- [Date] Last Seen Date
Date the finding was most recently observed.
- Details
States whether the operating system and browser are supported or unsupported.
- Finding Grade
The finding grade (
Bad,Warn,Fair,Good) as of the date the RRP was generated.- Geo Location
The geographical location where the unsupported operating system or browser was observed.
- Grade [Group]
The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.
- Observed Devices
The number of observed devices relating to the operating system and browser.
- OS/Browser
The operating system and browser associated with the finding, with version numbers.
- Sample IPs
Sample of the hosts detected using the operating system and browser.
Reference the Knowledge Base articles below for further information on the Desktop Software risk vector, findings, and remediation.
Mobile Software
Lists unsupported operating systems and browsers identified on mobile devices in your network that access the Internet. Potential findings include supported and unsupported operating systems and browsers.
Finding Details for Mobile Software:
- [Date] First Seen Date
Date the finding was first observed.
- [Date] Last Seen Date
Date the finding was most recently observed.
- Details
States whether the operating system and browser are supported or unsupported.
- Finding Grade
The finding grade (
Bad,Warn,Fair,Good) as of the date the RRP was generated.- Geo Location
The geographical location where the unsupported operating system or browser was observed.
- Grade [Group]
The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.
- Observed Devices
The number of observed devices relating to the operating system and browser.
- OS/Browser
The operating system and browser associated with the finding, with version numbers.
- Sample IPs
Sample of the hosts detected using the operating system and browser.
Reference the Knowledge Base articles below for further information on the Mobile Software risk vector, findings, and remediation.
DMARC
Finding Details for DMARC:
- Finding Identifier
The asset and its status that identifies the finding.
- [Date] First Seen Date
Date the finding was first observed.
- [Date] Last Seen Date
Date the finding was most recently observed.
- Finding Grade
The finding grade (
Bad,Warn,Fair,Good) as of the date the RRP was generated.- Policy
Policy determines how email receivers should handle emails that fail authentication. A policy of “none” allows all emails to pass through.
- Percentage
The proportion of emails that the policy will be applied to.
- RUA Report Email
The mailbox to which aggregate statistics about authentication failures will be sent.
- RUF Report Email
A second list of report recipients. Use is uncommon overall, but, for example, may be used to request detailed forensic authentication reports.
- Details
Details the issues that affect the finding grade.
- April 8, 2025: Risk Remediation Plan available for Web Application Security.
- July 10, 2024: The Critical Vulnerability Management lifetime is 90 days.
- May 29, 2024: Certificate Serial Number replaces Finding Identifier as the TLS/SSL Certificates finding identifier.
Comments
Please sign in to leave a comment.