Risk Remediation Plan Details by Risk Vector

The Risk Remediation supports multiple risk vectors. Each plan provides risk vector-specific details to enable your remediation efforts.

TLS/SSL Certificates

Lists issues found in your TLS/SSL certificates. Potential findings include expired certificates, self-signed certificates, insecure signature algorithms, and large numbers of DNS names.

Finding Details for TLS/SSL Certificates:

Certificate Serial Number

Unique identifier of the specific certificate with issues.

[Date] Last Seen Date

Date the finding was most recently observed.

Finding Grade

The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated.

Finding Identifier

The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding.

This is not applicable to TLS/SSL Certificate findings. Refer to the Certificate Serial Number to identify TLS/SSL Certificate findings.

Grade [Group]

The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.

Issues

Open issues that affect the finding grade.

Reference the Knowledge Base articles below for further information on the TLS/SSL Certificates risk vector, findings, and remediation.

TLS/SSL Configurations

Lists issues found in your TLS/SSL configurations. Potential findings include insecure protocols, missing or non-standard certificates, and other issues in your TLS/SSL configurations.

Finding Details for TLS/SSL Certificates:

[Date] Last Seen Date

Date the finding was most recently observed.

Finding Grade

The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated.

Finding Identifier

The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding.

Grade [Group]

The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.

Issues

Open issues that affect the finding grade.

Reference the Knowledge Base articles below for further information on the TLS/SSL Configurations risk vector, findings, and remediation.

Web Application Security

Performs multiple assessments related to web application security. It provides information about components with known vulnerabilities, broken authentication and access control, sensitive data exposure, cross-site scripting prevention mechanisms, and security misconfigurations.

Finding details for Web Application Security:

[Date] First Seen Date

Date the finding was first observed.

[Date] Last Seen Date

Date the finding was most recently observed.

Evidence Key

Asset (domain:port) associated with the finding to remediate.

Failed Evidence Count

The amount of failed evidence associated with the finding.

Finding Grade

The finding grade (Bad, Warn, Fair, Neutral, Good) as of the date the RRP was generated.

Total Evidence Count

The total amount of evidence associated with the finding.

Web App Security Test

Name of the web application security test.

Critical Vulnerability Management

The Critical Vulnerability Management Risk Remediation Plan (RRP) is available in two formats: a downloadable .csv or PDF and an interactive report within the Bitsight platform. The RRP considers a subset of unremediated findings to be fixed to calculate the projected grade. Please note that due to the nature of this risk vector, remediated findings will continue to impact your grade over time. 

Both formats list: 

  • remediation scenarios
  • group vulnerabilities by severity and duration
  • and project the future Critical Vulnerability Management grade based on each scenario. 

The PDF report offers an additional metric not currently available in the platform view: a "Total Findings Remediated Today" cumulative column within the scenarios. 

The Critical Vulnerability Management RRP provides an idea of trajectory and timescale based on different remediation scenarios. Due to the long lifetime period associated with this risk vector, grades improve slowly over time. This RRP can be leveraged to see how remediating the highest-impact Critical Vulnerabilities Management findings today would affect your grade over the its lifetime (90 days), assuming all findings in a scenario are remediated and no new findings are observed.

Finding details for Critical Vulnerability Management:

Finding Identifier

The numerical ID associated the finding.

Vulnerability Severity

The Bitsight severity of the vulnerabilities associated with the findings. Groups are sorted from top to bottom based on severity. Learn more here

Vulnerability

The flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s security policy.

Duration

The amount of time a vulnerability was seen unpatched. Duration ranges are dynamically defined based on quartiles, meaning each Duration range has a similar number of findings across all vulnerability severities.

Last Seen Date

Date the vulnerability was last seen.

1 Day

The projected grade improvement timeline if the scenario criteria are met..

30 Days

The projected grade improvement timeline if the scenario criteria are met..

60 Days

The projected grade improvement timeline if the scenario criteria are met..

91 Days

The projected grade improvement timeline if the scenario criteria are met..

Desktop Software

Lists unsupported operating systems and browsers identified on desktop devices in your network that access the Internet. Potential findings include supported or unsupported operating systems and browsers.

Finding Details for Desktop Software:

[Date] First Seen Date

Date the finding was first observed.

[Date] Last Seen Date

Date the finding was most recently observed.

Details

States whether the operating system and browser are supported or unsupported.

Finding Grade

The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated.

Geo Location

The geographical location where the unsupported operating system or browser was observed.

Grade [Group]

The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.

Observed Devices

The number of observed devices relating to the operating system and browser.

OS/Browser

The operating system and browser associated with the finding, with version numbers.

Sample IPs

Sample of the hosts detected using the operating system and browser.

Reference the Knowledge Base articles below for further information on the Desktop Software risk vector, findings, and remediation.

Mobile Software

Lists unsupported operating systems and browsers identified on mobile devices in your network that access the Internet. Potential findings include supported and unsupported operating systems and browsers.

Finding Details for Mobile Software:

[Date] First Seen Date

Date the finding was first observed.

[Date] Last Seen Date

Date the finding was most recently observed.

Details

States whether the operating system and browser are supported or unsupported.

Finding Grade

The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated.

Geo Location

The geographical location where the unsupported operating system or browser was observed.

Grade [Group]

The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated.

Observed Devices

The number of observed devices relating to the operating system and browser.

OS/Browser

The operating system and browser associated with the finding, with version numbers.

Sample IPs

Sample of the hosts detected using the operating system and browser.

Reference the Knowledge Base articles below for further information on the Mobile Software risk vector, findings, and remediation.

DMARC

Finding Details for DMARC:

Finding Identifier

The asset and its status that identifies the finding.

[Date] First Seen Date

Date the finding was first observed.

[Date] Last Seen Date

Date the finding was most recently observed.

Finding Grade

The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated.

Policy

Policy determines how email receivers should handle emails that fail authentication. A policy of “none” allows all emails to pass through.

Percentage

The proportion of emails that the policy will be applied to.

RUA Report Email

The mailbox to which aggregate statistics about authentication failures will be sent.

RUF Report Email

A second list of report recipients. Use is uncommon overall, but, for example, may be used to request detailed forensic authentication reports.

Details

Details the issues that affect the finding grade.

  • April 8, 2025: Risk Remediation Plan available for Web Application Security.
  • July 10, 2024: The Critical Vulnerability Management lifetime is 90 days.
  • May 29, 2024: Certificate Serial Number replaces Finding Identifier as the TLS/SSL Certificates finding identifier.
Was this article helpful?
2 out of 3 found this helpful

Comments

0 comments

Please sign in to leave a comment.