Risk Remediation Plan Details by Risk Vector Jessica The Risk Remediation supports multiple risk vectors. Each plan provides risk vector-specific details to enable your remediation efforts. TLS/SSL Certificates TLS/SSL Configurations Web Application Security Critical Vulnerability Management Desktop Software Mobile Software Web Application Headers DMARC TLS/SSL CertificatesLists issues found in your TLS/SSL certificates. Potential findings include expired certificates, self-signed certificates, insecure signature algorithms, and large numbers of DNS names.Finding Details for TLS/SSL Certificates: Certificate Serial Number Unique identifier of the specific certificate with issues. [Date] Last Seen Date Date the finding was most recently observed. Finding Grade The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated. Finding Identifier The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding. This is not applicable to TLS/SSL Certificate findings. Refer to the Certificate Serial Number to identify TLS/SSL Certificate findings. Grade [Group] The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated. Issues Open issues that affect the finding grade. Reference the Knowledge Base articles below for further information on the TLS/SSL Certificates risk vector, findings, and remediation. TLS/SSL Certificates Risk Vector How is the TLS/SSL Certificates Risk Vector Assessed? TLS/SSL Certificate Findings TLS/SSL Finding Remediation & Remediation Verification TLS/SSL ConfigurationsLists issues found in your TLS/SSL configurations. Potential findings include insecure protocols, missing or non-standard certificates, and other issues in your TLS/SSL configurations.Finding Details for TLS/SSL Certificates: [Date] Last Seen Date Date the finding was most recently observed. Finding Grade The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated. Finding Identifier The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding. Grade [Group] The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated. Issues Open issues that affect the finding grade. Reference the Knowledge Base articles below for further information on the TLS/SSL Configurations risk vector, findings, and remediation. TLS/SSL Configurations Risk Vector How is the TLS/SSL Configurations Risk Vector Assessed? TLS/SSL Configuration Findings TLS/SSL Finding Remediation & Remediation Verification Web Application SecurityPerforms multiple assessments related to web application security. It provides information about components with known vulnerabilities, broken authentication and access control, sensitive data exposure, cross-site scripting prevention mechanisms, and security misconfigurations. Web Application Security Risk Vector How is the Web Application Security Risk Vector Assessed? Web Application Security Findings Finding details for Web Application Security: [Date] First Seen Date Date the finding was first observed. [Date] Last Seen Date Date the finding was most recently observed. Evidence Key Asset (domain:port) associated with the finding to remediate. Failed Evidence Count The amount of failed evidence associated with the finding. Finding Grade The finding grade (Bad, Warn, Fair, Neutral, Good) as of the date the RRP was generated. Total Evidence Count The total amount of evidence associated with the finding. Web App Security Test Name of the web application security test. Critical Vulnerability ManagementThe Critical Vulnerability Management Risk Remediation Plan (RRP) is available in two formats: a downloadable .csv or PDF and an interactive report within the Bitsight platform. The RRP considers a subset of unremediated findings to be fixed to calculate the projected grade. Please note that due to the nature of this risk vector, remediated findings will continue to impact your grade over time. Both formats list: remediation scenarios group vulnerabilities by severity and duration and project the future Critical Vulnerability Management grade based on each scenario. The PDF report offers an additional metric not currently available in the platform view: a "Total Findings Remediated Today" cumulative column within the scenarios. The Critical Vulnerability Management RRP provides an idea of trajectory and timescale based on different remediation scenarios. Due to the long lifetime period associated with this risk vector, grades improve slowly over time. This RRP can be leveraged to see how remediating the highest-impact Critical Vulnerabilities Management findings today would affect your grade over the its lifetime (90 days), assuming all findings in a scenario are remediated and no new findings are observed.Finding details for Critical Vulnerability Management: Finding Identifier The numerical ID associated the finding. Vulnerability Severity The Bitsight severity of the vulnerabilities associated with the findings. Groups are sorted from top to bottom based on severity. Learn more here Vulnerability The flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s security policy. Duration The amount of time a vulnerability was seen unpatched. Duration ranges are dynamically defined based on quartiles, meaning each Duration range has a similar number of findings across all vulnerability severities. Last Seen Date Date the vulnerability was last seen. 1 Day The projected grade improvement timeline if the scenario criteria are met.. 30 Days The projected grade improvement timeline if the scenario criteria are met.. 60 Days The projected grade improvement timeline if the scenario criteria are met.. 91 Days The projected grade improvement timeline if the scenario criteria are met.. Desktop SoftwareLists unsupported operating systems and browsers identified on desktop devices in your network that access the Internet. Potential findings include supported or unsupported operating systems and browsers.Finding Details for Desktop Software: [Date] First Seen Date Date the finding was first observed. [Date] Last Seen Date Date the finding was most recently observed. Details States whether the operating system and browser are supported or unsupported. Finding Grade The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated. Geo Location The geographical location where the unsupported operating system or browser was observed. Grade [Group] The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated. Observed Devices The number of observed devices relating to the operating system and browser. OS/Browser The operating system and browser associated with the finding, with version numbers. Sample IPs Sample of the hosts detected using the operating system and browser. Reference the Knowledge Base articles below for further information on the Desktop Software risk vector, findings, and remediation. Desktop Software Risk Vector How is the Desktop Software Risk Vector Assessed? Desktop Software Findings Mobile SoftwareLists unsupported operating systems and browsers identified on mobile devices in your network that access the Internet. Potential findings include supported and unsupported operating systems and browsers.Finding Details for Mobile Software: [Date] First Seen Date Date the finding was first observed. [Date] Last Seen Date Date the finding was most recently observed. Details States whether the operating system and browser are supported or unsupported. Finding Grade The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated. Geo Location The geographical location where the unsupported operating system or browser was observed. Grade [Group] The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated. Observed Devices The number of observed devices relating to the operating system and browser. OS/Browser The operating system and browser associated with the finding, with version numbers. Sample IPs Sample of the hosts detected using the operating system and browser. Reference the Knowledge Base articles below for further information on the Mobile Software risk vector, findings, and remediation. Mobile Software Risk Vector How is the Mobile Software Risk Vector Assessed? Mobile Software Findings Web Application HeadersLists issues found in your web application headers. Columns for specific headers indicate whether the header is missing, faulty, OK, or not applicable. This risk vector may include Neutral findings that need to be maintained in order to keep an A; they can’t become Good, but should be prevented from becoming or returning to Bad, Warn, or Fair. As an example, once a Bad insecure redirect finding is fixed, the Bad finding is squashed by a Neutral one, not a Good one. This Neutral grade must be maintained to keep an A grade. Learn more about this risk vector: Web Application Headers Risk Vector How is the Web Application Headers Risk Vector Assessed? Web Application Header Findings Web Application Header Finding Grades Finding Details for Web Application Headers: Cache-Control Indicates whether the Cache-Control header is missing. This header is required. Content-Security-Policy Indicates whether the Content-Security-Policy header is faulty, missing, or OK. This header is required. [Date] Last Seen Date Date the finding was most recently observed. Domain Domain associated with the finding. Finding Grade The finding grade (Bad, Warn, Fair, Good, Neutral) as of the date the RRP was generated. Grade [Group] The group of findings that need to be fixed to get from one grade to the next as of the date the RRP was generated. HTML Links If HTML links are present, indicates the number of record types. HTML Resources If HTML resources are present, indicates the count of external HTML resources. Insecure Authentication If an insecure authentication is present, indicates where. Insecure Redirect If an insecure redirect is present, indicates where. Port Port of the web application finding. Set-Cookie Indicates whether the Set-Cookie header is faulty, missing, or OK. This header is optional. Strict-Transport-Security Indicates whether the Strict-Transport-Security header is faulty, missing, or OK. This header is required. Title Title of the webpage the finding is on. X-Content-Type-Options Indicates whether the X-Content-Type-Options header is faulty, missing, or OK. This header is required. X-XSS-Protection Indicates whether the X-XSS-Protection header is faulty, missing, or OK. This header is optional. X-Frame-Options Indicates whether the X-Frame-Options header is faulty, missing, or OK. This header is optional. DMARCFinding Details for DMARC: Finding Identifier The asset and its status that identifies the finding. [Date] First Seen Date Date the finding was first observed. [Date] Last Seen Date Date the finding was most recently observed. Finding Grade The finding grade (Bad, Warn, Fair, Good) as of the date the RRP was generated. Policy Policy determines how email receivers should handle emails that fail authentication. A policy of “none” allows all emails to pass through. Percentage The proportion of emails that the policy will be applied to. RUA Report Email The mailbox to which aggregate statistics about authentication failures will be sent. RUF Report Email A second list of report recipients. Use is uncommon overall, but, for example, may be used to request detailed forensic authentication reports. Details Details the issues that affect the finding grade. April 8, 2025: Risk Remediation Plan available for Web Application Security. July 10, 2024: The Critical Vulnerability Management lifetime is 90 days. May 29, 2024: Certificate Serial Number replaces Finding Identifier as the TLS/SSL Certificates finding identifier. Related articles Action Plans: Risk Remediation Run a Risk Remediation Plan TLS/SSL Finding Remediation & Remediation Verification Certificate Authorities TLS/SSL Configuration Findings Feedback 0 comments Please sign in to leave a comment.