Public Guide

Review and Prioritize Findings

Prioritize remediation using risk, exploitability, ownership, and tenant policy tuning so teams fix what matters first. Audience: Security triage teams, engineering leads, and service owners. Typical setup time: Ongoing, daily review recommended.

Start herejourney

Use this if

Prioritize remediation using risk, exploitability, ownership, and tenant policy tuning so teams fix what matters first.

Audience: Security triage teams, engineering leads, and service ownersTypical time: Ongoing, daily review recommended

Start here

Step 6 of 7

Recommended
1
2
3
4
5
6
7

Before You Begin

  • Confirm you have access to Findings, Trends, and ownership assignment actions.
  • Align severity-to-deadline policy with engineering leads before triage.
  • Decide escalation path for KEV and internet-exposed critical findings.

Do this now

1

Step 1

Triage highest-risk findings first

Use risk score and exploit context to build an actionable queue.

  • Start with Highest risk, then pivot through Recently seen, Exploit validated, CISA KEV, SLA breached, and Regressions.
  • Use the Open status view to focus on new, in-progress, and reopened risk.
  • Run Adversarial Exposure Validation (AEV) on-demand for the top queue and review validated/not-validated outcomes.
  • Filter by AEV state to separate immediately exploitable paths from inconclusive candidates.
  • Review affected assets to identify production or internet-facing impact.

What success looks like

Review affected assets to identify production or internet-facing impact.

2

Step 2

Remediate findings as themes

Group the current queue by asset, CVE, or scanner rule so one coordinated fix can close repeated risk.

  • Switch from List to Themes and choose Asset, CVE, or Rule.
  • Compare finding volume, maximum risk, critical/high counts, KEV, AEV, SLA, and affected-asset breadth.
  • Open View findings to inspect the exact bucket before changing lifecycle state.
  • Use Take action to preview eligibility before assigning, starting, reopening, suppressing, or resolving the theme.
  • Review skipped and failed counts after the background action completes.

What success looks like

A high-volume theme is reviewed and its eligible findings have a confirmed owner or lifecycle action.

3

Step 3

Assign ownership and deadlines

Every finding should have one accountable owner and a target resolution date.

  • Assign findings to service owners from impacted teams.
  • Set due dates aligned to your internal SLA policy.
  • Capture remediation notes and fix version targets.

What success looks like

Capture remediation notes and fix version targets.

4

Step 4

Tune tenant scoring policy safely

Use simulation before publishing weight changes so queue movement is intentional and auditable.

  • Open `/findings/risk-scoring` and review the current tenant policy version.
  • Run a simulation to inspect projected score, rank, and priority changes before publishing.
  • Record a change summary for every publish and use rollback if the new ordering does not match operating expectations.

What success looks like

Record a change summary for every publish and use rollback if the new ordering does not match operating expectations.

5

Step 5

Track closure and recurring drift

Monitor trend movement to verify risk is declining over time.

  • Review trend and backlog metrics at least weekly.
  • Track reopened findings and recurring high-severity issues.
  • Escalate overdue remediation items in operating reviews.

What success looks like

Weekly trend review confirms whether high-risk backlog and regressions are declining.

What success looks like

  • Each critical/high finding has an accountable owner and due date.
  • Repeated findings are reviewed by asset, CVE, or rule and bulk actions have no unexplained skips.
  • Weekly trend review shows decreasing open high-risk backlog.

Continue

Keep your rollout moving with the next recommended step.

What To Do After First Findings
Review and Prioritize Findings | BlackShield Docs