Remediation Prioritisation
Definition
The process of ordering vulnerability remediation by risk. Factors include CVSS base score, asset criticality, threat intelligence about active exploitation, and compensating controls already in place. The auditor reviews whether the organisation's prioritisation method is documented and consistently applied.
- Domain
- Vulnerability management
- Key input
- CVSS base score
- Also weighs
- Asset criticality, active exploitation
- Audit focus
- Documented, consistent method
Common questions
Why isn't CVSS score alone enough to prioritise fixes?+
A high CVSS score on a low-value, isolated asset can matter less than a moderate score on a system holding sensitive data or facing active exploitation, so criticality and threat intelligence are weighed alongside the score.
What does an auditor check about an organisation's prioritisation method?+
Whether the criteria are written down and actually applied the same way across findings, rather than remediation order being decided informally case by case.
Related terms
- Approved Scanning Vendor (ASV)
- An organisation qualified by the PCI Security Standards Council to conduct external vulnerability scans of cardholder data environments. PCI-DSS requirement 11.3.2 mandates...
- Audit Evidence
- Any information the auditor uses to draw conclusions about a control. To be acceptable, audit evidence must be sufficient (enough of it),...
- CVSS (Common Vulnerability Scoring System)
- An open standard maintained by FIRST (Forum of Incident Response and Security Teams) that assigns a numeric score from 0 to 10...
- Risk Acceptance
- A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
- Vulnerability Assessment
- A systematic process of identifying, classifying, and prioritising security weaknesses in systems, software, and infrastructure. Produces a list of findings with severity...