An open VAPT finding does not automatically determine the audit outcome, but it must never be hidden or casually marked closed. Apply the organization’s risk-treatment process: understand impact and exposure, implement immediate safeguards, assign remediation, document accountable acceptance where permitted, and discuss framework-specific implications with the auditor or assessor. Some requirements do not allow risk acceptance as a substitute.
Start with the assurance requirement
Identify the control, policy, contract and regulator affected by the open finding. Confirm whether the requirement permits exceptions, compensating controls or delayed remediation and who has authority to approve them.
Record the requesting party, framework or contract clause, assessment boundary, evidence period, due date and decision the evidence must support. Confirm the interpretation with the auditor, assessor or customer where possible. A penetration test can contribute strong assurance, but a report cannot guarantee an audit outcome or replace the organization’s wider control evidence.
Create a traceable evidence index
- Requirement or control identifier and the assertion being supported.
- In-scope systems, interfaces, environments, identities and important exclusions.
- Assessment dates, methodology, tester identity or competence evidence and authorization.
- Finding identifiers, severity rationale, remediation owner, status and exception reference.
- Retest evidence, closure date, residual risk and the location of protected technical detail.
Keep the original finding and severity basis, affected scope, exploitability and exposure, asset and data criticality, remediation options, compensating controls, validation evidence, owner, target date, formal acceptance, expiry, review triggers, auditor communication and retest plan.
Validate the finding and current exposure
Risk treatment begins with accurate evidence, not deadline pressure.
- Confirm reproducibility.
- Identify affected assets.
- Assess production reachability.
- Map data and business impact.
- Check active exploitation indicators.
Preserve the tester’s original conclusion and record any later contextual analysis separately.
Choose the treatment explicitly
Remediate, mitigate, avoid, transfer or accept according to policy and requirement.
- Compare durable fixes.
- Identify immediate containment.
- Evaluate compensating controls.
- Assign decision authority.
- Record residual risk.
Do not call a WAF rule or monitoring alert a permanent fix unless it removes the root condition and passes retest.
Document accountable acceptance
A valid exception is specific, time-bound and owned by someone with appropriate authority.
- State rationale.
- Name approver and owner.
- Set expiry date.
- Define review triggers.
- Record remediation commitment.
Link the exception to the finding ID and affected scope; avoid broad reusable waivers.
Validate compensating controls
A proposed safeguard needs evidence that it reduces the relevant attack path.
- State intended risk reduction.
- Test enforcement.
- Monitor operation.
- Identify bypass limits.
- Assign maintenance owner.
Framework-specific criteria for compensating controls may be strict; seek assessor agreement rather than assuming equivalence.
Prepare transparent audit communication
Give reviewers a coherent status without exposing unnecessary exploit detail.
- List open findings.
- Show treatment decision.
- Provide control evidence.
- Explain dates and dependencies.
- Reference retest plan.
Never backdate acceptance, alter the original report or imply closure where only treatment approval exists.
Operate the evidence workflow
- Confirm the requirement, evidence owner, reviewer and deadline.
- Freeze a versioned scope and record every approved change or exclusion.
- Collect assessment artifacts through a controlled, access-limited repository.
- Map findings and closure evidence without changing the tester’s original conclusion.
- Perform a completeness and consistency review before external sharing.
Hold a risk review with security, system owner, GRC and authorized management. Escalate findings that affect mandatory requirements, customer commitments or active exposure immediately.
Preserve evidence integrity and confidentiality
Keep the original signed or versioned report, evidence manifest and retest artifacts. Redact copies rather than overwriting the source. Restrict exploit steps, credentials, personal data and internal architecture to approved recipients. Record who received which version, under what authorization and for what purpose.
Quality checks before reliance
- Scope, dates and environment agree across the report, statement of work and evidence index.
- Every closure claim points to a finding identifier and retest result.
- Exceptions name an owner, rationale, review date and compensating controls.
- Control mappings distinguish direct evidence from supporting context.
- Sanitized summaries do not imply broader coverage or stronger closure than the source report.
Use framework language carefully
Use the applicable official control text and assessor guidance as the authority. The NIST Technical Guide to Information Security Testing and Assessment supports disciplined assessment planning and reporting, while the OWASP Web Security Testing Guide provides application testing context. Neither substitutes for framework-specific interpretation by the responsible auditor or assessor.
Report the assurance conclusion
Use an open-findings register with stable IDs, current status, affected controls, owner, action, compensating-control evidence, approval, expiry and retest date. Include a protected technical appendix.
State observed facts, limitations and management decisions separately. Do not use “compliant,” “certified,” “secure” or “all vulnerabilities fixed” unless the authorized assessor and evidence genuinely support that precise claim.
The GRC decision
Handle pre-audit open findings through transparent, policy-governed treatment and early assessor communication. Acceptance may explain a decision; it cannot guarantee auditor acceptance or convert open risk into technical closure.
Ask WIMD to review open VAPT findings and prepare clear remediation, compensating-control and retest evidence.
