From a security finding to a tracked action plan
The EBMC GROUP team
A security finding opens a piece of work. To track its resolution, you need to specify what must change, who can act and how the result will be verified.
01
Describe the issue to address
Restate the finding and its scope. The systems involved, the conditions observed and the information available help teams understand the situation.
Where some elements remain uncertain, identify the checks needed before deciding on the action.
02
Agree on priorities
Security, technical and business owners must be able to examine the effects of the problem and the constraints on any intervention.
The priority chosen must be understood by the people who will carry out the work. It comes with an owner and a follow-up date.
03
Prepare the fix
An action may depend on a technical change, on access or on work by another provider. Record these dependencies and the approvals required.
The organisation’s change procedures still apply. They are used to prepare the work with the teams that run the environments.
04
Verify the result
Distinguish between an action planned, an action carried out and a fix verified. These states do not describe the same situation.
Specify what allows you to conclude and keep a record of the verification. If the problem persists, tracking must make it visible.
05
Keep information useful
A regular review looks at completed actions, delays and pending decisions. It is also the moment to revisit deadlines when the context changes.
A useful action plan lets teams carry the work forward and gives decision-makers the visibility they need to decide.