An agreed ceiling for open vulnerability findings
A scanned host's open-vulnerability count should stay under the agreed threshold — a rising count with nobody remediating it is the gap between running a scanner and actually managing vulnerabilities.
Interpret the result in context
A count can help track backlog, but a low count does not mean low risk. Review severity alongside this control and avoid using the threshold as a substitute for prioritisation.
Configure the expectation.
Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.
Maximum open vulnerabilities
The open-vulnerability count a scanned host may carry before this control counts it as failing.
Review. Remediate. Verify.
Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.
- 01
Review the open findings and the client’s agreed threshold.
- 02
Prioritise remediation by severity and exposure.
- 03
Rescan and compare the updated count with the configured limit.
A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.
Make your baseline part of every client review.
Connect checks, findings and remediation to the same client record.