Learn · Governance, Risk, and Security Communication · Lesson 1

Writing Defensible Security Findings

Separate evidence, observation, judgment, scope, uncertainty, recommendation, and validation requirements.

Summary

A finding is a bounded statement about a condition and its evidence, not a scanner line or a complete conclusion. A defensible record lets another reviewer trace what was observed, what was inferred, what remains uncertain, and what evidence would change the recommendation.

Learning objectives and prerequisites

Use basic vulnerability and incident workflow vocabulary. Identify fact, observation, evidence, source, timestamp, provenance, inference, analytic judgment, assumption, conclusion, recommendation, confirmed scope, potential scope, and unknown scope.

Why this matters

A scanner result is evidence, not the complete finding. A CVE does not prove local applicability; severity does not equal treatment priority; exploit evidence does not prove local compromise; and absence of logs does not prove absence of activity. Unsupported certainty weakens a finding.

Core concepts and distinctions

Separate condition, criteria, affected scope, business context, technical severity, impact, likelihood, exposure, applicability, residual risk, implementation evidence, validation evidence, owner, target date, and closure state. Planned action is not completed remediation, and implementation is not validation.

Guided workflow

  1. Define the exact issue or decision question.
  2. Identify asset, service, identity, or process and record evidence with source and timestamp.
  3. Separate facts, judgments, and assumptions; validate local applicability.
  4. State confirmed, potential, and unknown scope, then describe exposure and credible exploit context.
  5. State impact, uncertainty, limitations, bounded conclusion, recommendation, owner, target date, and validation requirement.
  6. Review for unsupported claims and ambiguity.

Fictional worked example

A fictional scanner detects a public application version. A vendor advisory and affected-version evidence support one confirmed service; two services are potentially affected because runtime inventory is incomplete. A public exploit report increases the need for validation but there is no evidence of compromise. Poor wording says, "All services are compromised and must be patched immediately." Better wording names one confirmed service, potential scope, source-backed exploit context, remediation owner, target date, and version plus endpoint validation needed for closure.

Decision exercise

Review fictional statements for unsupported certainty, missing scope, mixed fact and judgment, vague recommendations, and missing validation evidence. Rewrite them as title, condition, evidence, scope, impact, confidence and uncertainty, recommendation, ownership, and validation requirement. This is a practical structure, not a universal audit or legal standard.

Knowledge checks and answer explanations

  1. Is a scanner result a complete finding? No; it needs scope, provenance, interpretation, limitations, and follow-up evidence.
  2. Does a CVE prove local applicability? No; product, version, feature, and deployment evidence are separate.
  3. Does severity equal priority? No; priority also depends on local context and treatment readiness.
  4. Does exploit evidence prove compromise? No; compromise needs separate local evidence.

Common misconceptions

Potential scope is confirmed scope, missing logs prove no activity, a target date proves completion, or a recommendation is an approved decision.

Practical takeaway

Write compactly: condition, evidence, scope, impact, analysis, confidence and uncertainty, recommendation, owner, and validation evidence.

Related content

Investigation Evidence Quality, Executive Vulnerability Briefing, Exploit Evidence Validation, Brief Builder, CVE Intake and Enrichment Review, and Curated CVEs.

Limitations

This lesson cannot prove local impact, exposure, compromise, remediation, approval, or complete scope in any environment.

Last reviewed: Unknown. Recheck source-backed and local evidence before acting.