Why: Risk-ranked remediation is a standing risk-response mechanism for one class of findings: every vulnerability gets a decision — fix within a window, defer with an owner and a date, or compensate — which is the explicit response behavior this new requirement asks for.
What this does not claim: The requirement spans findings from security assessments, monitoring, and audits — not only vulnerability scans — so most of its scope arrives through channels the practice never sees. Response options beyond mitigation (acceptance, avoidance, transfer) and the stated risk tolerance those decisions are made within are separate work the practice does not produce.
- Attach an explicit decision — remediate, defer, or compensate — to every vulnerability finding
- Record deferrals as risk acceptances with a named owner and expiry
- The findings queue showing per-finding decisions and owners
- Dated deferral and acceptance records
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06