Skip to main content

External Monitoring: Severity Levels

Learn more about the severity levels on external monitoring findings and what they mean.

Kian Pace avatar
Written by Kian Pace
Updated over a week ago

What are Severity Levels?

Severity levels are used in External Monitoring to assess and categorise the potential impact and urgency of security vulnerabilities or misconfigurations. They help prioritise security issues and determine appropriate response times for remediation.

The following factors have been taken into consideration in setting the severity of monitoring findings:

  • Prioritisation: Higher severity issues should be addressed first

  • Resource Allocation: Critical and High issues require immediate attention and resources

  • Risk Management: Helps balance security needs with operational constraints

  • Compliance: Supports meeting regulatory and policy requirements

  • Communication: Provides clear framework for discussing security issues with stakeholders


Severity Levels

Critical

Absence of fundamental security controls or critical misconfigurations that create immediate, exploitable vulnerabilities. Direct impact on system security and data protection. No mitigating controls in place

High

Major security control gaps or misconfigurations that significantly weaken system security. Could lead to system compromise with minimal additional conditions. Partial mitigating controls may exist.

Medium

Security controls present but suboptimal. Vulnerabilities require specific conditions to exploit. Limited impact or requires elevated privileges. Basic security measures exist but need improvement.

Low

Minor security improvements needed. Core security intact but not following all best practices. Minimal real-world impact. Optimisation opportunities rather than direct vulnerabilities.

Informational

Informational findings provides useful context from scans conducted, or highlights a potential error. Unlike an infraction, an informational finding does not represent a breach of best security practice, but it may offer insights or suggest areas for review.


πŸ’‘ If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.

Did this answer your question?