What are Severity Levels?
Severity levels are used in External Monitoring to assess and categorise the potential impact and urgency of security vulnerabilities or misconfigurations. They help prioritise security issues and determine appropriate response times for remediation.
The following factors have been taken into consideration in setting the severity of monitoring findings:
Prioritisation: Higher severity issues should be addressed first
Resource Allocation: Critical and High issues require immediate attention and resources
Risk Management: Helps balance security needs with operational constraints
Compliance: Supports meeting regulatory and policy requirements
Communication: Provides clear framework for discussing security issues with stakeholders
Severity Levels
Critical | Absence of fundamental security controls or critical misconfigurations that create immediate, exploitable vulnerabilities. Direct impact on system security and data protection. No mitigating controls in place |
High | Major security control gaps or misconfigurations that significantly weaken system security. Could lead to system compromise with minimal additional conditions. Partial mitigating controls may exist. |
Medium | Security controls present but suboptimal. Vulnerabilities require specific conditions to exploit. Limited impact or requires elevated privileges. Basic security measures exist but need improvement. |
Low | Minor security improvements needed. Core security intact but not following all best practices. Minimal real-world impact. Optimisation opportunities rather than direct vulnerabilities. |
Informational | Informational findings provides useful context from scans conducted, or highlights a potential error. Unlike an infraction, an informational finding does not represent a breach of best security practice, but it may offer insights or suggest areas for review. |
π‘ If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.