REM / REM-06
Remediation retesting and closure validation
Targeted verification that identified vulnerabilities or gaps have been fixed, maintaining a clear link to the original finding.

WHEN IT HELPS
A focused response
to a defined need.
CISO, CIO or contracting customer; audit closure, customer assurance or acceptance of a remediation workstream.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Review fixes
- replay authorised scenarios
- targeted regression checks and classification of remaining gaps
Deliverables
- Retest report
- fixed, partially fixed, not fixed or not verifiable status
- supporting evidence
Acceptance evidence
Each closure status has evidence and a date; an impossible check is marked “not verifiable”.
DELIVERY
How the work is structured.
Approach
Validate findings; prioritise and assign; prepare changes and rollback; implement or coach; retest and document closure.
Prerequisites & responsibilities
Customer: approvals, change windows, application owners and business acceptance. Provider: implementation only when included; otherwise advice, coordination and evidence review.
Scope factors
Number and complexity of root causes, environments, dependencies and retests. Time and materials, scoped package or recurring support; effort confirmed after report review.
Questions to clarify
Which specific findings? Which version changed? Are required accounts and environments available?
IMPORTANT BOUNDARIES
A retest is not a new full audit; major redesign may require a new scope.
Findings remain explicitly classified as fixed, mitigated, accepted, deferred or unverified. Closure is supported by evidence rather than the administrative status of a ticket.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A software vendor fixes five findings before release. Project: repeat scenarios from the original report. Target outcome: four closures and one remaining issue if that is observed; results are not forced to meet a sales deadline.
Scenario 02
A company says a firewall rule is fixed, but the environment is unavailable. Project: request evidence or reschedule testing. Target outcome: an honest “not verifiable” status until checked, not an unsupported attestation.
Technology and reference context
Original assessment scenarios and tools, adapted to approved changes.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
