Keep the original finding and affected asset context, the approved treatment, change or patch evidence, implementation time, exceptions or compensating controls, post-change validation, remaining exposure and reviewer/owner. Closing a work item is not the same as proving the vulnerability condition changed.
External reference
NIST defines enterprise patch management as identifying, prioritising, acquiring, installing and verifying the installation of patches, updates and upgrades across the organisation.
Primary source →Practical workflow
Retain the original state
Preserve the finding identifier, asset, vulnerable version/configuration, discovery time and risk context that triggered treatment.
Record the treatment
Capture patch, upgrade, configuration change, isolation, compensating control, acceptance or other approved action with an accountable owner.
Record implementation evidence
Keep deployment/change evidence, timestamps, targeted assets and any failures or deferred systems.
Validate the new state
Re-scan, re-query, inspect configuration or otherwise verify that the original condition no longer applies to the intended scope.
Close with residual context
Retain exceptions, unresolved assets, residual risk, rollback concerns and the reviewer who accepted closure.
Relevant Cybatar sources
Claim boundary
A closed remediation record does not prove that every affected asset was fixed, that no alternative exploit path exists, or that the environment is secure. Validation scope and evidence quality must remain explicit.
These pages are Cybatar-authored exposure-management and vulnerability-prioritisation guidance. CISA, FIRST and NIST are external sources. References do not create certification, endorsement, guaranteed exploit prediction, guaranteed remediation outcomes or proof that a vulnerability affects a specific environment.