Triage

The severity of the findings will dictate what resources are assigned to each flaw, and in what order each flaw needs to be remediated. Assign a severity rating to each flaw based on the security impact to the organization, and prioritize the high-severity findings to be fixed first.

If your organization uses Agile development tools such as the Atlassian suite (Jira, Confluence, and so on), you can also track these defects as issues, assign specific life cycle structures to them, and make judicious use of the different labels you can attach to them.

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.