Skip to main content

High Risk Triage

Use Security > High Risk to focus on critical and high-severity findings first.

  1. Filter to the production account or environment when needed.
  2. Open critical findings first.
  3. Confirm the affected resource and account.
  4. Assign remediation work in your normal issue tracker.
  5. Acknowledge reviewed findings.
  6. Accept risk only when your organization has approved the exception.
  7. Re-scan after fixes are merged or applied.

What not to do

  • Do not use Acknowledge to hide unresolved risk from compliance reviews.
  • Do not use Accept risk as a general backlog marker.
  • Do not assume a finding is resolved until a scan no longer detects it.

Next steps