How are remediation tickets created?
A remediation policy determines the criteria required for a remediation ticket to be created. A remediation policy can be set up so that tickets are automatically created when vulnerabilities of a certain criticality are found on certain hosts. The remediation policy also determines to whom remediation tickets are assigned as well as the expected ticket resolution date. The remediation workflow consists of a series of remediation policies. Each policy is evaluated and action is taken using a top-down, or first to last, process flow, therefore there can be several remediation policies for each host and/or each vulnerability. The first remediation policy that is a match in the workflow is processed and the rest are ignored, much like a firewall rule base.