Skip to main content
< All Topics
Print

Understanding Findings and Statuses

Purpose

This article explains what a finding is in CMSSPM, what the different finding statuses generally mean, and how those statuses affect review and scoring. The goal is to help administrators read scan results more confidently and understand the difference between something that is simply detected, something that needs action, and something that has already been addressed or formally handled.

Where to find it

You will encounter findings throughout the Overview Dashboard and the category-specific sections such as Core Security, Account Security, Browser Security, Email Security, and File Security. Findings are the basic units of information the plugin uses to show what was checked, what was discovered, and what may need attention.

What a finding is

A finding is an individual result produced by a check, scan, or evaluation performed by CMSSPM. In simple terms, it is the plugin’s way of recording that something specific was observed about the site’s current security posture.

A finding may represent:

  • a control that is correctly configured,
  • a weakness or missing protection,
  • a condition that needs review,
  • an informational result that helps provide visibility,
  • a previously identified item that has been mitigated or otherwise handled.

Not every finding means something is broken. Some findings exist to confirm protections are present, while others identify gaps or risks that should be reviewed.

Why statuses matter

Statuses are used to show the current state of a finding. They help distinguish between issues that are already acceptable, issues that are unresolved, and issues that may need human judgment rather than an automatic conclusion.

Without statuses, a list of findings would be harder to interpret because everything would appear equally unresolved. The status gives each finding context so administrators can understand what it means operationally and how it should influence prioritization.

Common status meanings

At a high level, findings may appear in states such as:

  • Pass — the check result is acceptable and does not count against the site.
  • Fail — the finding indicates a problem, gap, or unmet expectation.
  • Review — the result may need human interpretation, confirmation, or follow-up.
  • Informational — the result provides visibility but may not represent a direct scoring issue.
  • Mitigated — the finding has been intentionally marked as handled and is treated as passing for scoring purposes.

The exact labels or internal logic may vary by version or check type, but the general idea is that each status tells you whether the finding is acceptable, unresolved, pending review, or formally handled.

How mitigated findings work

In some environments, a finding may still appear even though the practical risk is already being addressed through another safeguard, a compensating control, or a documented risk decision. In that situation, an administrator can mark the finding as mitigated.

When a finding is marked as mitigated:

  • it is rated as passing for scoring purposes,
  • the user who applied the mitigation is logged,
  • a note or justification is stored with the finding,
  • the mitigation remains in effect until it is removed by an administrator.

This allows the system to preserve the record of the finding while also recognizing that it has been intentionally and auditable handled.

How findings affect scoring

Findings are one of the main inputs into the scoring model. In general, findings that are open, failing, or otherwise unresolved may lower category or overall scoring, while findings that pass do not reduce the score.

A mitigated finding is treated as passing for scoring purposes, but it is not erased from history. That distinction matters because CMSSPM is designed to support both operational scoring and documented decision-making.

Some findings may also be informational or weighted differently, which means not every finding affects the score in the same way.

How to use findings in practice

The best way to use findings is to treat them as a workflow, not just a report. Start by identifying the findings that are failing, heavily weighted, or concentrated in weaker categories, and then review the supporting detail before making changes.

A practical pattern is to:

  1. Review the finding and its status.
  2. Decide whether it needs remediation, review, or mitigation.
  3. Document the reason when mitigation is used.
  4. Make the necessary changes.
  5. Rescan and confirm the updated result.

This makes findings useful not only for detection, but for tracking improvement over time.

Notes and scope

This article is a plain-English overview of the finding model used by CMSSPM. It does not define the exact logic behind every status, every check, or every scoring rule.

Those details belong in the more technical documentation for individual checks, scoring behavior, and data handling. This page is meant to help users interpret what they are seeing when they work with findings day to day.

Table of Contents