SAST and SCA flooded the backlog after a civic services scan. How should the team prioritize remediation?
Select an answer to reveal the explanation.
Short Explanation
Not every finding is a five-alarm fire at city hall. Rank what an attacker could actually use against what would hurt residents most—outages, data loss, fraud. Exploitability plus civic impact beats sorting by vibes or file name.
Full Explanation
Effective software risk mitigation requires analyzing findings for exploitability, affected assets, and business or citizen-service impact rather than treating all alerts equally. Prioritization focuses scarce remediation capacity on highest residual risk. This aligns Domain 8 measurement of security effectiveness with organizational risk management.