TechKnowSurge
CompTIA CySA+ 2.5 NIST 800-53 CA-8 NIST 800-53 RA-5 ISC2 CISSP 7.8
VideoSecurityFree

Validation of Remediation

After implementing a control to address a vulnerability, validating that the fix actually worked is a critical step in the remediation process. The same methods used to discover the vulnerability — such as vulnerability scans or penetration tests — can typically be used to confirm it has been resolved.

Complete this video to capture a CTF flag worth 1 point.

About this video

Implementing a control to address a vulnerability is only part of the remediation process — confirming that the control actually works is equally important. Without a validation step, there is no assurance that the risk has been meaningfully reduced, even if a fix appears to have been applied. The principle here is straightforward: the same method used to detect the vulnerability is generally the most appropriate tool for verifying its resolution. For vulnerability scanning, this means simply rerunning the scan against the affected system after the fix is in place and confirming the finding no longer appears. For penetration testing, there are two common validation paths. The first involves using the pen test report itself, which typically documents the exact steps taken to identify and reproduce the vulnerability, allowing internal teams to attempt the same reproduction and confirm the issue is no longer exploitable. The second path applies to third-party engagements, where contracts often include a formal retesting provision. Under this arrangement, the organization is given a defined remediation window, and once fixes are applied, the testing firm is notified and returns to independently verify that the vulnerability has been resolved and no longer poses a risk.

What you'll learn

What's covered

Validating Security Controls

Aligned to

CompTIA CySA+
2.5 Explain concepts related to vulnerability response, handling, and management.
NIST 800-53
CA-8 Penetration Testing
RA-5 Vulnerability Monitoring and Scanning
ISC2 CISSP
7.8 Implement and support patch and vulnerability management

Key terms

Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing vulnerabilities in a system.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.
Vulnerability Scan Rerun
The process of executing a vulnerability scan a second time after remediation to confirm that a previously identified vulnerability has been successfully resolved.
Retesting
A follow-up assessment performed by a penetration tester after a vulnerability has been remediated, confirming that the fix is effective and the vulnerability no longer exists.

Topics

Vulnerability Remediation Vulnerability Scanning Penetration Testing Remediation Validation Cybersecurity

Transcript

If we put a control in place to mitigate some sort of vulnerability, then what we need to do next is validate that it actually worked.

This verification step, or validation step, is actually quite easy. With whatever step we use to discover that this was an issue, usually we can use that same process to verify that we have now fixed that issue. If we have run a vulnerability scan and then found a vulnerability on one of our systems, it is simple enough just to rerun that vulnerability scan and make sure that it is fixed.

Validating With Pen Testing

The other thing is, if we have pen testing, there are two ways we can validate that something has been fixed. One of the ways is that usually in the pen testing report it will explain exactly what the vulnerability is, and how they tested it, and how you can reproduce it. So what you can do is go back and reproduce the issue, or make sure that it is fixed, and validate that there is a fix in place with that.

The other thing is that usually when you are dealing with pen testing from a third party, then there will also be a clause in the contract saying that they will come and do a retesting. What that looks like is they will allow you a certain period of time to fix the issue, and then at the end of that period of time, or somewhere in that period of time, you tell them we fixed the issue, please do retesting. They will go back and retest and validate that the fix is now put into place and it is no longer a vulnerability.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →