Skip to main content

Test Results and Remediation

Understand test results, interpret failures, and follow remediation guidance to maintain continuous compliance.

John Ozdemir avatar
Written by John Ozdemir
Updated over a month ago

Test results reveal your actual compliance posture. Effective remediation keeps controls working and maintains certification readiness.

Understanding Test Results

Each test produces one of three outcomes:

Passing (Green): Control is working correctly, no action needed

Failing (Red): Control has issues requiring immediate remediation

Needs Attention (Yellow): Partial compliance or missing evidence requires review

Test Result Details

Click any test to view:

Result Summary: Status, last run time, pass/fail count

Specific Findings: Exactly what passed or failed

Affected Items: Which users, systems, or resources have issues

Result History: Trends and patterns over time

Example: MFA test shows 45 users compliant, 3 users without MFA enabled (with specific email addresses listed).

Common Failure Causes

Configuration Drift: Settings changed since last test

Process Gaps: Periodic requirements overdue (access reviews, training)

Integration Issues: Connection problems preventing verification

Incomplete Setup: New systems or users not properly configured

The Remediation Tab

Every test includes guidance for fixing failures:

Purpose: Why this control matters

How It Runs: What the test checks

Success Criteria: Requirements for passing

How to Remediate: Step-by-step fix instructions with console steps or CLI commands

[Screenshot needed: Remediation tab with fix instructions]

Remediation Workflow

  1. Assess Impact: Determine urgency based on risk level

  2. Identify Root Cause: Review failure details and determine what changed

  3. Implement Fix: Follow remediation guidance

  4. Verify Resolution: Re-run test to confirm fix

  5. Document: Add notes explaining what was fixed and why

Remediation Priority

Critical: Fix immediately - production security or active audit impact

High: Fix this week - important controls or multiple framework impact

Medium: Fix this month - standard controls, limited scope

Low: Fix this quarter - administrative or documentation issues

Time to Remediation

DSALTA tracks how quickly failures are resolved:

  • Demonstrates responsive security practices

  • Important metric for auditors

  • Reveals program maturity

  • Helps identify process improvements

Preventing Failures

Review before changes: Check compliance impact

Set up alerts: Catch drift early

Regular reviews: Identify issues proactively

Team training: Ensure compliance awareness

Did this answer your question?