Skip to content

Finding

What is Finding?

A conclusion drawn from audit evidence that identifies a condition, criteria, cause, and effect. Audit findings range from major nonconformities to minor observations and recommendations for improvement.

Audit

Each of these is named in at least one of the same controls as finding. The number is how many controls name both.

What the standards actually require on finding

Requirements naming finding across 6 standards, quoted from the control text.

PTES7 controls

The technical report must detail each finding with severity, evidence, reproduction steps, business impact, and remediation guidance, supporting both engineering and audit consumption.

PTES-REP-2 · Technical Findings

Address CAT III (Category III, low severity) STIG findings, which degrade measures to protect against loss.

STIG-SEV-CAT3 · Category III (low severity) finding remediation

Aggregate security telemetry into standardised destinations such as S3 log archive buckets, Security Hub and a centralised SIEM so analysts and automation can correlate across sources.

SEC04-BP02 · Capture logs, findings, and metrics in standardized locations

Base the assessment on presented evidence and facts, ensuring depth and coverage support an accurate determination of control effectiveness.

IRAP-EV-3 · Objectivity of findings
CIS Controls v83 controls

Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.

CIS-18.3 · Remediate Penetration Test Findings

Questions people ask about finding

What is Finding?
A conclusion drawn from audit evidence that identifies a condition, criteria, cause, and effect. Audit findings range from major nonconformities to minor observations and recommendations for improvement.
Why is Finding important for compliance?
Finding is a key concept in Audit. Understanding finding helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Finding?
Finding appears in the requirement text of PTES, DISA Security Technical Implementation Guides (STIGs), AWS Well-Architected Security Pillar, Australia IRAP - Information Security Registered Assessors Program, CIS Controls v8. Across these standards we have identified 28 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Finding?
Explore our compliance framework pages to see how finding applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Finding applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.