Remediation Workspace
The Remediation Workspace is the primary client collaboration environment for published findings and remediation activity. It is designed around the lifecycle of a finding after Cyber Op Source has determined that the client should be able to review and act on it.Core workflows
The workspace can support:- reviewing published findings,
- viewing recommended treatments,
- proposing treatment alternatives,
- working with assigned treatment owners,
- completing client actions,
- adding notes and progress updates,
- providing evidence,
- responding to evidence requests,
- reviewing activity history,
- working with documents and plans,
- using guided evidence or policy-assistance features when enabled.
Published findings
A finding becomes visible in the Remediation Workspace through a governed publication process. Client users do not directly modify Cyber Op Source’s internal finding record. This separation allows the assessment team to preserve internal working material while presenting a stable, authorized client view.Treatments
A treatment represents the work used to address a finding or reduce the associated risk. Treatments may include an owner, target state, status, actions, supporting evidence, and activity history. Client collaboration can include proposing treatment changes or completing assigned actions. Cyber Op Source retains the trusted assessment-side processing and verification responsibilities defined for the engagement.Evidence
Evidence may be requested or voluntarily supplied to demonstrate progress or completion. Good evidence is relevant, attributable, and sufficient to support the specific control or remediation claim. Examples can include:- policy or procedure excerpts,
- configuration screenshots,
- reports or exports,
- implementation records,
- approved change documentation,
- test results,
- training records,
- architecture or workflow documentation.
Activity timeline
Activity history helps users understand what happened over time. Client-facing activity is presented as meaningful human-readable events rather than raw system objects. Examples may include:- treatment released to the client,
- client note added,
- proposal submitted,
- action completed,
- evidence provided,
- status updated,
- review completed.