Skip to main content

Treatment Collaboration

Treatment collaboration turns a finding into managed work.

What a treatment can include

A treatment may define:
  • the intended remediation approach,
  • an owner,
  • work status,
  • target timing,
  • client actions,
  • evidence expectations,
  • notes and activity,
  • review or verification steps.
Cyber Op Source may publish a recommended treatment based on the finding and engagement context. A recommendation is intended to guide remediation. It does not prevent the client from identifying a better implementation approach that achieves the same security or risk objective.

Proposing an alternative

Where proposal functionality is enabled:
  1. review the original treatment objective,
  2. describe the alternative clearly,
  3. explain why it is appropriate,
  4. identify material dependencies or tradeoffs,
  5. submit the proposal for review.
Avoid proposals that only restate the current condition without explaining how the risk will be addressed.

Client actions

A treatment can contain concrete actions assigned to client participants. When completing an action:
  • perform the actual work first,
  • add a concise completion summary,
  • provide evidence when requested or appropriate,
  • avoid marking work complete solely to clear the dashboard.

Notes

Use notes for information that helps the treatment record, such as:
  • implementation progress,
  • dependency updates,
  • clarifications,
  • planned dates,
  • ownership changes,
  • obstacles requiring coordination.
Do not use treatment notes as a substitute for an incident-response channel or for transmitting secrets.

Verification and closure

Cyber Op Source may review completed work and evidence before accepting the treatment outcome or closing the associated finding. This separation of duties is intentional: client participants can perform and document remediation, while assessment-side verification remains governed.

Activity history

The activity timeline provides a readable history of meaningful events. Use it to determine what changed and when before adding a duplicate note or resubmitting an action.