Skip to main content
Finin2minBatch 08 · Source checked 14 Aug 2026
Cyber Security & ResilienceUpdated 5 October 2026

Vulnerability Assessment for Public-Facing Portals: Remediation Priority and Closure Evidence

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

India-first finance, audit and risk workflow with primary-source anchors.

2-minute summary

Current position

Public-facing vulnerability findings should be managed as risk-ranked remediation items with attributable owners and closure evidence. CERT-In’s current guidance supports preventive cyber hygiene and vulnerability reduction, but a scan rating alone does not replace business-impact, exploitability and exposure analysis.

Control and decision map

#Control / decision step
1Maintain an authoritative inventory of public domains, APIs, IPs and cloud endpoints.
2Run approved vulnerability assessment / penetration testing at an appropriate frequency and after major changes.
3Risk-rank findings using exposure, exploitability and business impact.
4Assign owners and target dates; escalate overdue critical findings.
5Retest or otherwise validate remediation before closure.
6Trend recurrence and root causes so the same class of weakness does not repeatedly reappear.

Evidence pack

Worked example

A scan labels an authentication bypass as “high” and an outdated library as “critical.” The bypass affects the production admin portal while the library is on an isolated test host. The remediation plan prioritises the production exposure first, documents a temporary restriction, then patches and retests both findings.

Common mistakes

  1. Ranking only by scanner CVSS score.
  2. Closing findings on verbal assurance.
  3. Leaving shadow APIs / domains outside the scan inventory.
  4. Accepting recurring vulnerabilities without root-cause correction.

Frequently asked questions

Does a clean scan prove the portal is secure?

No. It is one control among secure design, monitoring, access control and incident response.

What should closure evidence include?

A validated fix or documented compensating control and retest where appropriate.

How should exceptions be handled?

Time-bound, risk-approved and monitored until the underlying issue is resolved.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, contract, facts and professional judgement before acting.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.