Summary
Submitting remediation requests (like "Other Resolution" with compensating controls, or any other resolution type) for findings that are no longer Active/Open are being declined almost immediately, the findings have already Departed at the time you submitted the request.
This applies to any issue type - Content Security Policy, SPF record missing... It is not specific to any one type of finding.
Why This Happens
Remediation requests (compensating controls, "report as fixed," etc.) are designed to apply to currently active/open findings. When an issue decays, it means our system stopped observing that specific condition on that asset as of a certain scan date.
If you submit a remediation request against an issue that has already decayed:
- There is nothing "active" left for our review team to validate against
- The request will be declined, regardless of how strong the justification is, because the issue instance is no longer open
Important: Our platform's interface does not currently block you from submitting a remediation request against a decayed issue - so you can still fill out and submit the form, but it will be declined on review since it doesn't meet the "active issue" requirement. We recognize this is confusing and are tracking an improvement to prevent this submission path in the future.
How to Tell if an Issue Is Open
Before submitting a remediation/compensating control request, check the specific finding's status and the date it stopped being observed:
- If the issue shows as Open, remediation requests can be submitted and reviewed normally.
ex: Starting point in https://platform.securityscorecard.io/#/scorecard/<scorecard_domain>/issues/OPEN - If the issue does not show in Open, it already departed - no action is needed from you to remove it from current open issues, since it's no longer counted as open.
What This Means for Findings That Have Already Departed
For findings that have already departed, you don't need a remediation request to stop them from counting against your score - they're already excluded from active/open issues by virtue of having departed. If they reappear in a future scan (a new instance is detected), at that point a remediation request can be submitted against it while it's active.
Recommended Process Going Forward
- Check issue status first — confirm whether the finding is Open/Active before submitting anything, regardless of issue type.
- For Open/Active findings: submit your remediation request (e.g., "Other Resolution" with compensating controls, including vendor correspondence about acceptable use determinations, or any other supporting justification) while the issue is still active - this gives it the best chance of being properly reviewed.
- For Departed findings: no remediation submission is needed. If you're concerned about recurrence, monitor for the issue reappearing in a future scan and submit your request at that time, while it's active.
Note on "Report as Fixed" (to avoid confusion with the decline behavior described above): this resolution path doesn't include a free-text explanation field - it is a simple way of stating "It is fixed and the issue is no longer observed." If it's still observed, then it is not fixed and therefore will be declined.