## Purpose

**Use this tracker to manage cybersecurity improvements identified through:**

- Risk assessments
- Incidents
- Post-incident reviews
- Vulnerability assessments
- Access reviews
- Backup tests
- Vendor reviews
- Security exercises
- Audits
- Leadership reviews
- Employee reports

The objective is to make sure identified problems result in assigned, tracked, and verified improvements.

## Recommended Tracker Fields

|Field|Description|
|---|---|
|Action ID|Unique reference|
|Date Raised|When the issue was identified|
|Source|Risk assessment, incident, audit, test, review, etc.|
|Finding / Gap|What is wrong or missing|
|Required Action|What needs to be done|
|Risk / Impact|Why the action matters|
|Priority|Critical, High, Medium, Low|
|Owner|Person accountable|
|Supporting Team / Vendor|People helping complete it|
|Target Date|Expected completion|
|Status|Not Started, In Progress, Blocked, Complete, Accepted|
|Evidence Required|Proof that the action was completed|
|Verification Method|How effectiveness will be checked|
|Completion Date|Actual completion|
|Verified By|Person confirming completion|
|Residual Risk|Remaining risk after completion|
|Notes|Additional information|

## Priority Guidance

### Critical

Immediate or urgent action required because the issue creates a serious and credible threat to the company.

**Examples:**

- Known active compromise
- Critical exposed vulnerability being actively exploited
- No viable backup for a critical system
- Former administrator still has access

### High

Significant weakness that should be addressed promptly.

**Examples:**

- Missing MFA on important accounts
- Excessive privileged access
- Internet-facing unsupported system
- Untested critical backups

### Medium

Meaningful weakness that should be addressed through planned improvement.

### Low

Lower-risk improvement or security hygiene item that can be scheduled after higher priorities.

## Action Record

Action ID: ____________________

Date raised: ____________________

Raised from: ____________________

Finding:

---

Required action:

---

Risk if not completed:

---

Priority:

- Critical / High / Medium / Low

Owner: ____________________

Supporting party: ____________________

Target date: ____________________

Status:

- Not Started / In Progress / Blocked / Complete / Accepted

## Evidence Required

Examples:

- Screenshot
- Configuration export
- Updated policy
- Access report
- Restore test
- Security scan
- Training record
- Ticket
- Vendor confirmation

Evidence required:

---

## Verification

How will the company confirm the improvement actually works?

---

Verified by: ____________________

Verification date: ____________________

Result:

- Effective / Partially Effective / Ineffective / Retest Required

## Blocked Actions

If blocked:

Reason:

---

Escalation required:

---

Temporary control:

---

New target date:

---

## Closure

Completion date: ____________________

Residual risk:

- Low / Medium / High / Critical

Additional action required:

- Yes / No

Closure approved by: ____________________

Evidence location: ____________________

## Practical Rule

A finding without an owner and due date is only an observation.

A completed action without verification may only be an assumption.
