Cybersecurity Improvement Action Tracker
Purpose
Use this tracker to manage cybersecurity improvements identified through:
- Risk assessments
- Incidents
- Post-incident reviews
- Vulnerability assessments
- Access reviews
- Backup tests
- Vendor reviews
- Security exercises
- Audits
- Leadership reviews
- Employee reports
The objective is to make sure identified problems result in assigned, tracked, and verified improvements.
Recommended Tracker Fields
Priority Guidance
Critical
Immediate or urgent action required because the issue creates a serious and credible threat to the company.
Examples:
- Known active compromise
- Critical exposed vulnerability being actively exploited
- No viable backup for a critical system
- Former administrator still has access
High
Significant weakness that should be addressed promptly.
Examples:
- Missing MFA on important accounts
- Excessive privileged access
- Internet-facing unsupported system
- Untested critical backups
Medium
Meaningful weakness that should be addressed through planned improvement.
Low
Lower-risk improvement or security hygiene item that can be scheduled after higher priorities.
Action Record
Action ID: ____________________
Date raised: ____________________
Raised from: ____________________
Finding:
Required action:
Risk if not completed:
Priority:
- Critical / High / Medium / Low
Owner: ____________________
Supporting party: ____________________
Target date: ____________________
Status:
- Not Started / In Progress / Blocked / Complete / Accepted
Evidence Required
Examples:
- Screenshot
- Configuration export
- Updated policy
- Access report
- Restore test
- Security scan
- Training record
- Ticket
- Vendor confirmation
Evidence required:
Verification
How will the company confirm the improvement actually works?
Verified by: ____________________
Verification date: ____________________
Result:
- Effective / Partially Effective / Ineffective / Retest Required
Blocked Actions
If blocked:
Reason:
Escalation required:
Temporary control:
New target date:
Closure
Completion date: ____________________
Residual risk:
- Low / Medium / High / Critical
Additional action required:
- Yes / No
Closure approved by: ____________________
Evidence location: ____________________
Practical Rule
A finding without an owner and due date is only an observation.
A completed action without verification may only be an assumption.