Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Create a Risk from a Test Finding

Prev Next

There may be scenarios when:

  • A test finding requires formal acceptance or executive review before it can be remediated

  • Remediation will be delayed due to business constraints, resource limitations, or technical dependencies

In such cases, creating a risk directly from the test finding ensures that the finding is formally documented in your organization’s risk register, and you can manage it appropriately from the risk management module. In this article, we explain how to create a risk from a cloud test finding.

How To Create a Risk from a Cloud Test Finding

  1. Click Compliance → Cloud on the left navigation panel.

  2. Go to the Tests tab, and click on the specific test for which you want to create the risk.

    Pro Tip! Use the search bar and filters at the top to quickly locate specific tests.

  3. Click the three-dots icon on the top-right corner of the test findings page.

  4. Select Create Risk.

  5. The create risk form will be pre-filled with specific details from the test finding, such as Risk Name and Description.

  6. Enter the details for the other fields manually.

  7. Click Save. The test creation details are captured in the audit logs.

  8. Scroll to the Risk tab in the test finding page to view the risk details.

  9. Clicking on the risk details takes you directly to the Risk Register. The risk's Source Type is set to “Test,” and Source is set to the test name.

Once created, the test will appear in your Risk Register with the source and source type auto-populated from the test finding.

Best Practices

When ignoring entire tests (especially due to default configurations that cannot be modified), it's recommended to create a Risk and link it to the ignored test. This provides:

  • Proper documentation for auditors

  • Justification for why the test was ignored

  • Context through comments and screenshots

  • Audit trail for compliance purposes

Example Use Case: AWS servers with default internal policies that were configured at creation time and cannot be modified without recreating the server. Since recreating production servers is not feasible, creating a Risk with proper justification provides a compliant way to document why the test is ignored.

While not mandatory, this is the recommended approach for maintaining audit readiness.

FAQs


Should I mark the test as “Ignored” after creating a risk for it?

The decision to mark a test as "Ignored" after creating a risk depends on your organization's risk management process. Mark the test as "Ignored" when:

  • A formal risk acceptance decision has been documented

  • A remediation ticket has already been raised for the same finding

  • The risk is being actively tracked through your risk management workflow

Marking it as ignored indicates the finding is acknowledged and prevents duplicate or redundant alerts in your compliance dashboard.

Best Practices

Always include a clear justification when marking a test as ignored, such as:

  • Link to the remediation ticket or risk entry

  • Risk acceptance reason and approver

  • Timeline for planned remediation

  • Reference to the formal risk decision

Only mark tests as ignored when the risk is being actively managed through an alternative process. This ensures accountability while reducing noise in your compliance reporting.