You are here:
Review and Manage Security Health Review Findings
Use the Security Health Review findings view to investigate security gaps in your org, track remediation progress, and document compensating controls or risk decisions.
| Available in: Lightning Experience in Enterprise and Unlimited editions |
| User Permissions Needed | |
|---|---|
| To view findings, generate reports, track remediation progress, and download reports: | Customize Application OR Modify All Data OR View Health Assessments |
| To disposition findings, reclassify dispositions, and remove dispositions: | Manage Health Assessments |
Access to Security Health Review is limited to Signature Success customers.
To configure access, see Assign Access to the Security Health Review Tool.
Open a Finding
The finding detail includes:
| Field | Description |
|---|---|
| Finding ID | Unique alphanumeric identifier (such as IAC-06). |
| Security Domain | The high-level security category that the finding belongs to. |
| Sub-Domain | The specific control area within the domain. |
| Severity | Mandatory, Critical, High, Medium, or Low. |
| Status | Current remediation status: Open, In Progress, or Blocked. |
| Instances | Number of affected configurations or components. |
| Threat Description | Explains the security risk associated with this misconfiguration. |
| Affected Items | Lists the specific profiles, settings, or components that triggered the finding. |
| Recommended Baseline | The Salesforce-recommended configuration to remediate this finding. |
| Documentation | Links to the relevant Salesforce Help article and Well-Architected guidance. |
Mandatory controls show an additional warning indicating that they must be remediated and can't be dispositioned.
Use Save & Next at the bottom of the detail panel to move to the next finding without returning to the list.
Track Remediation
Track Remediation lets you record progress toward resolving a finding. The finding remains in the active severity counts while being tracked.
- Open a finding.
- In the Update this finding section, select Track Remediation.
-
Under Remediation status, select one of these:
- Open—no remediation action started.
- In Progress—remediation is underway. Enter a Target resolution date (required).
- Blocked—remediation is blocked by a dependency or external factor.
- Click Save.
Remediation status changes are reflected immediately in the Remediation progress bar on the main report page and in the User Activity Log.
Disposition a Finding
Disposition a finding to formally exclude it from the active severity counts. Disposition a finding when the risk is covered by an external control, when the finding doesn’t apply to your environment, or when you’ve made a deliberate decision to accept the risk.
- Open a finding.
- In the Update this finding section, select Disposition Finding.
-
Choose a Disposition type:
When selecting Accept Risk, these reasons are available:
- Compensating security control exists—Covers third-party tools (CASB/DLP/SIEM), network restrictions, WAF, VPN/ZTNA, encryption, detective controls, or custom code enforcement.
- Authentication handled externally—Covers SSO/IdP enforcement, MFA at IdP, conditional access, certificate-based auth, or custom login flows.
- Environment limits exposure—Covers sandbox/non-prod, internal-only org, no external users, no API integrations, decommission planned, regulated enclave, or feature not in use.
- Data sensitivity does not warrant remediation—Covers non-sensitive data, public data, no PII/PHI/PCI in scope, or data classification limits impact.
- Business/operational requirement—Covers approved business processes, partner/customer experience needs, regulatory obligations, ISV dependencies, cross-cloud integrations, or executive risk acceptance.
Disposition type When to use Accept Risk Your organization has reviewed the risk and made a deliberate decision to accept it. Select a Reason from the dropdown, choose a Validity period (3, 6, or 12 months), and check the acknowledgment before saving. Mitigated by Alternative Control An external control (such as a third-party tool, WAF, VPN/ZTNA, or IdP-enforced MFA) mitigates this risk. Select a Reason, and check the confirmation that you take ownership for ensuring the external control is in place. Not Applicable The relevant feature is not in use in this org, or this is a confirmed false positive. Select a Reason and check the confirmation before saving. - Click Save.
Dispositioned findings are excluded from the active severity counts immediately and moved to the Customized Controls tab.
Salesforce Mandated Critical Security Controls cannot be dispositioned regardless of the user’s permission level. These findings must be remediated.
Manage Dispositioned Findings
Dispositioned findings appear in the Customized Controls tab. This tab lists findings that have been excluded from the active severity counts, along with their disposition type, who classified them, expiration date (if applicable), and last updated date.
- Click Customized Controls tab.
- Click the finding ID to open its detail view.
-
In the Update this finding section:
- Click Reclassify to change the disposition type, reason, or validity period.
- Click Remove disposition to revoke the disposition. The finding returns to the Findings tab with status Open.
Review Compliant Controls
The Compliant Controls tab lists all controls that passed the Ideal Salesforce Org Security Hardening Benchmark. Each entry shows the Control ID, Security Control name, Domain, and Status (Compliant).
