Loading
Secure Your Salesforce Org
Review and Manage Security Health Review Findings

Review and Manage Security Health Review Findings

Use the Security Health Review findings view to investigate security gaps in your org, track remediation progress, and document compensating controls or risk decisions.

Available in: Lightning Experience in Enterprise and Unlimited editions
User Permissions Needed
To view findings, generate reports, track remediation progress, and download reports: Customize Application OR Modify All Data OR View Health Assessments
To disposition findings, reclassify dispositions, and remove dispositions: Manage Health Assessments

Access to Security Health Review is limited to Signature Success customers.

Navigate the Findings Tab

The Findings tab lists all active findings assessed against the Ideal Salesforce Org Security Hardening Benchmark, grouped by severity.

  1. In Setup, navigate to Health Assessments > Security Health Review.
  2. In the report view, scroll down to the tab section and click Findings.

To filter and search findings:

  • Severity filter tabs—click Mandatory, Critical, High, or Medium to filter by severity. The All tab shows every active finding with total count.
  • Search findings—enter a keyword to search across finding IDs and titles.
  • All Domains dropdown—filter findings by security domain (such as Identity Verification or Session Security Settings).
  • All Statuses dropdown—filter by remediation status: Open, In Progress, or Blocked.
  • Export—click the download icon to export the findings list.

Open a Finding

Click any finding ID (such as IAC-06) or finding row to open its detail view.

The finding detail includes:

Field Description
Finding ID Unique alphanumeric identifier (such as IAC-06).
Security Domain The high-level security category that the finding belongs to.
Sub-Domain The specific control area within the domain.
Severity Mandatory, Critical, High, Medium, or Low.
Status Current remediation status: Open, In Progress, or Blocked.
Instances Number of affected configurations or components.
Threat Description Explains the security risk associated with this misconfiguration.
Affected Items Lists the specific profiles, settings, or components that triggered the finding.
Recommended Baseline The Salesforce-recommended configuration to remediate this finding.
Documentation Links to the relevant Salesforce Help article and Well-Architected guidance.
Note
Note

Mandatory controls show an additional warning indicating that they must be remediated and can't be dispositioned.

Use Save & Next at the bottom of the detail panel to move to the next finding without returning to the list.

Track Remediation

Track Remediation lets you record progress toward resolving a finding. The finding remains in the active severity counts while being tracked.

  1. Open a finding.
  2. In the Update this finding section, select Track Remediation.
  3. Under Remediation status, select one of these:
    • Open—no remediation action started.
    • In Progress—remediation is underway. Enter a Target resolution date (required).
    • Blocked—remediation is blocked by a dependency or external factor.
  4. Click Save.

Remediation status changes are reflected immediately in the Remediation progress bar on the main report page and in the User Activity Log.

Disposition a Finding

Disposition a finding to formally exclude it from the active severity counts. Disposition a finding when the risk is covered by an external control, when the finding doesn’t apply to your environment, or when you’ve made a deliberate decision to accept the risk.

  1. Open a finding.
  2. In the Update this finding section, select Disposition Finding.
  3. Choose a Disposition type:

    When selecting Accept Risk, these reasons are available:

    • Compensating security control exists—Covers third-party tools (CASB/DLP/SIEM), network restrictions, WAF, VPN/ZTNA, encryption, detective controls, or custom code enforcement.
    • Authentication handled externally—Covers SSO/IdP enforcement, MFA at IdP, conditional access, certificate-based auth, or custom login flows.
    • Environment limits exposure—Covers sandbox/non-prod, internal-only org, no external users, no API integrations, decommission planned, regulated enclave, or feature not in use.
    • Data sensitivity does not warrant remediation—Covers non-sensitive data, public data, no PII/PHI/PCI in scope, or data classification limits impact.
    • Business/operational requirement—Covers approved business processes, partner/customer experience needs, regulatory obligations, ISV dependencies, cross-cloud integrations, or executive risk acceptance.
    Disposition type When to use
    Accept Risk Your organization has reviewed the risk and made a deliberate decision to accept it. Select a Reason from the dropdown, choose a Validity period (3, 6, or 12 months), and check the acknowledgment before saving.
    Mitigated by Alternative Control An external control (such as a third-party tool, WAF, VPN/ZTNA, or IdP-enforced MFA) mitigates this risk. Select a Reason, and check the confirmation that you take ownership for ensuring the external control is in place.
    Not Applicable The relevant feature is not in use in this org, or this is a confirmed false positive. Select a Reason and check the confirmation before saving.
  4. Click Save.

Dispositioned findings are excluded from the active severity counts immediately and moved to the Customized Controls tab.

Note
Note

Salesforce Mandated Critical Security Controls cannot be dispositioned regardless of the user’s permission level. These findings must be remediated.

Manage Dispositioned Findings

Dispositioned findings appear in the Customized Controls tab. This tab lists findings that have been excluded from the active severity counts, along with their disposition type, who classified them, expiration date (if applicable), and last updated date.

  1. Click Customized Controls tab.
  2. Click the finding ID to open its detail view.
  3. In the Update this finding section:
    • Click Reclassify to change the disposition type, reason, or validity period.
    • Click Remove disposition to revoke the disposition. The finding returns to the Findings tab with status Open.

Review Compliant Controls

The Compliant Controls tab lists all controls that passed the Ideal Salesforce Org Security Hardening Benchmark. Each entry shows the Control ID, Security Control name, Domain, and Status (Compliant).

Click any control ID to view its current setting and the recommended baseline.
 
Chargement
Salesforce Help | Article