iwlusytd.wiki← All articles
TECHNICAL JOURNAL / METHODOLOGY / 14

Turn a finding into a report someone can fix

Evidence, impact and retesting: what should remain after the assessment.

01 /

Name the violation precisely

“API security issue” does not define a useful task. Identify the action and boundary instead: “a user in one organization can read another organization’s test document.” The title should convey the issue without requiring the reader to inspect the entire traffic log.

02 /

Make reproduction self-contained

Specify the environment, role, preconditions, minimal steps and expected result. Include redacted requests and responses. Another specialist should be able to reproduce the observation without guessing which data or permissions the tester had.

03 /

Separate risk from assumptions

Describe the confirmed impact and the conditions needed to trigger it. Label an untested chain of consequences as a hypothesis. Severity should account for the affected data, scenario accessibility and the product’s actual context.

04 /

Close the loop with a retest

Tie the recommendation to the root cause. After remediation, repeat the original scenario and related variations that may be affected. Record the version, date and retest outcome; keep remaining limitations visible in the final document.

Have a correction or a question? iwlusytd@duhastmail.com
Message on Telegram ↗