When your vulnerability scanner flags a weakness in your VPN gateway, you're faced with a decision that impacts your compliance timeline: do you treat the risk immediately, or document the current state for your auditor and remediate after the assessment?
The FBI's recent disruption of Chinese-government hacking tools exploiting known CVE flaws in Ivanti and Citrix products since 2018 highlights why this decision matters. Organizations that delayed patching CVE-2019-11510 in Pulse Secure VPN became targets for QTFY operators who weaponized the vulnerability months after a fix was released. Your choice between immediate remediation and audit-first documentation determines whether you're closing attack windows or preserving evidence of exposure.
The Decision You're Facing
You've identified a control gap or vulnerability affecting your compliance posture. Now you need to decide:
- Remediate immediately and document the corrective action
- Document the current state for audit evidence, then remediate
- Implement a compensating control while planning permanent remediation
This isn't an academic question. ISO/IEC 27001 Clause 10.1 requires you to react to nonconformities, but it doesn't prescribe timing. SOC 2's CC7.4 expects you to respond to identified issues, but the Trust Services Criteria don't mandate a specific sequence when an audit is already scheduled.
Key Factors That Affect Your Choice
Exploitability and threat intelligence: If you're dealing with a vulnerability that's actively being weaponized, your decision is clear. The QTFY operators exploited CVE-2019-11510 and CVE-2019-19781 because organizations left patching windows open. Check CISA's Known Exploited Vulnerabilities catalog and your threat intelligence feeds. If attackers are scanning for your specific weakness, remediate now.
Audit timeline and scope: If your Stage 2 audit starts in three weeks and the finding relates to a control that's in scope, talk to your lead auditor before you change anything. Some auditors want to see the control operating in its current state. Others prefer evidence of your incident response capability.
Evidence availability: Can you recreate the evidence after remediation? Configuration snapshots, change logs, and before/after documentation matter for both ISO/IEC 27001 Clause 9.1 and SOC 2's CC4.1. If you patch a server and lose the forensic trail, you've solved one problem and created another.
Risk treatment plan status: Check your Risk Treatment Plan. If this vulnerability was already identified and accepted with a treatment deadline, you're documenting progress against a known risk. If it's a new finding, you're responding to an unplanned nonconformity, which changes your documentation requirements under ISO/IEC 27001 Clause 10.1.
Compensating control feasibility: Sometimes you can't patch immediately due to operational dependencies. The question becomes whether you can implement a temporary control (network segmentation, enhanced monitoring, access restrictions) that reduces risk while maintaining audit continuity.
Path A: Remediate Immediately
Choose this path when:
- The vulnerability has a CVSS score above 7.0 and known exploits exist
- Your threat intelligence indicates active scanning for this weakness
- The attack surface is externally facing (VPN gateways, web applications, IoT devices)
- Your audit is more than 60 days away
- You can reconstruct the evidence trail through change management records
Implementation steps:
- Document the current state with screenshots, configuration exports, and vulnerability scan results
- Create a change request that references your Risk Treatment Plan or incident response procedure
- Execute the remediation during your approved change window
- Validate the fix with a rescan and document the outcome
- Update your Statement of Applicability (for ISO/IEC 27001) or system description (for SOC 2) to reflect the corrective action
Audit considerations: You'll present this as evidence of effective operational planning and control (ISO/IEC 27001 A.8.1) or monitoring activities (SOC 2 CC7.2). Your auditor will verify that you followed your change management process and that the remediation was effective. Acting quickly on a critical vulnerability demonstrates the maturity of your information security risk assessment process (ISO/IEC 27001 Clause 6.1.2).
Path B: Document Current State, Then Remediate
Choose this path when:
- Your Stage 2 audit begins within 30 days
- The vulnerability is internal-only with no external attack surface
- You've already implemented a compensating control that reduces risk to acceptable levels
- Your lead auditor specifically requested to observe certain controls in their current operating state
- The finding relates to a control that's being tested as part of the audit scope
Implementation steps:
- Notify your lead auditor immediately about the identified gap
- Document the current control environment with timestamped evidence
- Prepare a detailed Risk Treatment Plan that includes root cause analysis, proposed remediation, timeline, and responsible parties
- Implement any available compensating controls (enhanced logging, access restrictions, additional monitoring)
- Schedule remediation for immediately after the audit fieldwork concludes
Audit considerations: You're demonstrating transparency and your ability to identify nonconformities through internal monitoring (ISO/IEC 27001 Clause 9.2) or your monitoring activities (SOC 2 CC4.1). Your auditor will assess whether your Risk Treatment Plan is adequate and whether your compensating controls reduce risk to acceptable levels. This path works when you can show that the risk is managed, even if the permanent fix isn't yet deployed.
Path C: Implement Compensating Control During Audit
Choose this path when:
- You can't remediate immediately due to operational constraints (legacy system dependencies, vendor patching delays, required testing cycles)
- The audit is already in progress
- You can implement a technological or organizational control that mitigates the risk
- Your risk assessment shows the compensating control reduces likelihood or impact to acceptable levels
Implementation steps:
- Conduct a scenario-based risk assessment to identify which compensating controls effectively reduce your exposure
- Implement controls such as network segmentation, web application firewalls, enhanced authentication requirements, or restricted access policies
- Document the compensating control in your Risk Treatment Plan with clear acceptance criteria
- Schedule permanent remediation with defined milestones
- Add monitoring requirements to verify the compensating control remains effective
Examples of effective compensating controls:
- For an unpatched VPN gateway: Implement IP allowlisting, require certificate-based authentication, and deploy intrusion detection signatures specific to the CVE
- For vulnerable IoT devices: Move devices to an isolated VLAN, implement strict firewall rules, and enhance logging
- For legacy applications: Deploy a web application firewall with virtual patching rules, restrict access to authorized users only, and implement session monitoring
Summary Matrix
| Factor | Remediate First | Document First | Compensating Control |
|---|---|---|---|
| Audit timeline | >60 days out | <30 days out | Audit in progress |
| Exploitability | Active exploits in wild | Internal-only exposure | Can be mitigated temporarily |
| Attack surface | External-facing | Internal systems | Isolated or restricted |
| Evidence trail | Can reconstruct | Need current-state baseline | Ongoing documentation |
| Operational impact | Can patch now | Requires coordination | Patching blocked by dependencies |
| Risk level | Critical/High | Medium with mitigations | Medium, mitigatable |
| Best for | ISO/IEC 27001 A.12.6.1, SOC 2 CC7.1 | ISO/IEC 27001 Clause 9.2, SOC 2 CC4.1 | ISO/IEC 27001 Clause 6.1.3, SOC 2 CC3.4 |
The QTFY operators succeeded because organizations treated vulnerability management as a compliance checkbox rather than a continuous security function. Your decision about remediation timing should prioritize risk reduction while maintaining audit integrity. When in doubt, implement a compensating control immediately and consult your lead auditor about timing for permanent remediation. The worst choice is the one that leaves an attack window open while you wait for the perfect documentation moment.



