Report Template
Required Sections
- Executive summary.
- Scope and authorization basis.
- Methodology.
- Findings summary.
- Evidence summary.
- Risk and impact.
- Remediation status.
- Limitations.
- References and appendices.
Publication Note
The public version should be written as a sanitized artifact. It should explain what was found and why it matters without increasing operational risk.
Review Requirements
A public report should separate public conclusions from private evidence. The final draft should state scope, authorization basis, evidence source class, limitations, and redaction status. Raw logs, screenshots, traces, customer data, and exploit construction details are not public report material by default.