Free Tool

Security Finding Routing Rules Design Worksheet
twelve sections that turn the routing rule library from analyst memory into a versioned design artefact the audit walkthrough reconstructs from

A free, copy-ready design worksheet for AppSec leads, heads of vulnerability management, security engineering leads, cloud security leads, product security leads, platform engineering partners, GRC and compliance teams, internal security teams, and CISOs. Twelve structured sections covering document control and version history, programme scope and rule library boundary, routing inputs and data-shape contract, rule catalogue with per-rule design block, default and fallback routing with the unowned-finding queue and the routing-policy-violation queue, multi-team and shared-asset routing rules with the routing-conflict tie-breaker, source-class triage routing before remediation owner, severity-band and asset-tier window compression, reassignment and prior-owner handover with the named rationale taxonomy, rule versioning and review cadence with per-cycle micro-review and per-quarter focused review and annual full review and named amendment triggers, audit walkthrough preparation with the framework crosswalk and per-rule audit-pack, and known failure modes with structural fixes. Aligned with ISO/IEC 27001:2022 Annex A 5.2 and A.8.8 and Clause 5.3, SOC 2 CC1.3 and CC2.2 and CC7.1 and CC8.1, NIST CSF 2.0 GV.RR and DE.AE and RS.MI and PR.IR, NIST SP 800-53 PM-2 and PM-29 and RA-5 and SI-2 and CA-7, PCI DSS 12.1 and 12.4 and 12.5 and 6.3.1, CIS Controls v8.1 Control 7 and 17, NIS2 Article 21, DORA Article 5 and Article 9, and HIPAA 164.308.

No credit card required. Free plan available forever.

Loading tool...

Run the rule library against the live workspace record, not against a static document

SecPortal pairs the versioned routing rules design worksheet to a programme engagement record so the per-rule design block, the per-rule fire pattern on the activity log, the routing-policy-violation queue, the unowned-finding queue, the reassignment-rationale taxonomy, the framework crosswalk, and the per-quarter focused review minutes all live on one workspace with a named-actor activity log. Free plan available.

No credit card required. Free plan available forever.