NOTE / SAMPLE /
A useful security report has executable consequences
A severity label is not remediation guidance, and a finding is not finished when the PDF ships.
Describe the system, not only the weakness
A useful finding explains the trust boundary, reachable path, consequence, preconditions, and evidence. It distinguishes what was demonstrated from what remains plausible but unverified.
That description lets an engineer repair the underlying assumption instead of hiding one symptom.
Make the repair testable
Where practical, the verification method should become an automated regression. The report then leaves behind a small durable control rather than a point-in-time assertion.
Security work becomes more valuable when assessment and software engineering remain in the same conversation.