Security issues and findings are formally tracked until resolution
A written rule that every security issue is logged in one place gives the incident plan a feeder system, so findings from audits or scans surface before they turn into incidents.
Logging every security finding in one place is a broader governance habit that gives event triage somewhere to record confirmed incidents once assessed.
This policy control keeps a written rule that every security issue is logged in one place and tracked until closed, the record A.5.36's compliance checking relies on.
https://sekit.ai/api/mcp/crosswalk