UAIF / L0 / L0-F04

Remediation Status

Objective

Capture and validate the remediation status element within the Incident Identity & Workflow layer.

UAIF requirement

The incident record should implement the canonical remediation_status field using the defined UAIF data type, validation constraints, and conditional rules.

Business impact

Supports stable incident identity, deduplication, workflow tracking and an auditable reporting record.

Validation approach

Validate remediation_status for required in the Core profile, controlled vocabulary membership. Then review semantic consistency against the source incident evidence and the selected conformance profile.

Expected evidence

Retain the source record or analyst input for remediation_status, schema-validation output, transformation history, selected profile, schema version and reviewer rationale where judgement is involved.

Mapping and source

UAIF Schema Specification; UAIF Technical Specification; JSON pointer /properties/remediation_status.

Implementation guidance

Populate remediation_status from an identified source or documented analyst decision. Enforce the schema constraints at record creation and update, preserve the original value and provenance, and surface validation failures without silently coercing data.

Assessment considerations

Sample records across normal, boundary and invalid conditions. Confirm that remediation_status is populated only when applicable, conditional rules are enforced, provenance is retained and downstream systems do not change its meaning or precision.

Canonical schema definition

JSON propertyremediation_status
Required in core profileYes
Type"string"
Allowed valuesDetected, Investigating, Mitigated, Resolved

Source: UAIF Schema Specification and UAIF Core JSON Schema.