Skip to content
Tier 3 · Best Practices

Best Practices

Reduce the rate at which the first two tiers refill

Tier 3 covers structural improvements with compounding returns. Nothing here is urgent in isolation, which is exactly why it never gets done without a tier of its own. Tier 3 is the only tier where deferral is a legitimate, recorded outcome — an organization that closes every Tier 3 item is probably under-investing elsewhere.

The test for this tier

Does fixing this reduce the number or severity of future Tier 1 and Tier 2 findings?

See the full decision procedure
Remediate within
90 days
Escalation
Reviewed at quarterly planning; may be formally deferred
Owned by
Platform and engineering teams
Budgeted from
Planned work — a standing percentage of engineering capacity

Where CVSS fits

Findings in this tier typically score 0.1 – 3.9 — but the score is an input, never the decision. A CVSS 9.8 with no reachability does not belong in Tier 1, and a CVSS 6.5 in the CISA KEV catalog on an internet-facing host does. How Beacon relates to CVSS, EPSS and KEV.

12 finding classes

Tier 3 findings by domain

Tier sets the deadline; domain sets the owner. Each entry links to its full definition, detection guidance, and remediation steps.

Network

NETWhat can be reached, and from where?

Identity & Access Management

IAMWho can act, and how strongly is that proven?

Data Protection

DATWhat happens to the data if everything else fails?

Processing Protection

PRCIs the compute that runs the business trustworthy and available?