Remediation Best Practices
Auto-remediation requires careful configuration to avoid unintended consequences.
Golden Rules
- Start Conservative - Begin with manual approval required. Only enable automation after validation.
- Use Cooldown Periods - Prevent remediation loops with appropriate cooldowns.
- Enable Notifications - Get alerts for all remediation actions.
- Plan for Rollback - Have a plan to undo any remediation action.
Implementation Phases
- Monitor Only (1-2 weeks) - Create policies but disable auto-execution
- Manual Approval (2-4 weeks) - Enable with manual approval required
- Semi-Automatic - Enable auto-execution for low-risk actions only
- Full Automation - After proven reliability, enable full automation
Do
- Test in non-production first
- Set appropriate cooldown periods
- Document all policies
- Review execution history regularly
Dont
- Enable full automation immediately
- Set thresholds too aggressively
- Ignore execution history
- Forget about rollback plans