Accountability should sit with the product and security leadership that decides whether a finding is accepted, remediated, or deferred. Repeated won’t fix decisions need governance, because they are not technical neutral acts. They shape exposure, customer trust, and regulatory risk. If the issue affects privileged identity paths, accountable owners should document the rationale and track compensating controls until closure.
Who Owns a Repeated Won’t Fix Decision
Repeated won’t fix findings should not float between teams without explicit ownership. The accountable party is the leader who can accept the risk, fund the fix, or approve the exception, usually product leadership in partnership with security leadership. If the finding affects overprivileged or poorly governed identity paths, that owner must treat the decision as a control choice, not a backlog preference.
Accountability matters because a won’t fix is a durable posture decision. It says the organisation has chosen to live with the exposure for now, so the decision needs a named owner, a review cadence, and a documented rationale that survives personnel changes. Without that, the same unresolved finding can be repeatedly rediscovered without any real governance movement.
Where the issue touches identity governance, the ownership question is broader than the ticket. You are accountable for the exposure created by credential lifecycle, visibility, and access governance, not just for closing an individual report. That includes deciding whether the finding should be fixed, accepted with conditions, or escalated because it affects privileged access paths.
What Repeated Deferrals Mean for Security and Governance
When the same identity finding keeps returning, the organisation is usually signalling one of three things: the risk is underestimated, the remediation path is blocked, or leadership has tacitly accepted the exposure without formal review. Any of those outcomes can widen customer, operational, and regulatory risk, especially when the issue involves secrets, service accounts, or privileged access.
Repeated deferral also weakens assurance. If a team can mark a finding won’t fix indefinitely, then the control is not really closed, it is only parked. That creates a gap between what the security programme reports and what the environment actually allows, which is why these decisions need governance instead of informal consensus.
For identity-heavy environments, the practical danger is that unresolved findings often sit on the same paths attackers prize: standing privilege, stale credentials, weak rotation, or poor inventory. NHIMG’s key NHI risk summary is useful here because it frames the underlying exposure pattern, while the OWASP Non-Human Identity Top 10 reinforces that overprivilege and secret sprawl are not cosmetic issues, they are common failure modes.
Risk and Threat Considerations
Repeated won’t fix decisions create a governance risk because they normalise unresolved exposure. If the finding involves identity security, the risk becomes operationally material quickly, since stale access, excessive privilege, or unmanaged secrets can persist long enough for misuse, lateral movement, or unauthorised access to occur.
Failure mechanism: The organisation treats a recurring security issue as an exception without tightening the approval path, so the same weakness remains in place, and the control owner loses visibility into whether compensating measures still exist or still work.
Impact: Exposure compounds over time. A repeated won’t fix on identity findings can preserve high-risk access paths, reduce trust in remediation reporting, and leave the business carrying unresolved customer, audit, and regulatory consequences.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Overprivileged Non-Human Identities | Repeated won’t fix on identity findings often preserves excessive access paths. |
| NHI-05 — Secret Sprawl and Credential Hygiene | Won’t fix findings often leave stale secrets or unmanaged credentials in place. | |
| NHI-08 — Visibility, Inventory, and Ownership | Repeated deferrals fail when no owner can explain or close the exposure. | |
| Recommendation — Reduce standing privilege and reapprove any accepted exception on a fixed review cycle. Track unresolved secret findings to expiry and rotate exposed credentials before accepting risk. Assign a named owner for every unresolved identity finding and keep the exception register current. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Repeated won’t fix decisions require explicit risk acceptance and oversight. |
| ID.IM-01 — Improvements Are Identified and Prioritised | A recurring won’t fix finding shows that remediation priorities and blockers are not being governed. | |
| PR.AA-02 — Identity Management, Authentication, and Access Control | Identity security findings affect access paths, privilege, and control effectiveness. | |
| Recommendation — Document who accepts the risk, why it is accepted, and when it must be reviewed again. Use recurring findings as input to remediation prioritisation and leadership review. Validate that accepted identity exceptions do not leave unauthorised access paths or standing privilege. | ||
| CIS Controls v8 | 6.3 — Require MFA for Externally-Exposed Applications | Identity findings often involve access paths that need stronger control if left unresolved. |
| 5.3 — Account Maintenance | Repeated deferrals can leave stale accounts and access paths active. | |
| Recommendation — Escalate unresolved access findings when compensating controls depend on weaker authentication. Review unresolved account findings on a fixed cadence and remove or justify access promptly. | ||
| NIST SP 800-63 | 5.2.5 — Authenticators and Verifiers | If the finding concerns identity assurance or authenticator handling, the acceptance decision affects trust in authentication. |
| Recommendation — Reassess authenticator strength before accepting recurring identity exceptions. | ||
Practitioner Guidance
What to prioritise: Assign a single accountable owner who can approve risk acceptance, not just a ticket resolver. If the finding affects privileged identity paths, require a named business owner and a security owner to sign off on the same decision.
What to verify: Confirm that each won’t fix has a current rationale, an expiry or review date, and a compensating control that is actually operating. If any of those are missing, the decision is effectively unmanaged and should be escalated.
Decision rule: If the finding can enable unauthorised access, privilege abuse, or secret reuse, treat it as a governance exception with time bounds. If it cannot be time-bounded or measured, it should not be considered an acceptable permanent state.
Practitioner takeaway: The main risk is not that a finding remains open, it is that repeated won’t fix decisions become invisible policy by habit. Accountability must sit with the leader who is consciously accepting the exposure and willing to defend that choice later.
Related resources from NHI Mgmt Group
- How should security teams prioritize identity security in a modern Zero Trust programme?
- Who should be accountable for break-glass access when emergency privileged access spans security, IT, and management teams?
- How should security teams evaluate identity platforms for cloud environments without getting distracted by vendor hype?
- How should security leaders evaluate identity convergence when they are consolidating IGA, IAM, and PAM capabilities?