A disposition is the recorded decision about how a finding, issue, or defect was handled. The word turns up in audit, compliance, quality assurance, security, and any issue tracker. A finding that has been dispositioned has had three things happen to it. Someone decided what to do. The decision was written down. The item left the open pile.
None of that means it was fixed. “Dispositioned” and “fixed” are different claims, and a report that blurs them hides risk.
| Label | What it means | Fixed? |
|---|---|---|
| Remediated | The problem was corrected and checked. | Yes |
| Accepted | The finding is valid and someone owns it. | Not yet |
| Deferred | It is valid, and the work is put off to a named later time. | No |
| Risk accepted | It is valid, and the owner chose to live with it, often until a set date. | No |
| Won’t fix | It is valid, and nobody will act on it. | No |
| False positive | The tool or reviewer was mistaken. There was nothing to fix. | Nothing to fix |
| Duplicate | The same finding is already tracked elsewhere. | See the other item |
| Not applicable | The rule does not apply to this system or case. | Nothing to fix |
| Tool | Its word for it | Labels it ships |
|---|---|---|
| Jira | Resolution | Done, Won’t do, Duplicate, Cannot reproduce |
| SonarQube | Status | Accepted, False positive |
| DefectDojo | Status | False positive, Out of scope, Risk accepted |
Jira’s “Won’t do” is defined as “This work item won’t be actioned.” DefectDojo’s “Risk accepted” lasts only “until the Risk Acceptance expires.”
This site dispositions its own raw ideas the same way. Each one ends as Publish, Merge, Park, or Drop, and the decision is logged.