1. Prerequisites
- Completion of Vulnerability Validation
- Completion of Vulnerability Exposure Assessment
- CVE, advisory, or finding identifier available
- Access to vulnerability management platform
- Access to asset inventory
- Access to CMDB (if available)
- Access to cloud asset inventory
- Access to endpoint management platform
- Access to SIEM
- Incident or tracking ticket created
2. Step-by-Step Instructions
-
Review Vulnerability Scope
- Review:
- CVE identifier
- Affected products
- Affected versions
- Vulnerability prerequisites
- Document affected technologies.
- Review:
-
Query Vulnerability Management Platform
- Search for:
- Existing vulnerability findings
- Matching software versions
- Matching operating systems
- Matching services
- Export relevant findings where possible.
- Search for:
-
Review Asset Inventory
- Identify assets running:
- Affected operating systems
- Affected applications
- Affected services
- Affected cloud workloads
- Document candidate assets.
- Identify assets running:
-
Review Cloud Environments
- Identify:
- Virtual machines
- Containers
- Serverless functions
- Managed services
- Determine whether vulnerable software is present.
- Identify:
-
Review Endpoint Population
- Review endpoint inventory for:
- Installed software
- Software versions
- Configuration information
- Identify affected endpoints.
- Review endpoint inventory for:
-
Review Internet-Facing Assets
- Identify:
- Public applications
- Public services
- External infrastructure
- Public cloud resources
- Prioritise exposed assets.
- Identify:
-
Validate Asset Status
- Confirm:
- Asset ownership
- Business function
- Production status
- Operational status
- Remove false positives where appropriate.
- Confirm:
-
Assign Asset Criticality
- Determine:
- Business criticality
- Data sensitivity
- Availability requirements
- Exposure level
- Prioritise remediation targets.
- Determine:
-
Create Vulnerable Asset Inventory
- Record:
- Hostname
- IP address
- Asset owner
- Business unit
- Asset criticality
- Vulnerability status
- Prepare final asset list.
- Record:
-
Escalate and Hand Off
- Provide findings to the Incident Commander and Technical Lead.
- Escalate to:
- Exploitation Verification
- Vulnerability Exposure Reduction
- Remediation activities
- Update the incident record with all findings.
3. Post-Action
- Ensure all affected assets are documented.
- Ensure asset ownership and criticality are recorded.
- Preserve vulnerability scan results and supporting evidence.
- Document any identified false positives.
- Attach the vulnerable asset inventory to the incident record.
- Support containment and remediation activities as required.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
