1. Prerequisites
- Vulnerability alert, advisory, disclosure, or report received
- CVE, advisory, or finding identifier available
- Access to vulnerability management platform
- Access to asset inventory
- Access to configuration management data
- Access to SIEM
- Access to threat intelligence sources
- Access to affected system information
- Incident or tracking ticket created
2. Step-by-Step Instructions
-
Review Vulnerability Information
- Collect:
- CVE identifier
- Vendor advisory
- Security bulletin
- Vulnerability description
- Severity rating
- Document all available information.
- Collect:
-
Validate Vulnerability Authenticity
- Verify the vulnerability through:
- Vendor advisories
- Official CVE records
- Trusted security sources
- Internal vulnerability management tooling
- Confirm the vulnerability is legitimate and applicable.
- Verify the vulnerability through:
-
Identify Affected Technologies
- Determine:
- Operating systems
- Applications
- Services
- Cloud platforms
- Network devices
- Document affected technologies.
- Determine:
-
Identify Potentially Affected Assets
- Review asset inventory and vulnerability management data.
- Identify:
- Externally exposed assets
- Internal assets
- Critical systems
- Production environments
- Document potentially affected assets.
-
Review Existing Vulnerability Data
- Determine:
- Existing detections
- Previous scan results
- Existing remediation status
- Previous findings
- Document relevant findings.
- Determine:
-
Assess Exposure
- Determine:
- Internet exposure
- Internal exposure
- Access requirements
- Exploitation prerequisites
- Document exposure level.
- Determine:
-
Review Threat Intelligence
- Determine whether:
- Public exploit code exists
- Active exploitation has been reported
- Threat actors are targeting the vulnerability
- Exploitation campaigns are ongoing
- Document findings.
- Determine whether:
-
Assess Preliminary Risk
- Consider:
- Severity score
- Exposure level
- Asset criticality
- Exploitation availability
- Existing mitigations
- Assign a preliminary risk rating.
- Consider:
-
Determine Required Response Actions
- Determine whether:
- Further analysis is required
- Immediate containment is required
- Emergency remediation is required
- Monitoring should be increased
- Document recommended actions.
- Determine whether:
-
Escalate and Hand Off
- Provide findings to the Incident Commander and Technical Lead.
- Escalate to:
- Vulnerability Exposure Assessment
- Vulnerable Asset Identification
- Exploitation Verification
- Vulnerability Exposure Reduction
- Update the incident record with all findings.
3. Post-Action
- Ensure all affected technologies are documented.
- Ensure all potentially affected assets are recorded.
- Preserve supporting advisories and intelligence sources.
- Document the preliminary risk assessment.
- Attach all validation findings to the incident record.
- Ensure appropriate analysis and remediation activities have been initiated.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
