Critical Zero-Day Response
Use this playbook to respond quickly when a new critical zero-day vulnerability is announced (e.g., widely exploited RCE or library vulnerability).
Assess Relevance
- Gather basic information:
- Affected products, versions, and configurations.
- Known exploit vectors and mitigations.
- Determine whether your technology stack uses impacted software or services.
Identify Potentially Affected Assets
Using Cloudaware:
- Search Cloudaware Vulnerability Scan records for:
- CVE identifier (once available).
- Package/library names and versions.
- If scanners have not yet released signatures:
- Use CMDB and Breeze Agent data to identify where affected software may be installed.
- Use tags, packages, and configuration data to build an initial asset list.
Create an Initiative and Tasks
- Create a dedicated Zero‑Day Initiative that:
- Describes the vulnerability, business impact, and timelines.
- Serves as a container for related tasks and reporting.
- Create Remediation Tasks per OU/application or platform team, including:
- Initial scoping and validation steps.
- Patch or configuration changes once vendor guidance is available.
See also: Vulnerability Management Processes
Coordinate with Patch and Change Management
- Work with Patch Management to:
- Prioritize patches or configuration changes related to the zero‑day.
- Schedule emergency maintenance windows as needed.
- Ensure Change Management processes are followed for high‑risk changes, but streamline approvals for emergency fixes where policy permits.
Communicate Broadly
- Use collaboration and ITSM integrations to:
- Notify affected teams, leadership, and incident response.
- Provide regular status updates (e.g., which systems are patched, which remain exposed).
- Update dashboards with a dedicated view for the zero‑day Initiative.
Verify Remediation
- Run targeted scans or rely on updated scanner signatures to confirm:
- Vulnerabilities are no longer detected on patched systems.
- No unexpected regressions appear.
- Update Initiative and task status to reflect remediation progress.
Document and Improve
- Capture:
- Timeline of detection, triage, remediation, and verification.
- Decisions about exceptions and compensating controls.
- Use this information to:
- Improve future zero‑day response.
- Adjust SLAs, risk models, and patch processes as needed.