Appearance
Vulnerability Remediation SLAs & Incident Response Standard
💡 Copyable AI Prompt Block (
AGENTS.md)
markdown
<!-- START AGENT-STANDARD: SECURITY-INCIDENT-RESPONSE -->
## Vulnerability SLAs & Incident Response Rules
- Enforce strict remediation SLAs: CRITICAL vulnerabilities ≤ 24h, HIGH ≤ 7d, MEDIUM ≤ 30d.
- Immediately revoke and rotate any exposed secret or key; follow emergency incident playbooks.
- Conduct mandatory post-incident root cause analyses (RCA) and record findings in post-mortem docs.
<!-- END AGENT-STANDARD: SECURITY-INCIDENT-RESPONSE -->Detailed Human Guide & Rationale
(Detailed guide to be authored collaboratively)
1. Vulnerability Severity Matrix & Patching SLAs
(Defining SLA response windows for CRITICAL, HIGH, MEDIUM, and LOW severity vulnerabilities)
2. Secret Exposure Revocation & Compromise Playbooks
(Step-by-step emergency procedures for revoking leaked tokens, database credentials, and cloud API keys)
3. Incident Management, Communication & Root Cause Analysis (RCA)
(Incident response roles, war-room coordination, public status updates, and post-mortem RCA documentation)
Primary Evidence & References
- NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide): https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
- CISA Vulnerability Remediation SLAs: https://www.cisa.gov/known-exploited-vulnerabilities-catalog