TriageSLA

Critical CVE Triage

Checks a newly published critical CVE against the asset list and opens one ticket per owning team.

Part of Vulnerability SLA tracking

Tools

Qualys, Jira Service Management, Slack

Outcomes

Affected hosts listed within the hour • One ticket per owning team • Patch date agreed and recorded

Documentation

Instruction-ready detail below

When a critical CVE is published, check <in:spreadsheets>the asset list</in:spreadsheets> for the affected product, open <jira>one ticket per owner</jira>, and <slack>post</slack> the host count and the patch deadline.

Instruction file

When a critical CVE is published, check <in:spreadsheets>the asset list</in:spreadsheets> for the affected product, open <jira>one ticket per owner</jira>, and <slack>post</slack> the host count and the patch deadline.

Setup requirements

Tools

Qualys, Jira Service Management, Slack

Trigger

When a critical CVE is published for a product in the asset list

Setup time

30 minutes

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download