# Vulnerability handling mini-playbook (A1.4)

A structured but lightweight, SME-sized vulnerability workflow, from the first alert to close-out.

## 1. Intake — How we receive alerts

Sources monitored:

- [ ] Project advisories
- [ ] CVE databases
- [ ] Dependency scanning tool
- [ ] Customer reports
- [ ] Internal testing

- **Alert owner**:
- **Backup contact**:

## 2. Triage — Decide severity and urgency

For each vulnerability, record:

- **Affected component and version(s)**:
- **Is it used in our product?** (Yes / No)
- **Exposure context** (Internal / Limited / Public):
- **Functional criticality** (Low / Medium / High):
- **Exploitability indicators** (if known):
- **Proposed response priority** (Low / Medium / High):

Decision rule (simple):

- High criticality + public exposure → treat as urgent
- Medium risk → planned fix
- Low risk → track and fix in the next planned cycle

## 3. Remediation — Fix and verify

Action taken:

- [ ] Upgrade to fixed version
- [ ] Apply patch
- [ ] Mitigation / configuration change
- [ ] Temporary workaround

- **Owner**:
- **Target date**:
- **Validation performed** (e.g., testing / regression / deployment verification):

## 4. Release and communication

- **Release notes updated** (Yes / No):
- **SBOM updated** (Yes / No):
- **Customer / internal communication required?** (Yes / No)
- **If yes: channel and message owner**:

## 5. Close-out and learning

- **Closure date**:
- **What worked / what to improve next time** (1–2 bullets):

---

_Based on OCCTET deliverable D2.3 – CRA Adoption Best Practice Document (v1.0, March 2026), licensed under CC BY 4.0._

<https://occtet.eu/best-practices/checklists-and-templates/>
