Vulnerability Disclosure Process Prompt
Prompt
Create a vulnerability disclosure process. Org type: [size, product type] Regulatory requirements: [SOC 2 / ISO 27001 / GDPR] Security team: [who handles incidents?] Current process: [describe if any] Please design: 1. How to receive reports (email / form / bug bounty) 2. Triage: severity classification with examples (Critical / High / Medium / Low) 3. Response SLAs per severity 4. Communication to reporter: what to say and when 5. Internal escalation by severity 6. Remediation tracking 7. A template acknowledgement email for initial response
Used by
IT & Ops Teams