zero-day-response-governance

Govern zero-day vulnerability response policies with CVSS-based severity and escalation criteria.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill zero-day-response-governance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: zero-day-response-governance
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/response/zero-day-response-governance
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill zero-day-response-governance

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a framework for governing how an organization handles zero-day vulnerabilities, ensuring a legally sound, ethically responsible, and operationally effective disclosure and response process.

Core Features & Use Cases

  • Policy Governance: Defines clear pathways for both discovering zero-days (responsible disclosure) and responding to them when the organization is a victim.
  • Response Timelines: Establishes severity assessment and response timelines based on CVSS scores and exploitation status.
  • Emergency Response: Outlines criteria and processes for declaring and managing zero-day emergencies, including expedited patching and workaround deployment.
  • Use Case: When a critical zero-day is announced and actively exploited in the wild, this Skill helps determine the immediate response actions, necessary approvals, and communication strategies according to established policies.

Quick Start

Govern the response to a newly discovered critical zero-day vulnerability affecting our internet-facing systems.

Frequently Asked Questions about zero-day-response-governance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is zero-day vulnerability response governance?

Zero-day vulnerability response governance establishes a policy framework for handling active exploitation by defining severity assessments, response timelines, and emergency declaration criteria based on CVSS scores and system criticality.

How do I determine response timelines for an actively exploited zero-day?

You determine response timelines by assessing CVSS scores, active exploitation status, and system criticality to trigger predefined response pathways, authorize emergency patching, and satisfy regulatory communication requirements.

What criteria justify declaring a zero-day emergency?

Declaring a zero-day emergency requires evaluating active exploitation in the wild, high CVSS severity scores, and the criticality of impacted internet-facing systems to authorize expedited patching and workaround deployment.

Can I use this framework to manage responsible disclosure for vulnerabilities we discover?

Yes, the governance framework defines clear pathways for responsible disclosure of discovered vulnerabilities, ensuring ethically responsible and legally sound cross-organizational escalation and communication.

Does zero-day response governance handle regulatory communication requirements?

Yes, the framework satisfies regulatory communication requirements by establishing necessary approvals and communication strategies according to established policies during a critical zero-day incident.

What is the best way to govern expedited patching authorization for zero-day vulnerabilities?

The best way to govern emergency patch authorization is applying a policy framework that evaluates exploitation status and CVSS severity to mandate response timelines and emergency declaration criteria.