Workbook

Vulnerability Prioritization Worksheet

Turn a vulnerability alert into a documented patch, mitigation, isolation, or investigation decision with an owner and a retest.

Vulnerability Prioritization Worksheet visual for DefendArm Security guidance
Preview before download

Triage the affected service

This worksheet supports local decisions; it is not the official CISA SSVC decision tree. Use vendor advisories and current exploitation evidence alongside business context.

Sample decisions
  • Is the affected component present and reachable through a relevant attack path?
  • Which new fact would justify emergency patching, mitigation, or isolation?
  • What test will show that all affected instances are fixed?
Common mistakes
  • Using a severity score as the whole priority decision.
  • Recording a workaround without testing whether it blocks the affected path.
  • Closing the ticket when deployment succeeds rather than checking the exposed service.
What is inside

Vulnerability Prioritization Worksheet

Turn a vulnerability alert into a documented patch, mitigation, isolation, or investigation decision with an owner and a retest. Includes a fillable PDF with worked examples and decision records.

Fillable PDF. Reviewed 2026-09-21. Includes practical guidance and reusable review records.

  • Triage the affected service: This worksheet supports local decisions; it is not the official CISA SSVC decision tree. Use vendor advisories and current exploitation evidence alongside business context.
  • Worked triage / Exposed gateway: Fictional exercise: a vendor publishes a fix for a gateway used by a customer portal, while the normal maintenance window is three days away.
  • Vulnerability decision record: Use one record per issue and service group. Reopen the decision when exposure or exploitation evidence changes.

References

Examples are fictional. Adapt these materials to your environment; completing a worksheet is not a certification.

Questions teams ask

Practical questions before you decide.

Who should use the Vulnerability Prioritization Worksheet?

This resource is built for security analysts, infrastructure owners, and change managers who need a clear way to turn security guidance into owners, evidence, and next actions.

What should a team prepare before using it?

Prepare current system owners, relevant policies, available logs or configuration evidence, and any known exceptions that affect the control area.

When should this turn into a deeper review?

Bring in the relevant specialist when the work exposes missing evidence, unclear authority, or controls your team cannot validate. Keep the unresolved issue, owner, and next decision recorded.