Token导航 LogoToken导航TokenDH.com
研究检索只读github未标认证来源可访问许可证需确认审计通过

building-vulnerability-aging-and-sla-tracking构建漏洞老化和 SLA 跟踪

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

423

周安装

18

GitHub Stars

5,927

下载量

148
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:building-vulnerability-aging-and-sla-tracking(构建漏洞老化和 SLA 跟踪)
来源仓库:https://github.com/mukul975/anthropic-cybersecurity-skills
仓库路径:skills/building-vulnerability-aging-and-sla-tracking
安装命令:
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill building-vulnerability-aging-and-sla-tracking
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill building-vulnerability-aging-and-sla-tracking

简介

跟踪漏洞修复周期并监控 SLA 达成情况,量化风险管理效果。

  • 适用于制定补丁策略、向管理层汇报风险态势或审计合规需求。
  • 支持自定义 SLA 阈值(如高危 14 天、中危 60 天),生成趋势报表。
  • 需集成扫描工具输出与工单系统,确保数据口径一致。building-vulnerability-aging-and-sla-tracking 属于研究检索类 Skill,可作为该场景下的辅助能力补充。
  • 异常延期应触发例外审批流程,并记录补偿控制措施。

SKILL.md

Building Vulnerability Aging and SLA Tracking

Overview

With over 30,000 new vulnerabilities identified in 2024 (a 17% increase from the prior year), organizations must track how long vulnerabilities remain unpatched and whether remediation occurs within defined Service Level Agreements (SLAs). Vulnerability aging measures the time between discovery and remediation, while SLA tracking enforces severity-based deadlines. Industry benchmarks indicate standard SLAs of 14 days for critical, 30 days for high, 60 days for medium, and 90 days for low vulnerabilities, though more aggressive timelines (24-48 hours for actively exploited critical CVEs) are increasingly common. This skill covers designing SLA policies, building aging dashboards, implementing automated escalations, and generating compliance metrics.

When to Use

  • When deploying or configuring building vulnerability aging and sla tracking capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Vulnerability management platform with historical scan data
  • Asset inventory with criticality ratings
  • ITSM/ticketing system for remediation tracking
  • Reporting platform (Splunk, Elastic, Power BI, Grafana)
  • Stakeholder agreement on SLA timelines and escalation procedures

Core Concepts

Standard Vulnerability SLA Framework

SeverityCVSS RangeStandard SLAAggressive SLACISA KEV SLA
Critical9.0-10.014 days48 hoursBOD 22-01 due date
High7.0-8.930 days7 days14 days
Medium4.0-6.960 days30 daysN/A
Low0.1-3.990 days60 daysN/A
Informational0.0Best effortBest effortN/A

Adaptive SLA Modifiers

FactorModifierRationale
Internet-facing asset-50% SLAHigher exposure risk
CISA KEV listedOverride to 48hActive exploitation confirmed
EPSS > 0.7-50% SLAHigh exploitation probability
Tier 1 (crown jewel) asset-25% SLAMaximum business impact
Compensating control in place+25% SLARisk partially mitigated
Vendor patch unavailableException with review dateCannot remediate yet

Key Performance Indicators (KPIs)

KPIFormulaTarget
Mean Time to Remediate (MTTR)Avg(remediation_date - discovery_date)< 30 days overall
SLA Compliance Rate(Vulns remediated within SLA / Total vulns) * 100>= 90%
Overdue Vulnerability CountCount where age > SLATrending downward
Vulnerability Aging DistributionCount by age bucket (0-14d, 15-30d, 31-60d, 60+d)Majority in 0-30d
Remediation VelocityVulns closed per weekTrending upward
Exception Rate(Exceptions / Total vulns) * 100< 5%

Workflow

Step 1: Define SLA Policy Document

Vulnerability Remediation SLA Policy v1.0

1. Scope: All information systems and applications
2. Severity Classification: Based on CVSS v4.0/v3.1 base score
3. SLA Timelines: See Standard SLA Framework table
4. Adaptive Modifiers: Applied based on asset context
5. Exception Process:
   - Must be documented with business justification
   - Requires compensating control description
   - Maximum extension: 90 days (one renewal)
   - CISO approval required for Critical/High exceptions
6. Escalation Path:
   - 50% SLA elapsed: Automated reminder to asset owner
   - 75% SLA elapsed: Escalation to manager
   - 100% SLA elapsed (overdue): CISO notification
   - 120% SLA elapsed: VP/CTO escalation
7. Metrics Reporting: Monthly to security committee

Step 2: Build the Aging Calculation Engine

import pandas as pd
from datetime import datetime, timedelta

class VulnerabilityAgingTracker:
    """Track vulnerability aging and SLA compliance."""

    SLA_DAYS = {
        "Critical": 14,
        "High": 30,
        "Medium": 60,
        "Low": 90,
    }

    def __init__(self, sla_overrides=None):
        if sla_overrides:
            self.SLA_DAYS.update(sla_overrides)

    def calculate_aging(self, vulns_df):
        """Calculate aging metrics for each vulnerability."""
        today = datetime.now()

        vulns_df["discovery_date"] = pd.to_datetime(vulns_df["discovery_date"])
        vulns_df["remediation_date"] = pd.to_datetime(
            vulns_df["remediation_date"], errors="coerce"
        )

        vulns_df["age_days"] = vulns_df.apply(
            lambda row: (row["remediation_date"] - row["discovery_date"]).days
            if pd.notna(row["remediation_date"])
            else (today - row["discovery_date"]).days,
            axis=1
        )

        vulns_df["sla_days"] = vulns_df["severity"].map(self.SLA_DAYS)
        vulns_df["sla_deadline"] = vulns_df["discovery_date"] + \
            pd.to_timedelta(vulns_df["sla_days"], unit="D")

        vulns_df["is_overdue"] = vulns_df.apply(
            lambda row: row["age_days"] > row["sla_days"]
            if pd.isna(row["remediation_date"]) else False,
            axis=1
        )

        vulns_df["sla_compliance"] = vulns_df.apply(
            lambda row: row["age_days"] <= row["sla_days"]
            if pd.notna(row["remediation_date"]) else None,
            axis=1
        )

        vulns_df["days_overdue"] = vulns_df.apply(
            lambda row: max(0, row["age_days"] - row["sla_days"])
            if row["is_overdue"] else 0,
            axis=1
        )

        vulns_df["sla_pct_elapsed"] = (
            vulns_df["age_days"] / vulns_df["sla_days"] * 100
        ).round(1)

        return vulns_df

    def generate_kpis(self, vulns_df):
        """Generate KPI summary from aging data."""
        open_vulns = vulns_df[vulns_df["remediation_date"].isna()]
        closed_vulns = vulns_df[vulns_df["remediation_date"].notna()]

        kpis = {
            "total_vulnerabilities": len(vulns_df),
            "open_vulnerabilities": len(open_vulns),
            "closed_vulnerabilities": len(closed_vulns),
            "overdue_count": open_vulns["is_overdue"].sum(),
            "mttr_days": closed_vulns["age_days"].mean() if len(closed_vulns) > 0 else 0,
            "sla_compliance_rate": (
                closed_vulns["sla_compliance"].mean() * 100
                if len(closed_vulns) > 0 else 0
            ),
        }

        kpis["overdue_by_severity"] = (
            open_vulns[open_vulns["is_overdue"]]
            .groupby("severity")
            .size()
            .to_dict()
        )

        return kpis

    def get_escalation_list(self, vulns_df):
        """Get vulnerabilities requiring escalation."""
        open_vulns = vulns_df[vulns_df["remediation_date"].isna()].copy()

        escalations = []
        for _, vuln in open_vulns.iterrows():
            pct = vuln["sla_pct_elapsed"]
            if pct >= 120:
                level = "VP/CTO Escalation"
            elif pct >= 100:
                level = "CISO Notification"
            elif pct >= 75:
                level = "Manager Escalation"
            elif pct >= 50:
                level = "Owner Reminder"
            else:
                continue

            escalations.append({
                "cve_id": vuln.get("cve_id", ""),
                "severity": vuln["severity"],
                "age_days": vuln["age_days"],
                "sla_days": vuln["sla_days"],
                "days_overdue": vuln["days_overdue"],
                "sla_pct": pct,
                "escalation_level": level,
                "asset": vuln.get("asset", ""),
                "owner": vuln.get("owner", ""),
            })

        return pd.DataFrame(escalations)

Step 3: Dashboard Visualization

# Grafana/Kibana query examples for vulnerability aging

# Age distribution histogram (Elasticsearch)
age_distribution_query = {
    "aggs": {
        "age_buckets": {
            "range": {
                "field": "age_days",
                "ranges": [
                    {"key": "0-7 days", "to": 8},
                    {"key": "8-14 days", "from": 8, "to": 15},
                    {"key": "15-30 days", "from": 15, "to": 31},
                    {"key": "31-60 days", "from": 31, "to": 61},
                    {"key": "61-90 days", "from": 61, "to": 91},
                    {"key": "90+ days", "from": 91},
                ]
            }
        }
    }
}

# SLA compliance trend (monthly)
sla_trend_query = {
    "aggs": {
        "monthly": {
            "date_histogram": {"field": "remediation_date", "interval": "month"},
            "aggs": {
                "within_sla": {
                    "filter": {"script": {
                        "source": "doc['age_days'].value <= doc['sla_days'].value"
                    }}
                }
            }
        }
    }
}

Best Practices

  1. Start with achievable SLA targets and tighten them as processes mature
  2. Adapt SLAs based on asset criticality and threat context, not just CVSS scores
  3. Automate escalation notifications to reduce manual tracking overhead
  4. Track MTTR trends month-over-month to demonstrate improvement
  5. Build exception workflows that require documented compensating controls
  6. Report SLA compliance to executive leadership monthly for accountability
  7. Include aging metrics in security committee and board-level reporting
  8. Integrate SLA tracking with ITSM ticketing for end-to-end remediation visibility

Common Pitfalls

  • Setting unrealistic SLA targets that teams cannot meet, causing SLA fatigue
  • Not adapting SLAs for asset criticality, treating all systems equally
  • Lacking exception processes, forcing teams to either ignore SLAs or request blanket waivers
  • Measuring only open vulnerability count without considering age and SLA compliance
  • Not tracking the SLA clock from discovery date (using report date instead)
  • Failing to re-baseline SLAs as team maturity improves

Related Skills

  • implementing-vulnerability-remediation-sla
  • building-executive-vulnerability-risk-report
  • implementing-security-metrics-and-kpis
  • performing-remediation-validation-scanning

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

37.71%
按下载量换算56

Claude

27.28%
按下载量换算40

Cursor

17.58%
按下载量换算26

Gemini CLI

9.58%
按下载量换算14

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills