When a vendor announces active exploitation of an unknown vulnerability, your incident response clock starts immediately. Your compliance posture depends on what you do in the first 48 hours.
This checklist guides compliance teams through critical steps when a zero-day vulnerability affects systems within your audit scope. It's based on ISO/IEC 27001:2022 Clause 6.1.2 (information security risk assessment) and the SOC 2 Trust Services Criteria CC7.3 (detection and response to security incidents).
Prerequisites
Before executing this checklist, ensure you have:
- Asset inventory: A current, searchable list of all software products and versions in your environment (ISO/IEC 27001:2022 Control 5.9).
- Incident response plan: A documented procedure defining roles, communication paths, and escalation criteria (ISO/IEC 27001:2022 Control 5.26).
- Change management authority: Pre-approved emergency change procedures for patching critical systems without standard approval cycles (SOC 2 CC8.1).
- Network documentation: Current network diagrams showing segmentation boundaries and access control points.
If you're missing any of these, you'll struggle to respond quickly. Aim to identify affected systems within 15 minutes and have authority to implement emergency controls within the hour.
Zero-Day Response Checklist
1. Identify affected systems within your audit scope
☐ Search your asset inventory for the affected product and all listed versions.
☐ Cross-reference against your system categorization to identify which systems process, store, or transmit data covered by your compliance obligations.
☐ Document the business function each affected system supports.
Goal: Have a complete list of affected systems, their data classification level, and their role in your control environment within 30 minutes of the vendor announcement.
2. Assess immediate risk to compliance controls
☐ Review which SOC 2 Trust Services Criteria or ISO/IEC 27001 controls depend on the affected systems.
☐ Determine if the vulnerability creates a control gap that would constitute a Major Nonconformity or Type I exception.
☐ Identify any compensating controls currently in place that might reduce immediate risk.
Goal: Clearly articulate to your auditor which specific controls are at risk and the business impact if those controls failed.
3. Implement vendor-recommended emergency mitigations
☐ Review the vendor's security advisory for temporary protective measures.
☐ If network isolation is recommended, implement firewall rules or network access controls to restrict access to trusted IP addresses only.
☐ Document what you implemented, when, and who authorized it.
☐ Verify the mitigation is working through testing or monitoring.
Goal: Emergency controls are in place within 2 hours, documented in your change log, and verified effective. Documentation includes specific IP ranges or network segments protected.
4. Install emergency patches
☐ Obtain the patch from the vendor's official source.
☐ Test the patch in a non-production environment if time permits.
☐ Deploy to production systems using your emergency change procedure.
☐ Verify successful installation on each affected system.
☐ Retain evidence of patch deployment (timestamps, version confirmations, deployment logs).
Goal: Patches are deployed within 24 hours for critical systems, within 72 hours for others. Change records show who approved, who deployed, and verification of success.
5. Check for indicators of compromise
☐ Review the vendor's published indicators of compromise.
☐ Search logs, SIEM alerts, and endpoint detection tools for evidence of the specific indicators.
☐ Document your findings, even if you find no evidence of compromise.
Goal: You've searched all relevant log sources, documented what you checked and when, and can demonstrate to an auditor that you looked for evidence of exploitation.
6. Update your risk register
☐ Add the zero-day event to your information security risk register.
☐ Document the risk treatment actions you took (patches, network controls, monitoring).
☐ Assess residual risk after your mitigations.
☐ Set a review date to verify the risk treatment remains effective.
Goal: Your Risk Treatment Plan (ISO/IEC 27001:2022 Clause 6.1.3) shows this event, your response, and how it affected your overall risk posture. An auditor can trace from the vendor announcement to your documented risk treatment.
7. Notify stakeholders per your incident response plan
☐ Inform your executive management if the vulnerability affects critical systems.
☐ Notify your external auditor if you're currently in an assurance engagement period.
☐ Alert affected business units about any service disruptions from your emergency controls.
☐ Document all notifications with timestamps.
Goal: Your incident log shows who you notified, when, and through what channel. If your auditor asks, you can show you followed your documented escalation criteria.
8. Preserve evidence for audit purposes
☐ Collect and preserve logs showing when you discovered the vulnerability.
☐ Save copies of the vendor advisory and any technical bulletins.
☐ Document your timeline: when you learned of the issue, when you implemented controls, when you patched.
☐ Retain evidence of testing and verification.
Goal: You have a complete evidence package that demonstrates compliance with your incident response procedures and satisfies ISO/IEC 27001:2022 Control 5.28 (collection of evidence).
Common Mistakes
Waiting for the CVE: Don't wait for formal tracking numbers to take action.
Skipping documentation under time pressure: Even a timestamped email documenting your actions is better than nothing.
Treating all systems equally: Use a risk-based approach. Patch internet-facing systems before internal development tools.
Forgetting compensating controls: If you can't patch immediately, document temporary controls and when you plan to remove them.
Not testing your IOC searches: Verify you're looking in the right log sources and know what a positive match would look like.
Next Steps
After completing this checklist:
- Schedule a post-incident review within two weeks.
- Update your incident response plan with lessons learned.
- Verify your asset inventory was accurate; if not, fix it.
- Review your patch management procedures to identify gaps.
- Document this event in your next management review (ISO/IEC 27001:2022 Clause 9.3).
The goal isn't just to survive this zero-day. It's to demonstrate to your auditors that your controls work under pressure, your procedures are followed even in emergencies, and your risk management process adapts to new threats. That's what separates a compliant organization from one that just has compliance documentation.



