Operational readiness
1. Identify the affected product with digital elements and internal product/version record.
2. Capture the nature of the actively exploited vulnerability or severe incident.
3. Record corrective or mitigating measures already taken.
4. Record corrective or mitigating actions users can take, where available.
5. For a severe incident, prepare an initial assessment of the incident.
6. Record information sensitivity where applicable and keep an evidence trail of who approved the submission.