Action Plan

Format: Prioritized checklist with owner suggestion, effort estimate, success criteria. Owners are suggestions โ€” adjust to your org structure.


๐Ÿ”ด P0 โ€” Do now (within 24 hours)

P0.1 โ€” Take Jira offline or migrate

P0.2 โ€” Rotate all leaked secrets from public repos


๐ŸŸ  P1 โ€” Do this week (within 7 days)

P1.1 โ€” Lock down EKS control plane

P1.2 โ€” Remove public SSH on dev hosts


๐ŸŸก P2 โ€” Do this sprint (within 2 weeks)

P2.1 โ€” Apply Kubernetes hardening defaults

P2.2 โ€” Remove dead DNS/ALB entries

P2.3 โ€” Audit doc.corezoid.com Google Doc


๐Ÿ”ต P3 โ€” Do this quarter (within 90 days)

P3.1 โ€” Org-wide secret management

P3.2 โ€” Close Jira migration + secrets cleanup loop

P3.3 โ€” Expand testing coverage


Tracking

Priority Count Findings
๐Ÿ”ด P0 2 CRZ-006 (Jira EOL), CRZ-009 (public-repo secrets)
๐ŸŸ  P1 5 CRZ-002 (k8s public), CRZ-007 (OpenSSH regreSSHion), CRZ-008 (SameSite), CRZ-011 (VPN TLS), CRZ-015 (postMessage origin)
๐ŸŸก P2 4 CRZ-010 (k8s hardening), CRZ-013 (destructive-op audit), CRZ-003 (widget nginx), CRZ-001 (admin-pre DNS)
๐Ÿ”ต P3 4 CRZ-012 (SHA-1 signatures โ†’ HMAC-SHA256 migration), CRZ-004 (Google Doc), CRZ-014 (super-user scope), org-wide secret mgmt
โšช Info 1 CRZ-005 (OpenVPN-AS version โ€” monitor)

Total findings: 15 (1 Critical, 3 High, 5 Medium, 3 Low/Low-Med, 3 Info). Engagement complete; no more findings pending.