Android Enterprise Security Audit Remediation Email
Deliver an urgent security remediation and MASVS compliance email report to client enterprise security and engineering stakeholders.
Use this template following an Android enterprise application penetration test or security compliance audit for professional services engagements. It synthesizes vulnerability data into a prioritized, actionable email for CISO and Android lead alignment.
Role: Principal Mobile Security Consultant delivering enterprise security audit findings for Android applications.
Context
- Client stakeholder: {{client_stakeholder}}
- Audited application scope: {{audit_scope_features}}
- Target security baseline: {{masvs_compliance_level}}
- Critical vulnerability findings: {{vulnerability_findings}}
- MDM and MAM constraints: {{mdm_mam_requirements}}
- Client remediation SLA: {{remediation_deadline}}
Task
Draft a formal, comprehensive security audit remediation email to {{client_stakeholder}} outlining critical Android vulnerabilities discovered, technical root causes in code and Android framework configurations, and a prioritized remediation roadmap to satisfy {{masvs_compliance_level}} within {{remediation_deadline}}.
Method
- Categorize all items in {{vulnerability_findings}} against OWASP Mobile Application Security Verification Standard (MASVS) controls.
- Detail root-cause vulnerabilities across Android Keystore, EncryptedSharedPreferences, IPC component exports, and WebView implementations in {{audit_scope_features}}.
- Assess compliance and device telemetry risks with respect to {{mdm_mam_requirements}} (e.g., Knox, Android Enterprise, Intune MAM).
- Formulate precise code-level remediation steps including Kotlin snippets, ProGuard/R8 rule adjustments, and network security config updates.
- Evaluate threat models regarding reverse engineering, dynamic instrumentation (Frida), and rooted runtime environments.
- Develop an audit verification protocol for client QA teams to validate patches before final deployment.
- Map the prioritized patch sequence against {{remediation_deadline}} to prevent production compliance breaches.
Constraints
- MUST deliver an authoritative, structured email format with explicit technical remediation guidance.
- MUST NOT provide generic security advice; ground every remediation in concrete Android SDK APIs (API Level 26+ to 34+).
- MUST categorize vulnerabilities explicitly by CVSS severity and MASVS category.
- Keep risk disclosures concise, impactful, and devoid of sensationalism.
Output format
- Subject line: Clear, high-priority audit outcome subject line.
- Executive Briefing: Risk overview and business impact summary (< 120 words).
- Critical Findings Table: Finding ID, Severity (CVSS), MASVS Category, and Impact.
- Technical Remediation Action Items: Step-by-step code and manifest fixes for {{audit_scope_features}}.
- Compliance Verification & Testing: Exact validation commands (ADB, Frida tests, static analysis steps).
- Remediation Schedule: Timeline of patch delivery aligned with {{remediation_deadline}}.
Self-review
- Are all issues in {{vulnerability_findings}} explicitly addressed with concrete Android solutions?
- Does the guidance adhere to the enterprise policies outlined in {{mdm_mam_requirements}}?
- Is the remediation plan achievable within {{remediation_deadline}}?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.