flâneur — a map of the web's best reading

Flipping the Vulnerability Management Model: CVSS → SSVC | by Stephen Shaffer | Medium

stephenshaffer.io · 3,164 words · saved by 1 readers

Vulnerability Management programs and products often utilize the Common Vulnerability Scoring System (CVSS) as a metric to deduce the severity of a particular vulnerability and make a decision on how to mitigate the vulnerability from being exploited. Organizations may expand the base score that is included with each Common Vulnerabilities and Exposures ID (CVE) by adding additional context to the score using Environmental and Temporal Metrics. These metrics can ingest a variety of signals such as the Exploit Prediction Scoring System (EPSS) or where the system sits in an organization’s infrastructure. These additional signals are very valuable information to help prioritize vulnerabilities, but the scoring system has muddied the waters of vulnerability and risk management. We should consider changing our approach by using a different model to achieve better results. In this post, I am going to make my case for a shift to a vulnerability management model based on the Stakeholder-Specif

Flipping the Vulnerability Management Model: CVSS → SSVC Stephen Shaffer 13 min read · Jun 21, 2023 -- Listen Share Press enter or click to view image in full size Photo by JESHOOTS.COM on Unsplash Vulnerability Management programs and products often utilize the Common Vulnerability Scoring System (CVSS) as a metric to deduce the severity of a particular vulnerability and make a decision on how to mitigate the vulnerability from being exploited. Organizations may expand the base score that is included with each Common Vulnerabilities and Exposures ID (CVE) by adding additional context to the s

Explore this link on the map →

related reading