Flipping the Vulnerability Management Model: CVSS → SSVC | by Stephen Shaffer | Medium
Vulnerability Management programs and products often utilize the Common Vulnerability Scoring System (CVSS) as a metric to deduce the severity of a particular vulnerability and make a decision on how to mitigate the vulnerability from being exploited. Organizations may expand the base score that is included with each Common Vulnerabilities and Exposures ID (CVE) by adding additional context to the score using Environmental and Temporal Metrics. These metrics can ingest a variety of signals such as the Exploit Prediction Scoring System (EPSS) or where the system sits in an organization’s infrastructure. These additional signals are very valuable information to help prioritize vulnerabilities, but the scoring system has muddied the waters of vulnerability and risk management. We should consider changing our approach by using a different model to achieve better results. In this post, I am going to make my case for a shift to a vulnerability management model based on the Stakeholder-Specif
Flipping the Vulnerability Management Model: CVSS → SSVC Stephen Shaffer 13 min read · Jun 21, 2023 -- Listen Share Press enter or click to view image in full size Photo by JESHOOTS.COM on Unsplash Vulnerability Management programs and products often utilize the Common Vulnerability Scoring System (CVSS) as a metric to deduce the severity of a particular vulnerability and make a decision on how to mitigate the vulnerability from being exploited. Organizations may expand the base score that is included with each Common Vulnerabilities and Exposures ID (CVE) by adding additional context to the s
Explore this link on the map →related reading
- Mediumstephenshaffer.io
- Unified Vulnerability Management (UVM) | Zscaleravalor.io
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Unified Vulnerability Management (UVM) | Zscaleravalor.io
- Claude Mythos Preview System Cardwww-cdn.anthropic.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- The bogus CVE problem [LWN.net]lwn.net
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org
- OpenSSF Scorecardsecurityscorecards.dev
- Measuring LLMs’ ability to develop exploits \ Anthropicred.anthropic.com
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com