flâneur — a map of the web's best reading

Determining EPSS Score Thresholds for Prioritization | by Stephen Shaffer | Medium

stephenshaffer.io · 2,182 words · saved by 1 readers

As I observe the adoption and rhetoric around the Exploit Prediction Scoring System (EPSS), two themes that I see recurring are: The last bit is an intentional omission by the co-chairs, as it is not a problem that the model is designed to solve, nor do the co-chairs recommend the usage of “binning” without a clear understanding that the practice could result in information loss. However, industry adoption of EPSS may suffer if there is not at least some guidance on how to integrate it into existing vulnerability scoring or prioritization methodologies, including when to start caring about the score and/or percentile (hint: you should always care). Of course, organizations and vendors are welcome to decide on their thresholds for prioritization/categorization based on their risk tolerance or scoring system. Still, in practice, this may be even harder to determine than the exercise I’m about to perform here. I’ve seen entities vary widely in how they bin EPSS scores (with some even trea

Cybersecurity Threat Intelligence Data Science Machine Learning Vulnerability Management Determining EPSS Score Thresholds for Prioritization Stephen Shaffer 9 min read · Nov 5, 2023 -- 1 Listen Share Press enter or click to view image in full size As I observe the adoption and rhetoric around the Exploit Prediction Scoring System (EPSS), two themes that I see recurring are: An unfamiliarity with what EPSS actually is; and Unclear guidance on how to determine score thresholds for prioritization. The last bit is an intentional omission by the co-chairs, as it is not a problem that the model is

Explore this link on the map →

related reading