Skip to content

Commit 10b6c02

Browse files
committed
Deployed fbb7403 with MkDocs version: 1.5.3
1 parent b168efa commit 10b6c02

7 files changed

Lines changed: 52 additions & 58 deletions

File tree

epss/EPSS_Thresholds/index.html

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1863,12 +1863,7 @@ <h3 id="monte-carlo-simulation-for-a-typical-enterprise">Monte Carlo Simulation
18631863
<p class="admonition-title">Recipe</p>
18641864
<ol>
18651865
<li>Take random % sample of CVEs <ol>
1866-
<li>where, e.g. 20%, corresponds to ~44K CVEs of ~220K CVEs<ol>
1867-
<li>where this number is chosen to be close to (but greater than
1868-
to give a worst case scenario) the ~40K CVEs observed in
1869-
the Cisco data set across 1000 enterprises</li>
1870-
</ol>
1871-
</li>
1866+
<li>where, e.g. 20%, corresponds to ~44K CVEs of ~220K CVEs</li>
18721867
</ol>
18731868
</li>
18741869
<li>Plot the result</li>

introduction/contributors/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1405,7 +1405,7 @@ <h1 id="contributors">Contributors<a class="headerlink" href="#contributors" tit
14051405
<li>Maor Kuriel</li>
14061406
<li>Patrick Garrity, VulnCheck</li>
14071407
<li>Sasha Romanosky, <abbr title="Exploit Prediction Scoring System">EPSS</abbr> Co-creator, <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> author</li>
1408-
<li>Stephen Shaffer, Peleton</li>
1408+
<li>Stephen Shaffer, Peloton</li>
14091409
<li>Steve Finegan</li>
14101410
</ul>
14111411

print_page/index.html

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1900,7 +1900,7 @@ <h2 id="introduction-introduction-notes">Notes<a class="headerlink" href="#intro
19001900
<li>Maor Kuriel</li>
19011901
<li>Patrick Garrity, VulnCheck</li>
19021902
<li>Sasha Romanosky, <abbr title="Exploit Prediction Scoring System">EPSS</abbr> Co-creator, <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> author</li>
1903-
<li>Stephen Shaffer, Peleton</li>
1903+
<li>Stephen Shaffer, Peloton</li>
19041904
<li>Steve Finegan</li>
19051905
</ul></section><section class="print-page" id="introduction-scope"><h1 id="introduction-scope-scope">Scope<a class="headerlink" href="#introduction-scope-scope" title="Permanent link">&para;</a></h1>
19061906
<div class="admonition abstract">
@@ -4047,12 +4047,7 @@ <h3 id="epss-epss_thresholds-monte-carlo-simulation-for-a-typical-enterprise">Mo
40474047
<p class="admonition-title">Recipe</p>
40484048
<ol>
40494049
<li>Take random % sample of CVEs <ol>
4050-
<li>where, e.g. 20%, corresponds to ~44K CVEs of ~220K CVEs<ol>
4051-
<li>where this number is chosen to be close to (but greater than
4052-
to give a worst case scenario) the ~40K CVEs observed in
4053-
the Cisco data set across 1000 enterprises</li>
4054-
</ol>
4055-
</li>
4050+
<li>where, e.g. 20%, corresponds to ~44K CVEs of ~220K CVEs</li>
40564051
</ol>
40574052
</li>
40584053
<li>Plot the result</li>
@@ -4170,9 +4165,11 @@ <h2 class='nav-section-title' id='section-stakeholder-specific-vulnerability-cat
41704165
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/cisa_ssvc_dt/DT_from_scratch.ipynb">Source Code</a> </p>
41714166
</div>
41724167
<h2 id="ssvc-ssvc-ssvc"><abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr><a class="headerlink" href="#ssvc-ssvc-ssvc" title="Permanent link">&para;</a></h2>
4173-
<p><a href="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization</a> is proposed as an alternative to
4174-
<abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Scores. <abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> provides a method for developing vulnerability management decision models that are tailored to the
4175-
specific needs of different stakeholders. </p>
4168+
<p><a href="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization (<abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr>)</a> is an alternative methodology for prioritizing vulnerabilities. </p>
4169+
<ul>
4170+
<li>It is designed to address some of the issues with <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> - including <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scoring. </li>
4171+
<li>It provides a method for developing vulnerability management decision models that are tailored to the specific needs of different stakeholders. </li>
4172+
</ul>
41764173
<p>It is based on research performed by the <a href="https://www.sei.cmu.edu/about/divisions/cert/">CERT Division</a>
41774174
of the <a href="https://www.sei.cmu.edu">Software Engineering Institute</a> (SEI) at <a href="https://www.cmu.edu">Carnegie Mellon University</a> (CMU):</p>
41784175
<ul>

search/search_index.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

sitemap.xml

Lines changed: 37 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -2,187 +2,187 @@
22
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
33
<url>
44
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/</loc>
5-
<lastmod>2024-03-12</lastmod>
5+
<lastmod>2024-03-13</lastmod>
66
<changefreq>daily</changefreq>
77
</url>
88
<url>
99
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/annex/Glossary/</loc>
10-
<lastmod>2024-03-12</lastmod>
10+
<lastmod>2024-03-13</lastmod>
1111
<changefreq>daily</changefreq>
1212
</url>
1313
<url>
1414
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/cisa_kev/cisa_kev/</loc>
15-
<lastmod>2024-03-12</lastmod>
15+
<lastmod>2024-03-13</lastmod>
1616
<changefreq>daily</changefreq>
1717
</url>
1818
<url>
1919
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/cvss/CVSS/</loc>
20-
<lastmod>2024-03-12</lastmod>
20+
<lastmod>2024-03-13</lastmod>
2121
<changefreq>daily</changefreq>
2222
</url>
2323
<url>
2424
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/epss/Applying_EPSS_to_your_environment/</loc>
25-
<lastmod>2024-03-12</lastmod>
25+
<lastmod>2024-03-13</lastmod>
2626
<changefreq>daily</changefreq>
2727
</url>
2828
<url>
2929
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/epss/EPSS_Thresholds/</loc>
30-
<lastmod>2024-03-12</lastmod>
30+
<lastmod>2024-03-13</lastmod>
3131
<changefreq>daily</changefreq>
3232
</url>
3333
<url>
3434
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/epss/EPSS_and_CISA_KEV/</loc>
35-
<lastmod>2024-03-12</lastmod>
35+
<lastmod>2024-03-13</lastmod>
3636
<changefreq>daily</changefreq>
3737
</url>
3838
<url>
3939
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/epss/Introduction_to_EPSS/</loc>
40-
<lastmod>2024-03-12</lastmod>
40+
<lastmod>2024-03-13</lastmod>
4141
<changefreq>daily</changefreq>
4242
</url>
4343
<url>
4444
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/epss/What_users_ask_for/</loc>
45-
<lastmod>2024-03-12</lastmod>
45+
<lastmod>2024-03-13</lastmod>
4646
<changefreq>daily</changefreq>
4747
</url>
4848
<url>
4949
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/includes/abbreviations/</loc>
50-
<lastmod>2024-03-12</lastmod>
50+
<lastmod>2024-03-13</lastmod>
5151
<changefreq>daily</changefreq>
5252
</url>
5353
<url>
5454
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/includes/epss_threshold/</loc>
55-
<lastmod>2024-03-12</lastmod>
55+
<lastmod>2024-03-13</lastmod>
5656
<changefreq>daily</changefreq>
5757
</url>
5858
<url>
5959
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/includes/plots_cvss_epss/</loc>
60-
<lastmod>2024-03-12</lastmod>
60+
<lastmod>2024-03-13</lastmod>
6161
<changefreq>daily</changefreq>
6262
</url>
6363
<url>
6464
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/includes/vendor_warning/</loc>
65-
<lastmod>2024-03-12</lastmod>
65+
<lastmod>2024-03-13</lastmod>
6666
<changefreq>daily</changefreq>
6767
</url>
6868
<url>
6969
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/includes/vulns_exploited/</loc>
70-
<lastmod>2024-03-12</lastmod>
70+
<lastmod>2024-03-13</lastmod>
7171
<changefreq>daily</changefreq>
7272
</url>
7373
<url>
7474
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/introduction/Introduction/</loc>
75-
<lastmod>2024-03-12</lastmod>
75+
<lastmod>2024-03-13</lastmod>
7676
<changefreq>daily</changefreq>
7777
</url>
7878
<url>
7979
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/introduction/Scope/</loc>
80-
<lastmod>2024-03-12</lastmod>
80+
<lastmod>2024-03-13</lastmod>
8181
<changefreq>daily</changefreq>
8282
</url>
8383
<url>
8484
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/introduction/code_and_data/</loc>
85-
<lastmod>2024-03-12</lastmod>
85+
<lastmod>2024-03-13</lastmod>
8686
<changefreq>daily</changefreq>
8787
</url>
8888
<url>
8989
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/introduction/contributors/</loc>
90-
<lastmod>2024-03-12</lastmod>
90+
<lastmod>2024-03-13</lastmod>
9191
<changefreq>daily</changefreq>
9292
</url>
9393
<url>
9494
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/introduction/foreword/</loc>
95-
<lastmod>2024-03-12</lastmod>
95+
<lastmod>2024-03-13</lastmod>
9696
<changefreq>daily</changefreq>
9797
</url>
9898
<url>
9999
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/introduction/preface/</loc>
100-
<lastmod>2024-03-12</lastmod>
100+
<lastmod>2024-03-13</lastmod>
101101
<changefreq>daily</changefreq>
102102
</url>
103103
<url>
104104
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/organizations/Yahoo/</loc>
105-
<lastmod>2024-03-12</lastmod>
105+
<lastmod>2024-03-13</lastmod>
106106
<changefreq>daily</changefreq>
107107
</url>
108108
<url>
109109
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/organizations/acme/Applied/</loc>
110-
<lastmod>2024-03-12</lastmod>
110+
<lastmod>2024-03-13</lastmod>
111111
<changefreq>daily</changefreq>
112112
</url>
113113
<url>
114114
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/requirements/Requirements/</loc>
115-
<lastmod>2024-03-12</lastmod>
115+
<lastmod>2024-03-13</lastmod>
116116
<changefreq>daily</changefreq>
117117
</url>
118118
<url>
119119
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Back_of_napkin/</loc>
120-
<lastmod>2024-03-12</lastmod>
120+
<lastmod>2024-03-13</lastmod>
121121
<changefreq>daily</changefreq>
122122
</url>
123123
<url>
124124
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Data_Sources/</loc>
125-
<lastmod>2024-03-12</lastmod>
125+
<lastmod>2024-03-13</lastmod>
126126
<changefreq>daily</changefreq>
127127
</url>
128128
<url>
129129
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Log4Shell/</loc>
130-
<lastmod>2024-03-12</lastmod>
130+
<lastmod>2024-03-13</lastmod>
131131
<changefreq>daily</changefreq>
132132
</url>
133133
<url>
134134
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Rbp_schemes/</loc>
135-
<lastmod>2024-03-12</lastmod>
135+
<lastmod>2024-03-13</lastmod>
136136
<changefreq>daily</changefreq>
137137
</url>
138138
<url>
139139
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Takeaway/</loc>
140-
<lastmod>2024-03-12</lastmod>
140+
<lastmod>2024-03-13</lastmod>
141141
<changefreq>daily</changefreq>
142142
</url>
143143
<url>
144144
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Understanding_Risk/</loc>
145-
<lastmod>2024-03-12</lastmod>
145+
<lastmod>2024-03-13</lastmod>
146146
<changefreq>daily</changefreq>
147147
</url>
148148
<url>
149149
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/risk/Vulnerability_Landscape/</loc>
150-
<lastmod>2024-03-12</lastmod>
150+
<lastmod>2024-03-13</lastmod>
151151
<changefreq>daily</changefreq>
152152
</url>
153153
<url>
154154
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/ssvc/SSVC/</loc>
155-
<lastmod>2024-03-12</lastmod>
155+
<lastmod>2024-03-13</lastmod>
156156
<changefreq>daily</changefreq>
157157
</url>
158158
<url>
159159
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/ssvc/decision_trees/</loc>
160-
<lastmod>2024-03-12</lastmod>
160+
<lastmod>2024-03-13</lastmod>
161161
<changefreq>daily</changefreq>
162162
</url>
163163
<url>
164164
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/ssvc/decision_trees_from_scratch/</loc>
165-
<lastmod>2024-03-12</lastmod>
165+
<lastmod>2024-03-13</lastmod>
166166
<changefreq>daily</changefreq>
167167
</url>
168168
<url>
169169
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/vendors/Edgescan/</loc>
170-
<lastmod>2024-03-12</lastmod>
170+
<lastmod>2024-03-13</lastmod>
171171
<changefreq>daily</changefreq>
172172
</url>
173173
<url>
174174
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/vendors/Microsoft_Exploitability_Index/</loc>
175-
<lastmod>2024-03-12</lastmod>
175+
<lastmod>2024-03-13</lastmod>
176176
<changefreq>daily</changefreq>
177177
</url>
178178
<url>
179179
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/vendors/Qualys/</loc>
180-
<lastmod>2024-03-12</lastmod>
180+
<lastmod>2024-03-13</lastmod>
181181
<changefreq>daily</changefreq>
182182
</url>
183183
<url>
184184
<loc>https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/vendors/vendors/</loc>
185-
<lastmod>2024-03-12</lastmod>
185+
<lastmod>2024-03-13</lastmod>
186186
<changefreq>daily</changefreq>
187187
</url>
188188
</urlset>

sitemap.xml.gz

0 Bytes
Binary file not shown.

ssvc/SSVC/index.html

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1499,9 +1499,11 @@ <h1 id="stakeholder-specific-vulnerability-categorization-ssvc">Stakeholder-Spec
14991499
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/cisa_ssvc_dt/DT_from_scratch.ipynb">Source Code</a> </p>
15001500
</div>
15011501
<h2 id="ssvc"><abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr><a class="headerlink" href="#ssvc" title="Permanent link">&para;</a></h2>
1502-
<p><a href="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization</a> is proposed as an alternative to
1503-
<abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Scores. <abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> provides a method for developing vulnerability management decision models that are tailored to the
1504-
specific needs of different stakeholders. </p>
1502+
<p><a href="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization (<abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr>)</a> is an alternative methodology for prioritizing vulnerabilities. </p>
1503+
<ul>
1504+
<li>It is designed to address some of the issues with <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> - including <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scoring. </li>
1505+
<li>It provides a method for developing vulnerability management decision models that are tailored to the specific needs of different stakeholders. </li>
1506+
</ul>
15051507
<p>It is based on research performed by the <a href="https://www.sei.cmu.edu/about/divisions/cert/">CERT Division</a>
15061508
of the <a href="https://www.sei.cmu.edu">Software Engineering Institute</a> (SEI) at <a href="https://www.cmu.edu">Carnegie Mellon University</a> (CMU):</p>
15071509
<ul>

0 commit comments

Comments
 (0)