You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<li>Sasha Romanosky, <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> Co-creator, <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> author</li>
<li>Sasha Romanosky, <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> Co-creator, <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> author</li>
<p><ahref="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization</a> is proposed as an alternative to
4174
-
<abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Scores. <abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> provides a method for developing vulnerability management decision models that are tailored to the
4175
-
specific needs of different stakeholders. </p>
4168
+
<p><ahref="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization (<abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr>)</a> is an alternative methodology for prioritizing vulnerabilities. </p>
4169
+
<ul>
4170
+
<li>It is designed to address some of the issues with <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> - including <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scoring. </li>
4171
+
<li>It provides a method for developing vulnerability management decision models that are tailored to the specific needs of different stakeholders. </li>
4172
+
</ul>
4176
4173
<p>It is based on research performed by the <ahref="https://www.sei.cmu.edu/about/divisions/cert/">CERT Division</a>
4177
4174
of the <ahref="https://www.sei.cmu.edu">Software Engineering Institute</a> (SEI) at <ahref="https://www.cmu.edu">Carnegie Mellon University</a> (CMU):</p>
<p><ahref="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization</a> is proposed as an alternative to
1503
-
<abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Scores. <abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> provides a method for developing vulnerability management decision models that are tailored to the
1504
-
specific needs of different stakeholders. </p>
1502
+
<p><ahref="https://certcc.github.io/SSVC/">Stakeholder-Specific Vulnerability Categorization (<abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr>)</a> is an alternative methodology for prioritizing vulnerabilities. </p>
1503
+
<ul>
1504
+
<li>It is designed to address some of the issues with <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> - including <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scoring. </li>
1505
+
<li>It provides a method for developing vulnerability management decision models that are tailored to the specific needs of different stakeholders. </li>
1506
+
</ul>
1505
1507
<p>It is based on research performed by the <ahref="https://www.sei.cmu.edu/about/divisions/cert/">CERT Division</a>
1506
1508
of the <ahref="https://www.sei.cmu.edu">Software Engineering Institute</a> (SEI) at <ahref="https://www.cmu.edu">Carnegie Mellon University</a> (CMU):</p>
0 commit comments