You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<li>Organizations may want to extend, customize, or optimize a <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization Scheme for their environment e.g. change the prioritization associated with a data source or add a new data source.</li>
5087
-
<li>Some schemes do this by design e.g. <ahref="https://github.com/CERTCC/SSVC"><abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr></a>"<abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr>aims to avoid one-size-fits-all solutions in favor of a modular decision-making system with clearly defined and tested parts that vulnerability managers can select and use as appropriate to their context."</li>
5087
+
<li>Some schemes do this by design e.g. <em>"<ahref="https://github.com/CERTCC/SSVC"><abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr></a> aims to avoid one-size-fits-all solutions in favor of a modular decision-making system with clearly defined and tested parts that vulnerability managers can select and use as appropriate to their context."</em></li>
5088
5088
</ol>
5089
+
</li>
5090
+
</ol>
5091
+
<h3id="risk-takeaway-cvss-temporal-threat-metrics"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Temporal & Threat Metrics<aclass="headerlink" href="#risk-takeaway-cvss-temporal-threat-metrics" title="Permanent link">¶</a></h3>
5092
+
<p>It is possible to combine all the key risk factors into an overall <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score but...</p>
5093
+
<divclass="admonition quote">
5094
+
<pclass="admonition-title">Quote</p>
5095
+
<p>The convenience of a single <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score comes with the cost of not being able to understand or differentiate between the risk factors from the score, and not being able to prioritize effectively using the score.</p>
5096
+
<p><ahref="#cvss-cvss"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a></p>
5097
+
</div>
5098
+
<p>But if you do chose this option then, see "Enriching the <abbrtitle="National Vulnerability Database">NVD</abbr><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal & Threat Metrics" project referenced in <ahref="#cvss-cvss"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a>.</p>
5099
+
<h3id="risk-takeaway-cvss-base-score-ratings-with-exploitation-focus"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score Ratings with Exploitation Focus<aclass="headerlink" href="#risk-takeaway-cvss-base-score-ratings-with-exploitation-focus" title="Permanent link">¶</a></h3>
5100
+
<p><ahref="#vendors-qualys-in-depth-look-into-data-driven-science-behind-qualys-trurisk">Qualys TruRisk Approach</a> is a good starting point. Any organization can apply this approach or similar.</p>
5101
+
<p><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> should be included to inform "likelihood of exploitation".</p>
5102
+
<ul>
5103
+
<li>TODO provide code to implement this or similar</li>
<p><ahref="#ssvc-ssvc"><abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr></a> Decision Trees can give more granularity than combining <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Ratings and Exploitation factors i.e. better <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization.</p>
5107
+
<p>The <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base score parameters are used instead of <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores.</p>
5108
+
<ul>
5109
+
<li>Reference Code is provided in this guide.</li>
5110
+
</ul>
5089
5111
<h2id="risk-takeaway-risk-based-prioritization-summary-against-requirements"><abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization Summary against Requirements<aclass="headerlink" href="#risk-takeaway-risk-based-prioritization-summary-against-requirements" title="Permanent link">¶</a></h2>
5090
5112
<table>
5091
5113
<thead>
5092
5114
<tr>
5093
5115
<th>Requirement</th>
5094
5116
<th><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></th>
5095
-
<th>Qualys</th>
5117
+
<th><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score Ratings with Exploitation Focus</th>
<h3id="risk-takeaway-cvss-temporal-threat-metrics"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Temporal & Threat Metrics<aclass="headerlink" href="#risk-takeaway-cvss-temporal-threat-metrics" title="Permanent link">¶</a></h3>
5121
-
<p>It is possible to combine all the key risk factors into an overall <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score but...</p>
5122
-
<divclass="admonition quote">
5123
-
<pclass="admonition-title">Quote</p>
5124
-
<p>The convenience of a single <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score comes with the cost of not being able to understand or differentiate between the risk factors from the score, and not being able to prioritize effectively using the score.</p>
5125
-
<p><ahref="#cvss-cvss"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a></p>
5126
-
</div>
5127
-
<p>But if you do chose this option then, see "Enriching the <abbrtitle="National Vulnerability Database">NVD</abbr><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal & Threat Metrics" project referenced in <ahref="#cvss-cvss"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a>.</p>
5128
-
<h3id="risk-takeaway-cvss-base-score-ratings-with-exploitation-focus"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score Ratings with Exploitation Focus<aclass="headerlink" href="#risk-takeaway-cvss-base-score-ratings-with-exploitation-focus" title="Permanent link">¶</a></h3>
5129
-
<p><ahref="#vendors-qualys-in-depth-look-into-data-driven-science-behind-qualys-trurisk">Qualys TruRisk Approach</a> is a good starting point. Any organization can apply this approach or similar.</p>
5130
-
<p><abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> should be included to inform "likelihood of exploitation".</p>
5131
-
<ul>
5132
-
<li>TODO provide code to implement this or similar</li>
<p><ahref="#ssvc-ssvc"><abbrtitle="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr></a> Decision Trees can give more granularity than combining <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Ratings and Exploitation factors i.e. better <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization.</p>
5136
-
<p>The <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base score parameters are used instead of <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores.</p>
5137
-
<ul>
5138
-
<li>Reference Code is provided in this guide.</li>
<p>If you <strong>implement</strong> a proprietary <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization scheme, keep the following in mind:</p>
0 commit comments