National Institute of Standards and Technology releases draft guide on measuring vulnerabilities of information technology

June 9, 2022 |

The National Institute of Standards and Technology (“NIST”) has released Measuring the Common Vulnerability Scoring System Base Score Equation for comment.  It is a particularly useful document in that calculating the severity of information technology vulnerabilities permits prioritisation of remediation techniques.  It also helps to understand the risk of a vulnerability.

The abstract provides:

It is a highly 52 page technical document .

Some matters worth noting about the Common Vulnerability Scoring System (CVSS):

  • it is a widely used industry standard for characterizing the properties of information technology vulnerabilities and measuring their severity.
  • it is based on human expert opinion.
  • the severity is defned primarily through a multi-part “base score” equation, with 8 input metrics.

Leave a Reply





Verified by MonsterInsights