CVE
What is CVE?
Common Vulnerabilities and Exposures, a catalog of publicly known cybersecurity vulnerabilities identified by unique CVE ID numbers.
Terms that appear alongside cve
Each of these is named in at least one of the same controls as cve. The number is how many controls name both.
- vulnerability 18 shared controls
- cisa 7 shared controls
- policy 6 shared controls
- vulnerability disclosure 6 shared controls
- penetration testing 6 shared controls
- remediation 5 shared controls
- vulnerability scanning 5 shared controls
- mitre 5 shared controls
Frameworks that govern cve
What the standards actually require on cve
Requirements naming cve across 6 standards, quoted from the control text.
Issue CVEs for security defects with CWE root cause and accurate severity, supporting customer triage.
SBD-10 · CVE Issuance with Complete Detail →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Integrate D3FEND with broader cybersecurity ecosystem and frameworks. ATT&CK-D3FEND bidirectional mappings - each D3FEND defensive technique is mapped to ATT&CK offensive techniques it counters + each ATT&CK offensive technique maps to D3FEND defensive techniq...
MITRE-D3FEND-Integration-Mapping-ATTACK-CWE-CVE-CAPEC-NIST-CSF-CIS-ISO-27001-STIX-OpenC2 · MITRE D3FEND Integration + Mapping + ATT&CK + CWE + CVE + CAPEC + NIST CSF + CIS + ISO 27001 + STIX + OpenC2 →Rank 18 in the 2024 CWE Top 25 (frequency x severity of CVEs). The software performs an authorization check but does so incorrectly, granting access that should be denied.
CWE-863 · Incorrect Authorization →An external (unauthenticated) vulnerability scan of all internet-facing IP addresses in scope. Any high or critical CVE older than 14 days fails.
CE-PLUS.2 · External Vulnerability Scan of Internet IPs →UR E27 requires equipment manufacturers to provide Software Bill of Materials (SBOM) and demonstrate secure development. SBOM contents per CISA SBOM Minimum Elements + SPDX or CycloneDX format: component name + version + supplier + license + dependency relatio...
IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity · IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity →Questions people ask about cve
What is CVE?
Why is CVE important for compliance?
Which compliance frameworks address CVE?
Where can I learn more about CVE?
See how CVE applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.