CVSS
What is CVSS?
The Common Vulnerability Scoring System provides a standardized method for rating the severity of security vulnerabilities on a scale of 0 to 10.
Terms that appear alongside cvss
Each of these is named in at least one of the same controls as cvss. The number is how many controls name both.
- vulnerability 10 shared controls
- cisa 5 shared controls
- remediation 5 shared controls
- cve 4 shared controls
- cybersecurity 4 shared controls
- iso 27001 3 shared controls
- vulnerability disclosure 3 shared controls
- nist 3 shared controls
Frameworks that govern cvss
What the standards actually require on cvss
Requirements naming cvss across 6 standards, quoted from the control text.
FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Inte...
FIRST-CVSS-v4 · FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy →Operate or point to a daily updated online register of known vulnerabilities affecting the provider and assets customers install or run themselves, scored using CVSS, reachable by every customer, and stating per flaw whether an update exists, when it ships and...
C5-PSS-03 · Online Register of Known Vulnerabilities →An authenticated vulnerability scan of a representative sample of end user devices and servers must show no high or critical CVEs older than 14 days with CVSS 7.0 or above.
CEP-PM-03 · Authenticated Vulnerability Scan of Sample Devices →HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...
HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint →ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Su...
ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA · ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Questions people ask about cvss
What is CVSS?
Why is CVSS important for compliance?
Which compliance frameworks address CVSS?
Where can I learn more about CVSS?
See how CVSS applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.