Skip to content

CVSS

What is CVSS?

The Common Vulnerability Scoring System provides a standardized method for rating the severity of security vulnerabilities on a scale of 0 to 10.

Information Security

Each of these is named in at least one of the same controls as cvss. The number is how many controls name both.

What the standards actually require on cvss

Requirements naming cvss across 6 standards, quoted from the control text.

FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Inte...

FIRST-CVSS-v4 · FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy
C5 (Germany)1 control

Operate or point to a daily updated online register of known vulnerabilities affecting the provider and assets customers install or run themselves, scored using CVSS, reachable by every customer, and stating per flaw whether an update exists, when it ships and...

C5-PSS-03 · Online Register of Known Vulnerabilities

An authenticated vulnerability scan of a representative sample of end user devices and servers must show no high or critical CVEs older than 14 days with CVSS 7.0 or above.

CEP-PM-03 · Authenticated Vulnerability Scan of Sample Devices
HKMA TM-G-11 control

HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...

HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint
ISMAP (Japan)1 control

ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Su...

ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA · ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management

Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;

JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response

Questions people ask about cvss

What is CVSS?
The Common Vulnerability Scoring System provides a standardized method for rating the severity of security vulnerabilities on a scale of 0 to 10.
Why is CVSS important for compliance?
CVSS is a key concept in Information Security. Understanding cvss helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address CVSS?
CVSS appears in the requirement text of FIRST CSIRT Services Framework and Standards, C5 (Germany), Cyber Essentials Plus, HKMA TM-G-1, ISMAP (Japan). Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about CVSS?
Explore our compliance framework pages to see how cvss applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how CVSS applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.