Abstract
Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.
| Original language | American English |
|---|---|
| Number of pages | 29 |
| DOIs | |
| State | Published - 2026 |
NLR Publication Number
- NLR/TP-5T00-96283
Keywords
- coordinated vulnerability disclosure
- EVSE
- exploitations
- mitigations
- vulnerability
- weakness
Fingerprint
Dive into the research topics of 'Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver