Skip to main navigation Skip to search Skip to main content

Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance

  • National Laboratory of the Rockies

Research output: NLRTechnical Report

Abstract

Vulnerability management is a process of discovering, analyzing, and handling new or reported security vulnerabilities in systems to prevent the systems from being exploited, to reduce risk, and to protect assets. For vulnerability analysis, handling, and response, the prioritization of organizational and analyst resources must precede. The Common Vulnerability Scoring System (CVSS) is a standard prioritization method that is used to rate the severity of security vulnerabilities in systems by assigning numerical severity scores, but it does not provide clear guidelines of how the numerical severity scores might inform decisions. The Stakeholder-Specific Vulnerability Categorization (SSVC) provides a method for prioritizing vulnerabilities based on the needs of the stakeholders involved in the vulnerability management process. Instead of the numerical scoring used in the CVSS, the SSVC focuses on contextual decision-making to determine how quickly and effectively an organization should respond to vulnerabilities. The main functionality of the SSVC accommodates the diversity of the stakeholders in the vulnerability management process, including finders, vendors, coordinators, deployers, and others. So, the SSVC should be designed to be used by any of these stakeholders, and it should be customizable to enable specific stakeholder decision models and risk appetites.
Original languageAmerican English
Number of pages29
DOIs
StatePublished - 2026

NLR Publication Number

  • NLR/TP-5T00-96283

Keywords

  • coordinated vulnerability disclosure
  • EVSE
  • exploitations
  • mitigations
  • vulnerability
  • weakness

Fingerprint

Dive into the research topics of 'Blueprint: Stakeholder-Specific Vulnerability Categorization Guidance'. Together they form a unique fingerprint.

Cite this