Software Engineering Institute (SEI) Podcast Series

A Stakeholder-Specific Approach to Vulnerability Management

10.27.2020 - By Members of Technical Staff at the Software Engineering InstitutePlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

Many organizations use the Common Vulnerability Scoring System (CVSS) to prioritize actions during vulnerability management. This podcast—which highlights the latest work in prioritizing actions during vulnerability management—presents a testable Stakeholder-Specific Vulnerability Categorization (SSVC) that avoids some problems with CVSS. SSVC takes the form of decision trees for different vulnerability management communities. During this podcast, CERT vulnerability researchers Eric Hatleback, Allen Householder, and Jonathan Spring discuss SSVC and also take audience members through a sample scoring vulnerability.

More episodes from Software Engineering Institute (SEI) Podcast Series