Replies: 26 comments 4 replies
|
Post from Nucleus Security research lead: |
|
Fortinet's FortiSOAR (Managed SOC Services) also had a linked in post mentioning use of SSVC, but details are still being tracked down from Amit Jain https://www.linkedin.com/posts/amitjainixd_fortisoar-cisa-nvd-activity-7079009317193998336-9N-d?utm_source=share&utm_medium=member_desktop |
|
Qualys - https://blog.qualys.com/product-tech/2022/11/30/effective-vulnerability-management-with-ssvc-and-qualys-trurisk Just dumping from my notes before I loose these. |
|
Should we be capturing these in a page in the |
|
|
2024-02-14 Applying Vulnerability Intelligence to CVSS and SSVC Frameworks https://www.youtube.com/watch?v=Gn1t7ljdSH0 2024-02-15 No More Business As Usual: Vulnerability Management Focused On Managing Risk https://www.spiceworks.com/it-security/vulnerability-management/guest-article/best-vulnerability-management-practices/ 2024-02-24 5 Things to Consider Before Using SSVC Vulnerability Prioritization Framework https://nucleussec.com/blog/5-things-to-consider-before-using-ssvc-to-automate-vulnerability-prioritization/ |
|
2024-02-15 The SSVC risk prioritization method: what it is, when to use it, and alternatives https://vulcan.io/blog/the-ssvc-risk-prioritization-method-what-it-is-when-to-use-it-and-alternatives/ |
|
11-16-2022 Using ssvc decision trees intelligence-led vulnerability management https://nucleussec.com/blog/ssvc-decision-trees-intelligence-led-vulnerability-management |
|
Yotam Perkal talk on SSVC |
|
2024-03: Risk Based Prioritization https://riskbasedprioritization.github.io/ uses a customized SSVC derived from CISA's implementation that incorporates threat feeds and other operational data in improving vulnerability response decisions. |
|
2024-05-09: CISA Vulnrichment adds SSVC decision point info from CISA analysts to CVE data as an ADP provider. On github: Media coverage: |
|
Chris Hughes; Nikki Robinson, "Vulnerability Scoring and Software Identification," in Effective Vulnerability Management: Managing Risk in the Vulnerable Digital Ecosystem , Wiley, 2024, pp.79-114, doi: 10.1002/9781394277155.ch5. keywords: {Measurement;Organizations;Vectors;Software;NIST;Databases;Industries},
|
|
A paper was presented at the 41st Symposium on Cryptography and Information Security (SCIS2024) in Nagasaki earlier this year: (Translated from Japanese by Google Translate)
Although the slides & paper have been shared with us, I don't currently have a link to a public version of them to share. We're in touch with the research team to see about integrating their suggestions though, keep an eye on new issues for further developments on that front. |
|
Looks like FutureVuls, Japanese tool, implements some support for SSVC:
|
|
BitSight on SSVC real world data analysis from CISA's vulnrichment information. https://www.bitsight.com/blog/do-we-need-yet-another-vulnerability-scoring-system-ssvc-thats-yass |
|
|
Not a media report, but SSVC support is under consideration in OASIS CSAF https://groups.oasis-open.org/discussion/motion-for-803#bm87c96b9f-de9e-4b75-9a60-25f534cfbbda |
|
NTT Japan |
|
Prioritizing patching: A deep dive into frameworks and tools – Part 2: Alternative frameworks In the second of a two-part series on tools and frameworks designed to help with remediation prioritization, we explore some alternatives to CVSS Written by Matt Wixey |
|
Turning Data into Decisions: How CVE Management Is Changing Unlocking Vulnrichment: Enriching CVE Data |
|
Apparently a Waterfall ICS Podcast with our good friend Thomas Schmidt at BSI (Germany) in March 2023 https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/stakeholder-specific-vulnerability-categorization-ssvc-episode-102/ |
|
https://pure.tue.nl/ws/portalfiles/portal/305655112/Tommasini_M.pdf
builds a very SSVC-looking decision tree:
|
|
Been forgetting to add VulnCheck people |
|
More bloggings arrive https://stephenshaffer.medium.com/flipping-the-vulnerability-management-model-cvss-ssvc-aaa78f1426e1 |
|
Note For future reference, rather than replying to this thread, please post new links as their own post in the Sightings category: |

Uh oh!
There was an error while loading. Please reload this page.
Good work from Yahoo using SSVC:
https://github.com/theparanoids/PrioritizedRiskRemediation
The Risk Remediation Taxonomy and Decision Tree are part of a conference presentation by Yahoo Chris Madden: https://www.bsidesdub.ie/ May 27 2023.
See the slide deck and the recording.
All reactions