CyberMax
Home › Glossary › Vulnerability management

What is SSVC?

Vulnerability management glossary · 1 primary source

Stakeholder-Specific Vulnerability Categorization: a decision-tree method that turns a few facts about a vulnerability into an action, such as Track, Attend or Act.

Instead of one number, SSVC asks questions with a small set of answers: is it being exploited (none, proof of concept, active), can exploitation be automated (yes, no), what is the technical impact (partial, total), and how much it matters to the mission and to public well-being. CISA's version maps the answers to four outcomes: Track, Track*, Attend and Act.

CISA's Vulnrichment programme adds exploitation, automatable and technical-impact values to many CVE records, and BOD 26-04 uses those values to set federal deadlines.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary