« The Clintons do the Sopranos | Main | Tim Greene finds out - when it comes to NAC - who is the boss »

June 20, 2007

CVSS version 2 released

If you are involved in vulnerability management you are probably aware that back in 2005 the Common Vulnerability Scoring System (CVSS) came out to replace a hodge podge of vulnerability severity scoring systems.  This was a big improvement over the minor-major-critical scale that was used before. Now according to this article on Security Focus, the Forum of Incident Response and Security Teams (FIRST) have come out with their long in progress version 2 of the CVSS.  You can read the full history and definitions here.

I see no reason why version 2 of the CVSS will not be as widely adopted as the first, so you should familiarize yourself with the changes in the new version sooner than later.  The National Vulnerability Database which has already assigned CVSS rankings to over 25k vulnerabilities has stepped up and lent its support to version 2 by the way.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/547509/19460724

Listed below are links to weblogs that reference CVSS version 2 released:

» CVSS v2 Official from .:Computer Defense:.
Anyone whos worked with CVSS knows that it has some serious flaws Today we can change that statement to had some serious flaws, at least until we find problems with CVSS v2 which was announced today (via SSAATY). The incorporated changes ... [Read More]

Comments

Search

Lijit Search

disclaimer

  • The views and opinions expresed here are those of myself only and in no way represent the views or positions or opinions of my employer, Latis Networks, Inc. d/b/a StillSecure or anyone else.

Forbes.com

StillSecure, After all these years, the podcast

  • Podlogo

Currently Reading

  • Conn Iggulden: Genghis: Birth of an Empire

    Conn Iggulden: Genghis: Birth of an Empire
    I have always been drawn to stories of Genghis Khan. How was he able to take a primitive people and conquer most of the world? What did the Mongol culture have that enabled this. This is the first of a trilogy on the life of the great Khan. It is great, easy reading and gives a great picture into the life and times of GK. (****)

Read Recently

Blog powered by TypePad
Member since 10/2005