CVSS Scores Are Dead. Let’s Explore 4 Alternatives
Description:
Explore the limitations of CVSS scores and discover alternative risk-based approaches to vulnerability scoring in this 40-minute conference talk from RSA Conference. Delve into the benefits of incorporating factors such as exploit availability, patch status, and deployment scale when assessing vulnerabilities. Learn about four alternative scoring systems, including EPSS, SSVC, and VPR, as Allan Liska, Principal Consultant at Recorded Future, examines their pros and cons. Gain insights into more comprehensive vulnerability assessment methods that go beyond the traditional CVSS framework.
CVSS Scores Are Dead - Let’s Explore 4 Alternatives