Skip to content

theparanoids/PrioritizedRiskRemediation

Repository files navigation

Risk-Based Prioritization of CVEs

A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).

Background

A Risk Remediation Taxonomy is defined here to support Risk Based Prioritization of CVEs:

  • the constituent components of risk and remediation for a CVE
  • the associated data sources for these components

A Risk-based Decision Tree is defined with

  • inputs for the Decision Tree Decision Nodes
  • output Decisions

The Risk Remediation Taxonomy and Decision Tree are part of a conference presentation by Yahoo Chris Madden: https://www.bsidesdub.ie/ May 27 2023.

Risk Remediation

A tree with the constituent components of Risk and Remediation for a CVE - Top Level

RiskRemediationTop

Diagram Source: RiskRemediation_top.puml

A tree with the constituent components of Risk and Remediation for a CVE - and associated data sources

RiskRemediation

Diagram Source: RiskRemediation.puml

Risk-based Decision Tree Decision Node Inputs

The inputs for the Decision Tree Decision Nodes - and associated data sources from Risk Remediation Taxonomy.

RiskRemediationTop

Diagram Source: DT_decisions.puml

Risk-based Decision Tree Decisions

The Decision Tree with output Decisions

RiskRemediationTop

Diagram Source: DT_Full.puml.

Contribute

Please refer to the Contributing.md file for information about how to get involved. We welcome issues, questions, and pull requests.

Plantuml

The diagram(s) are written in the wonderful Plantuml.

License

This project is licensed under the terms of the Apache 2.0 open source license. Please refer to LICENSE for the full terms.

About

A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).

Resources

License

Code of conduct

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published