CVSS is an important tool for vulnerability management, which is the continuous discovery, prioritization and resolution of security vulnerabilities in an organization’s IT infrastructure and software. Identifying and resolving errors and cybersecurity weaknesses, such as firewall misconfigurations and unpatched bugs, is critical to ensuring the full functionality of IT infrastructure and software.
Resolution measures can include:
- Remediation: ensuring a vulnerability can no longer be exploited.
- Mitigation: making a vulnerability more difficult to exploit while reducing the potential impact of its exploitation.
- Acceptance: leaving a vulnerability in place if it’s unlikely to be exploited or would cause little damage.
Given the complexity of today’s IT systems and their large volume of vulnerabilities and cyberthreats, determining which issues to address and resolve first can be challenging for IT managers.
That’s where CVSS proves valuable: It provides IT managers with a systematic approach to assessing the severity of a vulnerability, helping inform their decisions on prioritizing and planning vulnerability resolutions for affected systems.1
CVSS scores can be incorporated into risk assessments, but a CVSS assessment on its own should not be used in place of a comprehensive risk assessment, according to FIRST.org. CVSS user guides advise that comprehensive assessments should include factors outside the scope of CVSS.2