<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Risk and CVSS (Post 1)</title>
	<atom:link href="http://risktical.com/2008/08/24/risk-and-cvss-post-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/</link>
	<description>Assessing, Articulating &#38; Quantifying Information Security Risk</description>
	<lastBuildDate>Mon, 31 Oct 2011 20:19:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: HyunChul</title>
		<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/#comment-435</link>
		<dc:creator><![CDATA[HyunChul]]></dc:creator>
		<pubDate>Fri, 19 Feb 2010 10:26:51 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=48#comment-435</guid>
		<description><![CDATA[By the way, a vulnerability in CVSS is defined as a software defect which can be exploited by malicious users so that it can potentially cause negative impact.]]></description>
		<content:encoded><![CDATA[<p>By the way, a vulnerability in CVSS is defined as a software defect which can be exploited by malicious users so that it can potentially cause negative impact.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HyunChul</title>
		<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/#comment-434</link>
		<dc:creator><![CDATA[HyunChul]]></dc:creator>
		<pubDate>Fri, 19 Feb 2010 10:24:02 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=48#comment-434</guid>
		<description><![CDATA[The main goal of CVSS is to standardize software related vulnerabilities mainly , so that we can make it sure that when we say vulnerability A, it is not the same one with vulnerability B among the people. 
Also, it can prioritize severity of vulnerabilities. It can help for the administrators which one should be first to be cure. Of course, as you said, it should not be panacea, but still it provides a tremendous services, especially for quantitative software risk analyzes.]]></description>
		<content:encoded><![CDATA[<p>The main goal of CVSS is to standardize software related vulnerabilities mainly , so that we can make it sure that when we say vulnerability A, it is not the same one with vulnerability B among the people.<br />
Also, it can prioritize severity of vulnerabilities. It can help for the administrators which one should be first to be cure. Of course, as you said, it should not be panacea, but still it provides a tremendous services, especially for quantitative software risk analyzes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Hayes</title>
		<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/#comment-40</link>
		<dc:creator><![CDATA[Chris Hayes]]></dc:creator>
		<pubDate>Mon, 25 Aug 2008 16:22:02 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=48#comment-40</guid>
		<description><![CDATA[Yep, PCI QSAs are using CVSS for vulnerability scoring. However, some of the vendors are not educating the PCI merchant about the portion of CVSS called the “environmental metric group” vectors which can have an impact on the overall CVSS score. As a matter of fact, the CVSS documentation implies that the environmental metrics are not something the vendor(s) can score – because they do not understand each and every organization’s environment. Granted, the environmental vectors are “optional” according to CVSS – but PCI QSAa should provide some value add and educate their clients about assigning the vulnerability in the context of their environment. For PCI gaps, one should separate risk due to the vulnerability itself vs. risk with not being compliant. 

Also, some PCI QSAs do not even perform the CVSS method themselves, they just go to the National Vulnerability Database and grab the CVSS score / vector from there. How original is that? High reuse, less work, more profit – less value-add.]]></description>
		<content:encoded><![CDATA[<p>Yep, PCI QSAs are using CVSS for vulnerability scoring. However, some of the vendors are not educating the PCI merchant about the portion of CVSS called the “environmental metric group” vectors which can have an impact on the overall CVSS score. As a matter of fact, the CVSS documentation implies that the environmental metrics are not something the vendor(s) can score – because they do not understand each and every organization’s environment. Granted, the environmental vectors are “optional” according to CVSS – but PCI QSAa should provide some value add and educate their clients about assigning the vulnerability in the context of their environment. For PCI gaps, one should separate risk due to the vulnerability itself vs. risk with not being compliant. </p>
<p>Also, some PCI QSAs do not even perform the CVSS method themselves, they just go to the National Vulnerability Database and grab the CVSS score / vector from there. How original is that? High reuse, less work, more profit – less value-add.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/#comment-39</link>
		<dc:creator><![CDATA[Ben]]></dc:creator>
		<pubDate>Mon, 25 Aug 2008 11:13:31 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=48#comment-39</guid>
		<description><![CDATA[fwiw, PCI uses CVSS for scoring criteria in patch mgmt requirements. That&#039;s when I first encountered it in my consulting, after a client started asking questions about it in order to implement a compliant patch mgmt program.]]></description>
		<content:encoded><![CDATA[<p>fwiw, PCI uses CVSS for scoring criteria in patch mgmt requirements. That&#8217;s when I first encountered it in my consulting, after a client started asking questions about it in order to implement a compliant patch mgmt program.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

