<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Risk and CVSS (Post 2)</title>
	<atom:link href="http://risktical.com/2008/09/01/risk-and-cvss-post-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://risktical.com/2008/09/01/risk-and-cvss-post-2/</link>
	<description>Assessing, Articulating &#38; Quantifying Information Security Risk</description>
	<lastBuildDate>Fri, 04 Jun 2010 19:07:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Walt Williams</title>
		<link>http://risktical.com/2008/09/01/risk-and-cvss-post-2/#comment-67</link>
		<dc:creator>Walt Williams</dc:creator>
		<pubDate>Tue, 09 Sep 2008 12:14:32 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=58#comment-67</guid>
		<description>This is all for the good in determining a company neutral evaluation of the relative risk for CVSS issues, but any evaluation must be placed within the context of the system you&#039;re protecting.  XSS may be a larger issue for company X than for company Y based upon their business model.

On a similar basis, SQL injection may be a smaller issue for company Y than for company X due to a lack of use of SQL databases under their web application.

However the CVSS scoring will flag SQL Injection issues as more critical than XSS for both companies.

Creating relative risk metrics from CVSS scoring won&#039;t reflect the business model, the assets present, nor the real impact to the organization.  As such, any effort to assign risk from CVSS scoring is doomed to be an inadequate model for analyzing risk.</description>
		<content:encoded><![CDATA[<p>This is all for the good in determining a company neutral evaluation of the relative risk for CVSS issues, but any evaluation must be placed within the context of the system you&#8217;re protecting.  XSS may be a larger issue for company X than for company Y based upon their business model.</p>
<p>On a similar basis, SQL injection may be a smaller issue for company Y than for company X due to a lack of use of SQL databases under their web application.</p>
<p>However the CVSS scoring will flag SQL Injection issues as more critical than XSS for both companies.</p>
<p>Creating relative risk metrics from CVSS scoring won&#8217;t reflect the business model, the assets present, nor the real impact to the organization.  As such, any effort to assign risk from CVSS scoring is doomed to be an inadequate model for analyzing risk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Risk and CVSS &#124; RiskAnalys.is</title>
		<link>http://risktical.com/2008/09/01/risk-and-cvss-post-2/#comment-53</link>
		<dc:creator>Risk and CVSS &#124; RiskAnalys.is</dc:creator>
		<pubDate>Tue, 02 Sep 2008 17:33:34 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=58#comment-53</guid>
		<description>[...] Hayes is taking me to town in terms of risk content with his last two posts on Risk &amp; CVSS.  I told you his blog was going to be a good [...]</description>
		<content:encoded><![CDATA[<p>[...] Hayes is taking me to town in terms of risk content with his last two posts on Risk &amp; CVSS.  I told you his blog was going to be a good [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
