The danger of looking at risk scores without any context

0
129
Analysis of the NIST National Vulnerability Database shows that security teams were under siege in 2020 and into the first part of 2021 defending against an unprecedented number of flaws. Today’s columnist, Ed Bellis of Kenna Security, cautions that CVSS scores don’t always tell the full story. shioshvili is licensed under CC BY-SA 2.0

A growing number of companies are adopting risk-based vulnerability management programs to handle the endless wave of new vulnerabilities being disclosed every day — more than 2,800 in the first three months of 2021. Yet, too often these programs make one critical error – they focus too much time on a risk score, and not enough time on the system itself.

That’s wrong, because it obscures vital context. By missing that context, organizations can miss prioritizing and patching vulnerabilities that are truly high-risk to their organizations.

Take, for example, the Common Vulnerability Scoring System (CVSS). When a hot new vulnerability garners mass attention, analysts often quote the vulnerability’s CVSS score.

Those comments fail to recognize that the distribution of CVSS scores isn’t a tidy bell curve…

Read More…