• SpacePirate@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    9 months ago

    Glancing through your article, while you have correctly assessed the need for risk based prioritization of vulnerability remediation and mitigation, your central premise is flawed.

    Vulnerability is not threat— CVSS is a scoring system for individual vulnerabilities, not exploit chains. For that, you’ll want to compare with ATT&CK or the legacy cyber kill chain.