Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Model National Cyber Incident Scoring System (NCISS) #705

Open
ahouseholder opened this issue Feb 20, 2025 · 2 comments · May be fixed by #707
Open

Model National Cyber Incident Scoring System (NCISS) #705

ahouseholder opened this issue Feb 20, 2025 · 2 comments · May be fixed by #707
Assignees
Labels
enhancement New feature or request
Milestone

Comments

@ahouseholder
Copy link
Contributor

ahouseholder commented Feb 20, 2025

Describe the solution you'd like

CISA has developed a National Cyber Incident Scoring System. It's a numerical function, but its spec contains a number of ordered categorical lists that could be useful to include in the SSVC vocabulary.

Additional context

This could help us expand applicability of SSVC beyond pure vulnerability response and increase its ability to model vulnerability response in the face of adversarial activity as expressed in incident data.

@ahouseholder ahouseholder added the enhancement New feature or request label Feb 20, 2025
@ahouseholder
Copy link
Contributor Author

I have a work-in-progress branch that models a few of the NCISS parameters as decision points. Without more detail on the other criteria it's hard to know how to model them. The unmodeled categories include:

  • Functional Impact
  • Observed Activity
  • Actor Characterization
  • Information Impact
  • Cross-Sector Dependency
  • Potential Impact

There may be resources other than the NICSS PDF that provide more details, but I'm unaware of any at the moment.

Meanwhile, here are some screenshots of what is in the current branch.

menu screenshot incident severity observed location recoverability

@ahouseholder ahouseholder self-assigned this Feb 20, 2025
@ahouseholder ahouseholder added this to the 2025-03 milestone Feb 20, 2025
@ahouseholder ahouseholder changed the title Model National Cybersecurity Incident Scoring System Model National Cyber Incident Scoring System (NCISS) Feb 20, 2025
@ahouseholder ahouseholder linked a pull request Feb 20, 2025 that will close this issue
@ahouseholder
Copy link
Contributor Author

Additional references:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant