You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CISA has developed a National Cyber Incident Scoring System. It's a numerical function, but its spec contains a number of ordered categorical lists that could be useful to include in the SSVC vocabulary.
Additional context
This could help us expand applicability of SSVC beyond pure vulnerability response and increase its ability to model vulnerability response in the face of adversarial activity as expressed in incident data.
The text was updated successfully, but these errors were encountered:
I have a work-in-progress branch that models a few of the NCISS parameters as decision points. Without more detail on the other criteria it's hard to know how to model them. The unmodeled categories include:
Functional Impact
Observed Activity
Actor Characterization
Information Impact
Cross-Sector Dependency
Potential Impact
There may be resources other than the NICSS PDF that provide more details, but I'm unaware of any at the moment.
Meanwhile, here are some screenshots of what is in the current branch.
Describe the solution you'd like
CISA has developed a National Cyber Incident Scoring System. It's a numerical function, but its spec contains a number of ordered categorical lists that could be useful to include in the SSVC vocabulary.
Additional context
This could help us expand applicability of SSVC beyond pure vulnerability response and increase its ability to model vulnerability response in the face of adversarial activity as expressed in incident data.
The text was updated successfully, but these errors were encountered: