Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

CISA Releases Decision Tree Model to Help Companies Prioritize Vulnerability Patching

The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday announced the release of a Stakeholder-Specific Vulnerability Categorization (SSVC) guide that can help organizations prioritize vulnerability patching using a decision tree model.

The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday announced the release of a Stakeholder-Specific Vulnerability Categorization (SSVC) guide that can help organizations prioritize vulnerability patching using a decision tree model.

The SSVC system was created in 2019 by CISA and Carnegie Mellon University’s Software Engineering Institute (SEI), and a year later CISA developed its own customized SSVC decision tree for security flaws relevant to government and critical infrastructure organizations.

CISA is now encouraging organizations of all sizes to use its version of the SSVC for vulnerability management.

The SSVC provides a customized decision tree model that assists companies in prioritizing vulnerability response. CISA’s SSVC helps organizations categorize each vulnerability into one of four categories:

  • Track – does not require any action at this time and should be patched within standard update timelines,
  • Track* – may require closer monitoring for changes and should be patched within standard update timelines,
  • Attend – requires attention from internal supervisory-level individuals and should be addressed sooner than standard update timelines,
  • Act – requires attention from supervisory- and leadership-level people and should be addressed as soon as possible.

The SSVC tree helps users make a decision based on a vulnerability’s exploitation status, technical impact, whether it is automatable, impact on mission-essential functions, and the potential impact of system compromise on humans.

SSVC decision tree

CISA recommends using the SSVC in conjunction with its Known Exploited Vulnerabilities (KEV) catalog, Common Security Advisory Framework (CSAF) machine-readable security advisories, and the Vulnerability Exploitability eXchange (VEX).

[ READ: CISA’s ‘Must Patch’ List Puts Spotlight on Vulnerability Management Processes ]

“Everyone in the industry understands at this point that we can’t just blindly use CVSS scores to prioritize vulnerabilities,” commented Derek McCarthy, director, field engineering at NetRise. “Context matters (a lot), and SSVC has done incredible work enumerating all the factors that should be involved in determining how to deal with vulnerabilities in any given setting. CISA’s work in extending that should prove to be valuable in boiling up some of the more pertinent details to allow organizations to more easily digest and implement vulnerability management policies and procedures that reflect the goals of the SSVC framework.”

Related: CISA Says ‘PwnKit’ Linux Vulnerability Exploited in Attacks

Related: CISA Clarifies Criteria for Adding Vulnerabilities to ‘Must Patch’ List

Related: CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

Management & Strategy

Industry professionals comment on the recent disruption of the Hive ransomware operation and its hacking by law enforcement.

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.

IoT Security

Lexmark warns of a remote code execution (RCE) vulnerability impacting over 120 printer models, for which PoC code has been published.

Management & Strategy

Tens of cybersecurity companies have announced cutting staff over the past year, in some cases significant portions of their global workforce.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Email Security

Microsoft is urging customers to install the latest Exchange Server updates and harden their environments to prevent malicious attacks.