Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

CISA Releases Decision Tree Model to Help Companies Prioritize Vulnerability Patching

The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday announced the release of a Stakeholder-Specific Vulnerability Categorization (SSVC) guide that can help organizations prioritize vulnerability patching using a decision tree model.

The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday announced the release of a Stakeholder-Specific Vulnerability Categorization (SSVC) guide that can help organizations prioritize vulnerability patching using a decision tree model.

The SSVC system was created in 2019 by CISA and Carnegie Mellon University’s Software Engineering Institute (SEI), and a year later CISA developed its own customized SSVC decision tree for security flaws relevant to government and critical infrastructure organizations.

CISA is now encouraging organizations of all sizes to use its version of the SSVC for vulnerability management.

The SSVC provides a customized decision tree model that assists companies in prioritizing vulnerability response. CISA’s SSVC helps organizations categorize each vulnerability into one of four categories:

  • Track – does not require any action at this time and should be patched within standard update timelines,
  • Track* – may require closer monitoring for changes and should be patched within standard update timelines,
  • Attend – requires attention from internal supervisory-level individuals and should be addressed sooner than standard update timelines,
  • Act – requires attention from supervisory- and leadership-level people and should be addressed as soon as possible.

The SSVC tree helps users make a decision based on a vulnerability’s exploitation status, technical impact, whether it is automatable, impact on mission-essential functions, and the potential impact of system compromise on humans.

SSVC decision tree

CISA recommends using the SSVC in conjunction with its Known Exploited Vulnerabilities (KEV) catalog, Common Security Advisory Framework (CSAF) machine-readable security advisories, and the Vulnerability Exploitability eXchange (VEX).

[ READ: CISA’s ‘Must Patch’ List Puts Spotlight on Vulnerability Management Processes ]

“Everyone in the industry understands at this point that we can’t just blindly use CVSS scores to prioritize vulnerabilities,” commented Derek McCarthy, director, field engineering at NetRise. “Context matters (a lot), and SSVC has done incredible work enumerating all the factors that should be involved in determining how to deal with vulnerabilities in any given setting. CISA’s work in extending that should prove to be valuable in boiling up some of the more pertinent details to allow organizations to more easily digest and implement vulnerability management policies and procedures that reflect the goals of the SSVC framework.”

Related: CISA Says ‘PwnKit’ Linux Vulnerability Exploited in Attacks

Advertisement. Scroll to continue reading.

Related: CISA Clarifies Criteria for Adding Vulnerabilities to ‘Must Patch’ List

Related: CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join SecurityWeek and Hitachi Vantara for this this webinar to gain valuable insights and actionable steps to enhance your organization's data security and resilience.

Register

Event: ICS Cybersecurity Conference

The leading industrial cybersecurity conference for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Register

People on the Move

Jared Bartel has been named CISO at Idaho State University.

Automated phishing protection and scam prevention company Bolster has appointed Rod Schultz as CEO.

Bugcrowd has appointed Trey Ford as CISO for the Americas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.