Standard method of rating security vulnerabilities
Standard method of rating security vulnerabilities
R E L A T E D   C O N T E N T
ADVERTISEMENT

Flaw ratings take pain out of patching

Common Vulnerability Scoring System allows IT managers to prioritise patches

Steve Ranger, vnunet.com 24 Feb 2005
ADVERTISEMENT

A group of IT companies has developed a standard way to rate security vulnerabilities, in a bid to give systems administrators a better way of prioritising software patches.

The Common Vulnerability Scoring System (CVSS) was designed by engineers from companies including Microsoft and Cisco.

CVSS uses a series of measurements to rate the severity of a flaw, according to a report in New Scientist.

System administrators currently have to decide which of the dozens of alerts and patches are the most important as different vendors have their own scoring systems.

The CVSS assessment judges a vulnerability according to characteristics such as whether it gives hackers access to confidential information, or allows them to modify or destroy data.

The assessment also takes into account the age of the flaw, rating older flaws as more serious as hackers are more likely to have developed a way to exploit the vulnerabilities.

See also:

Vulnerabilities could allow attackers to take complete controlUsers urged to update systems immediately  13 Apr 2005
Eight new security updates'Critical' Windows flaws fixed in monthly upgrade  11 Apr 2005
Do firms want to patch in their own time?  17 Feb 2005
Patches cover several 'critical' flawsVulnerabilities could allow hackers to take full control  09 Feb 2005

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities