Security Teams Need to Stop Treating CVSS Scores Like a Patch Queue
Patch management sounds simple.
A vulnerability is discovered. A security advisory is published. A patch becomes available. The administrator installs it.
Problem solved.
In real-world environments, it rarely works that way.
Organizations can have thousands of systems, hundreds of applications, multiple software versions and infrastructure spread across different networks. Security teams must decide which vulnerabilities require immediate action and which can be handled during a normal maintenance cycle.
The biggest mistake is treating vulnerability severity as the same thing as real-world risk. It isn't.
A Critical Vulnerability Is Not Automatically Your Biggest Problem
Most organizations use CVSS to help prioritize vulnerabilities.
CVSS is useful because it provides a standardized way to describe technical severity. It considers factors such as attack complexity, privileges required, user interaction and the potential impact on confidentiality, integrity and availability.
But a CVSS score does not know your infrastructure.
A vulnerability with a score of 9.8...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE