Chapter 6
SCAP Vulnerability Measurement
At the time of this writing, nearly 50,000 vulnerabilities are listed in the National Vulnerability Database; each has some impact on a given set of systems but none affects all systems within a security manager’s purview. Security practitioners often need to determine the priority of addressing a given vulnerability as part of an overall vulnerability management process, such as determining the urgency of applying a workaround to mitigate risk of a vulnerability’s exploitation. The ability to categorize vulnerabilities based upon their potential impact on an information system’s confidentiality, integrity, ...