SSVC icon indicating copy to clipboard operation
SSVC copied to clipboard

Stakeholder-Specific Vulnerability Categorization

Results 56 SSVC issues
Sort by recently updated
recently updated
newest added

Linkchecker also confirms that the site builds successfully, so any changes to the pip requirements should trigger it to run as well. This will let us detect when dependabot proposes...

**Describe the bug** On the page https://certcc.github.io/SSVC/reference/decision_points/mission_impact The reference Federal Emergency Management Agency. Federal continuity directive 2: federal executive branch mission essential functions and candidate primary mission essential functions identification...

bug
documentation

Not sure what the current preferred term is, but drawing on @sei-vsarvepalli's comment on #119: > JSON format allows for UTF-8 representation of each of "keys" and "values" in both...

enhancement
help wanted
clarification needed

**Describe the bug** It looks like there is some legacy notation of "none" for Mission Impact (v1.0.0) still in the child_trees. This option was eliminated in the Mission Impact (V2.0.0)....

bug

**Describe the bug** The license of the documentation is impractical for any use in any open source software. Could you work out something that makes it possible to reuse and...

bug

**Describe the solution you'd like** [*NIST SP 800-40 Rev. 4 Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology*](https://csrc.nist.gov/pubs/sp/800/40/r4/final) seems highly relevant to the Deployer stakeholder. We should at...

enhancement

Capturing feedback from @bkoo in #412: > I mostly echo what @ehatleback has already mentioned with an emphasis on his second point. By having the selections always visible to enable...

enhancement
ssvc-calc

Based on a comment from @j---, it's possible that a response decision could also involve an "inititate incident response". For example, if you're already behind on fixing something that's open...

enhancement

Be clear about how Industrial Control System and Operations Technology stakeholders are handled. In many cases they may use the usual SSVC v1 decision points, but with a different risk...

enhancement
help wanted
clarification needed

This issue is just to collect links to the various CVSSv4 related issues we've got open. - #523 - #455 - #441 - #394 - #393 - #392 - #329...

enhancement