Skip to content

Severity computation #73

Answered by 0x6d69636b
ataumo asked this question in Q&A
Sep 29, 2021 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Level 1 and 2 are specifications from CIS, I have simply adopted them. Therefore, I will not make any adjustments or add more levels there.

The severity levels are my personal assessments if the framework does not give any guidelines. In the case of NIST/STIG, they have defined severity levels themselves. Basically, I use CVSS as a guideline, but this is not quite as easy to convert for configuration reviews. Since a missing configuration setting does not directly represent a vulnerability.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ataumo
Comment options

Answer selected by ataumo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
2 participants