EPISODE · Oct 27, 2020 · 37 MIN
A Stakeholder-Specific Approach to Vulnerability Management
from Software Engineering Institute (SEI) Podcast Series · host Dr. Jonathan Spring, Eric Hatleback, Allen Householder
Many organizations use the Common Vulnerability Scoring System (CVSS) to prioritize actions during vulnerability management. This podcast—which highlights the latest work in prioritizing actions during vulnerability management—presents a testable Stakeholder-Specific Vulnerability Categorization (SSVC) that avoids some problems with CVSS. SSVC takes the form of decision trees for different vulnerability management communities. During this podcast, CERT vulnerability researchers Eric Hatleback, Allen Householder, and Jonathan Spring discuss SSVC and also take audience members through a sample scoring vulnerability.
NOW PLAYING
A Stakeholder-Specific Approach to Vulnerability Management
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Jan 2, 2026 ·47m
Dec 21, 2025 ·46m