Fixing vulnerability data quality requires fixing the architecture first
ID: f830637d-c76c-5464-b0e8-0b5f53e20e47
STIX ID: report--f830637d-c76c-5464-b0e8-0b5f53e20e47
Feed Name: Help Net Security
This interview with Art Manion examines why vulnerability records across repositories are inconsistent and hard to trust, introduces the idea of Minimum Viable Vulnerability Enumeration (MVVE) as a way to think about assertions needed to identify the same vulnerability across systems, and argues for shared terms, provenance, and architecture-focused repository design rather than new specs or metrics-driven shortcuts such as overreliance on CVSS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
