Jonathan Spring, Art Manion, Allen Householder
We present a testable Stakeholder-Specific Vulnerability Categorization (SSVC) that avoids some of the problems with the Common Vulnerability Scoring System (CVSS). SSVC takes the form of decision trees for different vulnerability management communities. Since there are many different stakeholders in vulnerability management, we aim to avoid one-size-fits-all solutions as much as is practical.