Finding severity measures the amount of risk that a given security finding introduces. Refer to the Asset Risk Matrix for details on the following measurement criteria:
- The finding severities of Compromised Systems and User Behavior findings depends on the risk vector.
- The finding severities of Diligence findings (except Critical Vulnerabilities Management) depends on their finding grades.
- Critical Vulnerabilities Management (CVM) finding severity is based on the vulnerability’s Bitsight severity.
Features
Finding severity is leveraged in the following features:
- May 31, 2024: Published.
Comments
Please sign in to leave a comment.