CERTCC / SSVC

Stakeholder-Specific Vulnerability Categorization
https://certcc.github.io/SSVC/
Other
119 stars 33 forks source link

FIRST services framework #314

Open j--- opened 9 months ago

j--- commented 9 months ago

Service area 3 is about vulnerability triage for PSIRTs https://www.first.org/standards/frameworks/psirts/psirt_services_framework_v1.1

Service area 7.2.2 is about CSIRT vulnerability triage https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1#7-2-Service-Vulnerability-report-intake

SSVC may be in a position to be providing additional detail about these areas. I don't think we're overlapping, but if we are in fact providing additional detail to things listed in the PSIRT and CSIRT services frameworks, we should reach out to FIRST to coordinate and see if they agree and want to link to SSVC documentation for additional detail.

ahouseholder commented 9 months ago

Need to digest the services frameworks in more detail, but I could imagine one way to represent this could be to do a cross-walk table similar to what we did with Vultron and various vulnerability disclosure ISO docs:

j--- commented 9 months ago

Something like this, yes. In this case, I think we also have the opportunity to chat with the FIRST framework authors and get their feedback after we draft it.