RiskBasedPrioritization / RiskBasedPrioritization.github.io

https://riskbasedprioritization.github.io/
Creative Commons Attribution Share Alike 4.0 International
8 stars 6 forks source link

MaorK: Add Abbreviations and Definitions #4

Closed Crashedmind closed 8 months ago

Crashedmind commented 8 months ago

Description, Use Case and User Stories A list of abbreviations that are relevant to Risk Based Prioritization Guide in one file. A list of definitions in a separate file

Definition of Ready

  1. The details on what's required for definitions and abbreviations are defined.

Acceptance Criteria

  1. The abbreviations are in a text file called abbreviations.md - current file content below.
  2. The definintions are in a table in a document/sheet. These will be converted to a markdown table. This does not exist yet.
  3. The definitions should follow NIST definitions where possible with a link to the nist page https://csrc.nist.gov/glossary

Additional context The abbreviations are in a specific format - because this allows all abbreviations in the guide to automatically have a hover over for the details.

The existing abbreviations.md file content is

*[CWE]: CWE Common Weakness Enumeration
*[CVE]: CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.
*[KEV]: Known Exploited Vulnerability
*[NVD]: National Vulnerability Database
*[SSVC]: SSVC Stakeholder-Specific Vulnerability Categorization
*[EPSS]: Exploit Prediction Scoring System
*[CVSS]: Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.
*[CISA]: Cybersecurity & Infrastructure Security Agency
*[NVD]: National Vulnerability Database
Crashedmind commented 8 months ago

Added as https://riskbasedprioritization.github.io/annex/Glossary/

https://github.com/RiskBasedPrioritization/RiskBasedPrioritization.github.io/commit/b4b97edfd9dc88964e16c45564f7f2b44a2f5ec9