center-for-threat-informed-defense / security-stack-mappings

🚨ATTENTION🚨 The Security Stack Mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept here as an archive.
https://center-for-threat-informed-defense.github.io/mappings-explorer/
Apache License 2.0
379 stars 64 forks source link

Scoring and metrics of mitigation measures #144

Open FreddyDezeure opened 3 years ago

FreddyDezeure commented 3 years ago

It would be helpful if the (very useful) inventory of mitigation measures would be scored in a quantitative way, in addition to the qualitative assessment (minimal, partial, significant). It would allow users to covert coverage and effectiveness into numeric dashboards/metrics. Ideally the way this is implemented would allow users to configure weights for the three qualitative levels.