What is CVSS? | Common Vulnerability Scoring System

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 ก.พ. 2025
  • #security #ciso #soc #securityOperationsCenter
    • What is CVSS?
    • Version of CVSS calculators?
    • How is severity of vulnerability defined?
    • How to use CVSS calculator?
    • How CVSS helps in Vulnerability Management?

    Vulnerability Management is one of the key services which SOC has to offer. We are starting off with very basics, I mean knowing what a vulnerability is, and then slowly we transition to designing and building Security Operations Center.
    NIST Cybersecurity Framework listing Vulnerability management as one of the key service - nvlpubs.nist.g....
    Mitre CVE portal - cve.mitre.org
    NVD portal - nvd.nist.gov
    Regards,
    ConceptsWork

ความคิดเห็น • 12

  • @badkarma082
    @badkarma082 3 ปีที่แล้ว +7

    Hard to believe you don't have more views. I've seen quite a few instructional videos in my days. You are a true lecturer with some deep knowledge. One thank for many videos watched.

  • @aurelijaeinoryte6017
    @aurelijaeinoryte6017 2 ปีที่แล้ว +1

    Thanks for helping to wrap my head around the concept of CVSS. Great instructions.

  • @cyber_sal
    @cyber_sal 2 ปีที่แล้ว +1

    Great overview of CVSS - easy to follow and understand. Thank you!

  • @vickysingh2150
    @vickysingh2150 3 ปีที่แล้ว +1

    Thanks for the wonderfully informative and clearly explained video. waiting for more Cybersecurity Stuff

  • @peteallennh
    @peteallennh ปีที่แล้ว

    Very clear and helpful explanation, thank you!

  • @Tenly2009
    @Tenly2009 3 ปีที่แล้ว +1

    This video was great. Very well organized and explained - ending with a summary of what was covered! Thanks!
    I do have 1 question that wasn’t covered - and that is “Why do CVE’s still contains CVSS scoring for both v2.0 and v3.0 instead of simply displaying the newer v3.0 score…?”

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว +1

      it all depends how the enumeration process works for a specific security product.
      There are three different authority who are involved here, application vendor, security solution provider and the governing authority listing CVE. Since once the CVE is published, there is no ground work done to go back and revise the score.
      So, to make sure everything stays connected, still the score is been derived from both the models.

  • @shaktisingh8788
    @shaktisingh8788 2 ปีที่แล้ว +1

    I am very much liking your content and the presentation you provide , very well organized and full of knowledge . I am looking for a carrier in Vulnerability Management , could you please guide and help me with the right approach . Thanks !

    • @ConceptsWork
      @ConceptsWork  2 ปีที่แล้ว

      I would suggest to start with understanding different frameworks and then move gradually to advanced workloads.

  • @amanjha2289
    @amanjha2289 11 หลายเดือนก่อน

    can we continue this🥺 series please

  • @lewaplay
    @lewaplay 2 ปีที่แล้ว

    Soo.. how to use it? Any irl example?