Skip to content
Notifications
Clear all

Complete newbie here - where should I start with a policy setup?

19 Posts
19 Users
0 Reactions
23 Views
(@cipher_blue)
Honorable Member
Joined: 6 months ago
Posts: 506
 

Defining your own severity matrix is solid in theory, but it assumes the vendor's findings are actually mappable. I've seen scanners where the "critical" tag is just marketing fluff for a library version two patches behind, with no PoC in the wild. You can map it to your "low" all day, but you're still wasting cycles categorizing nonsense.

The real test is whether their scoring methodology is even audit-able. Can you see the exploitability data they used? If not, you're just building a translation layer for their opaque, and often lazy, threat model.



   
ReplyQuote
(@derekf)
Reputable Member
Joined: 2 months ago
Posts: 285
 

You've hit on the core issue: mapping requires a transparent source. I audited a vendor's "critical" CVE scoring last quarter and found they were using CVSS v3 Base Scores exclusively, ignoring Temporal metrics that had downgraded half of them due to known workarounds. Their API didn't expose the vector string.

This creates a meta-problem. You're not just translating their "critical" to your "low." You're forced to maintain an external database to re-score their findings against actual exploitability data (like EPSS scores or CISA KEV) before any mapping can even begin. The overhead defeats the purpose of buying a managed service.

The vendor's threat model isn't just lazy, it's often structurally incapable of incorporating runtime or environmental context. If their methodology isn't auditable, your internal matrix is built on shifting sand.


No free lunch in cloud.


   
ReplyQuote
(@gracew23)
Reputable Member
Joined: 2 months ago
Posts: 281
 

If they're ignoring Temporal scores, they're probably ignoring Environmental scores too. So your asset metadata is useless to them anyway.

That's the real vendor lock in. You can't feed them better data to improve their scoring. You have to redo their work externally.


Trust, but audit.


   
ReplyQuote
(@infra_architect_rebel_alt)
Honorable Member
Joined: 5 months ago
Posts: 487
 

Exactly, and that's why you sometimes have to abandon their scoring altogether. I've seen teams build that external re-scoring layer, only to realize they're now maintaining a full vulnerability database themselves. At that point, the "managed" tool is just a fancy data collector.

The cheaper path is often to treat their "critical" as a raw data feed and pipe it into your own rules engine that *does* understand your environmental context. Use it as a dumb scanner, not a smart advisor. It's less work than trying to fix their model.


keep it simple


   
ReplyQuote
Page 2 / 2