Hi Vijay,
Thanks for raising this. CVSS and CISA-SSVC do answer different questions - "how bad is it" vs "what do I do about it" - and exchanging that second one in a machine-readable way is worth a look.
A few things to consider before treating it as a SCAP metric:
- Where does the decision belong? A CISA-SSVC outcome is tied to a stakeholder and a moment in time, while a CVSS base vector on a CVE is more general but carries no context. As an aside, getting to a final CISA-SSVC outcome requires answering the "Mission Prevalence" input for each affected asset.
- Which SSVC? SSVC has multiple possible instantiations, the most well-known likely being CISA-SSVC.
- How do we reuse? If it does move forward, prefer starting from SSVC's existing models and schemas rather than rebuilding them.
We put CVSS, SSVC, and EPSS side by side on a severity panel at our recent CPE workshop (Jono Spring covered SSVC), so there's some shared ground here already. Glad to join the requirements and interoperability discussion, and I'll look at the GitHub issue.
Thanks,
//Dragos.
Best regards,
Dragos Prisaca
Computer Scientist | NIST Technical Lead, CPE specifications
National Institute of Standards and Technology
From: Vijay S Sarvepalli <vssarv...@cert.org>
Sent: Thursday, July 16, 2026 3:58 PM
To: SCAP-DEV <scap...@list.nist.gov>; SCAP <sc...@nist.gov>
Subject: [EXTERNAL] SCAP support for SSVC metrics in vulnerability reporting and management
|
Some people who received this message don't often get email from vssarv...@cert.org. Learn why this is important |
2. Which SSVC? SSVC has multiple possible instantiations, the most well-known likely being CISA-SSVC.
3. How do we reuse? If it does move forward, prefer starting from SSVC's existing models and schemas rather than rebuilding them.
|
Warning: External Sender - do not click links or open attachments unless you recognize the sender and know the content is safe.
|
Hi Vijay,
Thanks for the detailed follow-up - the BOD 26-04 framing and the schema links are helpful.
A good part of our team is out over the next couple of weeks, so rather than give you a rushed answer I'd like to wait until everyone's back before we respond properly. Figure early August.
Appreciate your patience.
Thanks,
//Dragos.
Best regards,
Dragos Prisaca
Computer Scientist | NIST Technical Lead, CPE specifications
National Institute of Standards and Technology
From: Vijay S Sarvepalli <vssarv...@cert.org>
Sent: Monday, July 20, 2026 3:59 PM
To: Prisaca, Dragos (Fed) <dragos....@nist.gov>; SCAP-DEV <scap...@list.nist.gov>; SCAP <sc...@nist.gov>
Subject: Re: [EXTERNAL] SCAP support for SSVC metrics in vulnerability reporting and management
|
You don't often get email from vssarv...@cert.org. Learn why this is important |