Live Online Classes in Design, Coding & AI — Small Classes, Free Retakes
Master Production-Ready Machine Learning, Step by Step
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Learn how to use industry-standard vulnerability scoring methodologies and frameworks to prioritize vulnerabilities for remediation.
Syllabus
Vulnerability Basics
- Vulnerability risk assessment
- Vulnerability types and their causes
- Methods for addressing vulnerabilities
- Intro to determining severity with CVSS
- Making sense of the CVSS Vector String
- Attack method or vector when determining severity
- How attack complexity impacts severity
- How access or privileges required affects severity
- How user interaction affects severity
- Security Scope in CVSS v 3.1
- How impacts affect severity
- Severity and risk are not the same
- Challenges with CVSS and severity scores
- Vendor-specific severity scoring methodologies
- Other vulnerability scoring methodologies: KEV and EPSS
- Solution: Comparing vulnerabilty severity scores
- Why severity scores alone aren't enough
- Risk assessment basics
- Exploit availability
- Asset categorization
- Combining severity and risk to drive action
- Solution: Prioritize vulnerabilities for remediation
- Intro to SSVC
- SSVC: Exploitation
- SSVC: Automatable
- SSVC: Technical impact
- SSVC: Mission prevalence and public well-being
- Using SSVC
- Solution: Using SSVC to prioritize vulnerabilities
- Core components to a program
- Detect vulnerabilities
- Assess the risk
- Assign vulnerablities for remediation
- Remediate and confirm vulnerabilities
- Outliers: Handling celebrity vulnerabilities
- Just the beginning
Taught by
Lora Vaughn