Unified evidence model addressing #278, #333 and other concerns. - #980
Unified evidence model addressing #278, #333 and other concerns.#980stevespringett wants to merge 2 commits into
Conversation
Signed-off-by: Steve Springett <steve@springett.us>
|
RFC notice sent on July 20, 2026
Public RFC period ends August 17, 2026 |
Signed-off-by: Steve Springett <steve@springett.us>
|
@stevespringett - in reviewing all this, it occurs to me that we do a good job of capturing evidence of vulnerability. But to really understand a risk, it's important to understand any compensating controls. It's like evidence against vulnerability - that it doesn't exist or isn't as dangerous as it might be. Like VEX sort of. I'm wondering if we should add something in the standard to model these controls so that you can take them into account. Is this already handled somehow? Or is this somewhere else in the standard that I missed? If we dd this, we could distinguish inherent and residual ratings and allow the residual rating to reference the mitigation assertion. |
Closes #979
Closes #278
Closes #333