Hacker News new | ask | show | jobs
by carty76ers 2447 days ago
I’ve never used it, but could you elaborate on why it’s worthless? And what alternatives do you use?
2 comments

It is a tool to have a discussion, not a solution to risk management. Security is one of the few fields that uses qualitative measurements, and any attempt of applying more quantitative techniques faces a lot of resistance.

CVSS in isolation is pretty good, but for risk management it lacks "context". A higher level framework would be needed for that.

A bug can have a CVSS score of 10 (critical), and still have little to no impact to the business. It's all about context.

I don't think it even ever intended to be more then a data point to consider for risk management but dev

It is an answer to the wrong question.
That is no more helpful in terms of the extra explanation requested than the original response...

Kind of "is it possible to be more vague here?" "yes, yes it is'.