RHACS and EPSS

Updated

What is EPSS?

The Content from www.first.org is not included.EPSS website states:

The Exploit Prediction Scoring System (EPSS) is a data-driven effort for estimating the likelihood (probability) that a software vulnerability will be exploited in the wild. Our goal is to assist network defenders to better prioritize vulnerability remediation efforts. While other industry standards have been useful for capturing innate characteristics of a vulnerability and provide measures of severity, they are limited in their ability to assess threat. EPSS fills that gap because it uses current threat information from CVE and real-world exploit data. The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

Should I be concerned about my EPSS score?

The EPSS is a data-driven effort, by First organization, for estimating the likelihood (probability) that a software vulnerability will be exploited in the wild. RHACS provides EPSS produced scores as an additional data point to assist with better prioritization of vulnerability remediation efforts.

It is up to each organization's discretion whether to take this data into account for prioritizing vulnerability remediation efforts.

What other considerations should I factor in when looking at my EPSS score?

If you are new to the EPSS probability scores, we encourage you to review the documentation by First:

What if I don't see the EPSS column?

Scanner v4 is a prerequisite for EPSS. If you do not have Scanner V4, you will not see the column.

Category
Components
Article Type