Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TVM-07 measure either the number of authenticated scans (where authentication is successful) or the number of deployed agents reporting vulnerabilities to the number of scanned hosts #74

Open
pritikin opened this issue Oct 12, 2022 · 1 comment

Comments

@pritikin
Copy link
Collaborator

This is a proposed effectiveness metric from Walt Williams

TVM-07-M1
To test for effectiveness, measure either the number of authenticated scans (where authentication is successful) or the number of deployed agents reporting vulnerabilities to the number of scanned hosts. If the number of authenticated scans does not match the asset count, or the number of agents doesn't match the asset count, this control is not effective.

@mosi-k-platt
Copy link
Collaborator

I don't think it's useful to update the metric to focus on authenticated scans or agents, but I do think the implementation guidelines for this metric could be updated to state reporters should specify what type of scans provide the numerator in the existing TVM-07-M1 metric.

This is a coverage metric not an effectiveness metric. I think an effectiveness metric for vulnerability detection would measure an org's mean time to discover vulns against some target - like the mean time to discover vulns on the internet (as reported by sources like https://attacksurfacetop10.com) or some risk-based targets for vuln discovery time set in a vuln management policy or standard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants