Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AIS-07-M6 is either A/B or 1-(A/B), but which? #40

Open
pritikin opened this issue Feb 16, 2022 · 0 comments
Open

AIS-07-M6 is either A/B or 1-(A/B), but which? #40

pritikin opened this issue Feb 16, 2022 · 0 comments

Comments

@pritikin
Copy link
Contributor

The expression description and the example don't match.
Perhaps more importantly the example of 1-(A/B) provides a nicer target but the description results in the inverse.

This metric measures the percentage of critical vulnerabilities that are not fixed or marked as accepted within the time specified by policy.

Percentage: 100 * A/B
A = Number of unaccepted critical or high vulnerabilities with an age greater than the policy defined maximum age
B = Total number of critical or high vulnerabilities within this period
Example:
Percentage: 100 * 1-(A/B)
A = Number of deployed production appliances with unaccepted critical
or high vulnerabilities with an age greater than the policy defined
maximum age
B = Total number of deployed production applications
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant