Proceedings of EC2ND'07:
VRDA: Vulnerability Response Decision Assistance
Hal Burch, Art Manion,CERT/CC; Yurie Ito, JPCERT/CC
Abstract
Each year, thousands of new software vulnerabilities are reported,
and affected organizations must analyze them and decide how to respond. Many
organizations employ ad hoc systems of decision making, which often result in
inconsistent decisions that do not properly reflect the concerns of the
organization at large. VRDA (Vulnerability Response Decision Assistance)
allows organizations to leverage the analysis effort at other organizations and to
structure decision-making. VRDA enables organizations to spend less time
analyzing vulnerabilities in which they are not interested, to make decisions
more consistently, and to structure their decision making to better align with the
goals of the organization. VRDA consists of a data exchange format, a decision
making model, a decision model creation technique, and a tool embodying these
concepts. One response team is employing a basic form of VRDA to cut the
number of vulnerabilities analyzed by a factor of two. Another response team is
developing and testing a VRDA implementation within their organization.
Download this paper: pdf