Why lists for security vulnerabilities are flawed

Krebs on Security reports on the flaws in listing security vulnerabilities.

You’ve probably seen the Top 10 Vulnerabilities lists that highlight the worst offenders in security, but Krebs on Security says those lists aren’t really all that helpful.

Krebs reports these lists look at only one factor — the number of security reports, a measure too simplistic for the complex, multi-faceted problem of cybersecurity.

It’s a bit like trying to gauge the relative quality of different Swiss cheese brands by comparing the number of holes in each: The result offers almost no insight into the quality and integrity of the overall product, and in all likelihood leads to erroneous and — even humorous — conclusions.

Krebs offers another way to measure vulnerabilities: a severity rating.

This story is part of Federal News Radio’s daily Cybersecurity Update brought to you by Tripwire. For more cybersecurity news, click here.

Copyright © 2024 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

    GettyImages-1710421116Visual representation of cloud computing.

    FEMA’s cloud journey hitting uphill portion of marathon

    Read more
    DCSA

    New DCSA director sees a data-driven future for security clearances and more

    Read more
    HHS, cybersecurity, Administration of Children and families,The Department of Health and Human Services building

    A look into whether one HHS component is properly securing its cloud information systems

    Read more