FIRST CSIRT Services Framework and Standards
FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

FIRST CSIRT Services Framework and Standards FIRST-CVSS-v4: FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy

FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Interaction + Vulnerable System Impact + Subsequent System Impact (Confidentiality + Integrity + Availability for each); (b) THREAT METRICS (replacing v3.1 Temporal) - Exploit Maturity; (c) ENVIRONMENTAL METRICS - Modified Base + Confidentiality / Integrity / Availability Requirements; (d) SUPPLEMENTAL METRICS (NEW in v4) - Safety + Automatable + Recovery + Value Density + Vulnerability Response Effort + Provider Urgency; (e) MACRO VECTOR - 5-character compressed equivalence-class identifier; (f) QUALITATIVE SEVERITY - None (0.0) / Low (0.1-3.9) / Medium (4.0-6.9) / High (7.0-8.9) / Critical (9.0-10.0). CVSS v4 IMPROVEMENTS: finer-grained scoring + Threat = Exploit Maturity decoupling from Temporal; Supplemental metrics support sector-specific contextualization (medical device safety; operational technology recovery); the Macro vector enables consistent equivalence-class reporting. CISA KEV CATALOG + the NVD adopt CVSS scores; CVSS feeds the EU CRA vulnerability handling + the 2024 OMB M-22-09 remediation timelines. ENGAGEMENT: organisations should adopt CVSS v4 for new advisories; legacy v3.1 scores remain valid + comparable via CVSS Calculator + Mapping Tables.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.