ISO/SAE 21434
Clause 15: Threat analysis and risk assessment methods – ISO/SAE 21434

ISO/SAE 21434 RC-15-13: [RC-15-13] CVSS-based approach

Where the CVSS-based method is chosen, the rating should come from the exploitability metrics in the base metric group, namely attack complexity, attack vector, user interaction and privileges required (Annex G.3).

Maintained by Gerard BlokdykControl text last updated

Other controls in Clause 15: Threat analysis and risk assessment methods – ISO/SAE 21434

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.