Why lists for security vulnerabilities are flawed

Krebs on Security reports on the flaws in listing security vulnerabilities.

You’ve probably seen the Top 10 Vulnerabilities lists that highlight the worst offenders in security, but Krebs on Security says those lists aren’t really all that helpful.

Krebs reports these lists look at only one factor — the number of security reports, a measure too simplistic for the complex, multi-faceted problem of cybersecurity.

It’s a bit like trying to gauge the relative quality of different Swiss cheese brands by comparing the number of holes in each: The result offers almost no insight into the quality and integrity of the overall product, and in all likelihood leads to erroneous and — even humorous — conclusions.

Krebs offers another way to measure vulnerabilities: a severity rating.

This story is part of Federal News Radio’s daily Cybersecurity Update brought to you by Tripwire. For more cybersecurity news, click here.

Copyright © 2024 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

    White House Executive order

    Biden’s executive order to protect Americans’ personal data: A step in the right direction, but other factors must still be addressed

    Read more
    Graphic By: Derace LauderdaleDoD graphic

    DoD continues domination of President’s Cup competition

    Read more