Vulnerability triage & response
Security & software supply chain
Vulnerability triage & response
Vulnerability triage assesses exposure and impact. Combine severity (CVSS) with exploit evidence such as the CISA KEV catalogue and EPSS scores. Give each response an owner and a deadline that matches the risk.
Resources
Links marked “Amazon affiliate link” open an Amazon product page. As an Amazon Associate I earn from qualifying purchases. About affiliate links
NIST Secure Software Development Framework (SSDF)Framework · NIST · opens in a new tabOSV: open source vulnerability databaseReference · Google, OpenSSF · opens in a new tabCISA Known Exploited Vulnerabilities catalogueReference · CISA · opens in a new tabEPSS: Exploit Prediction Scoring SystemReference · FIRST · opens in a new tabCVSSReference · FIRST · opens in a new tabDevOps guides (in French)Blog · Stéphane Robert · opens in a new tabOWASP Cheat Sheet SeriesReference · OWASP · opens in a new tabAlice and Bob Learn Application SecurityBook · Tanya Janca · Amazon affiliate link, opens Amazon in a new tabSecuring DevOpsBook · Julien Vehent · Amazon affiliate link, opens Amazon in a new tabDeveloping Secure Software (LFD121)Course · OpenSSF, The Linux Foundation · opens in a new tab