Vulnerabilities – CVSS
Security within the IT infrastructure is a top priority for centron, particularly in the context of our ccloud³ cloud solution. To assess vulnerabilities efficiently and consistently, we use the Common Vulnerability Scoring System (CVSS), which was developed by the Forum of Incident Response and Security Teams (FIRST). This framework enables us to assess potential security vulnerabilities accurately and prioritise appropriate countermeasures.
Common Vulnerability Scoring System SIG
Why CVSS is important for the ccloud³
-
Standardised security assessment
By incorporating CVSS into ccloud³’s security strategy, we are able to assess vulnerabilities systematically and consistently. This ensures transparent communication between the IT Teams at centron and our customers.
-
Clearly defined risk prioritisation
CVSS helps centron to accurately assess the severity of a security vulnerability and to prioritise remedial actions based on this assessment. This assessment logic is incorporated into our ccloud³ security processes to ensure that the most serious vulnerabilities are addressed immediately
-
Improving the security strategy
The ccloud³ is designed to ensure the highest possible security standards. CVSS enables us to monitor the effectiveness of security measures and to improve them on an ongoing basis. This helps to ensure data integrity and the protection of our customers’ sensitive data.
How CVSS is applied in the ccloud³
1. Vulnerability Assessment
In ccloud³, every vulnerability detected is assessed using the CVSS framework. This assessment comprises three core components:
-
Base score: This determines the severity of the vulnerability itself.
-
Temporal value: Takes into account how the threat evolves over time.
-
Environmental impact: Determines the extent to which the vulnerability affects the specific environment of the ccloud³ and our customers.
2. Prioritisation and measures
Following the CVSS assessment, we initiate measures to rectify the vulnerability. The CVSS score is used to determine how urgently the vulnerability needs to be addressed:
-
Highly critical vulnerabilities: (CVSS score 9.0–10.0) are given the highest priority.
-
Moderate to critical vulnerabilities: (CVSS score 4.0–8.9) are also addressed promptly, but prioritised according to urgency.
-
Low-risk vulnerabilities: (CVSS score 0.1–3.9) are monitored and, where necessary, addressed in future updates.
By integrating the CVSS into centron and ccloud³’s security processes, we ensure that vulnerabilities are not only detected but also assessed objectively and prioritised. This enables centron to provide our customers with a reliable and highly secure cloud platform that can withstand the latest threats in the IT world.
Sources for identifying and deriving vulnerabilities
| Category | Source | Type of information |
|---|---|---|
| Rating systems | FIRST CVSS (https://www.first.org/cvss/)) | Severity rating |
| National CERTs | CERT-Bund (BSI) | Security alerts |
| National Situation Centres | Cyber Alliance Centre (CAZ) Bavaria | Situation reports, campaign alerts |
| EU authorities | ENISA Threat Landscape | Threat analyses |
| Vendor (Microsoft) | Microsoft Security Response Centre (MSRC) – https://msrc.microsoft.com | Security bulletins, patch information, CVEs |
| Vendor (Microsoft) | Microsoft Security Update Guide – https://portal.msrc.microsoft.com | Structured overview of vulnerabilities and updates |
| Vendor (Juniper) | Juniper Security Advisories – https://advisory.juniper.net/ | Security bulletins for Junos OS & components |
| Vendor (Juniper) | Juniper PSIRT (Product Security Incident Response Team) | Coordinated vulnerability disclosures |
| Vendor (other) | Vendor security bulletins for components in use | Product-related vulnerabilities |
| Open Source | GitHub Security Advisories | OSS vulnerabilities |
| Internal processes | PSS-02 – Identification of vulnerabilities | internal assessment |
| Internal tests | Penetration tests / scans (OPS-22 / OPS-25) | technical findings |
| Incidents | SIM-01 / OPS-21 | Lessons learnt |