ASSESSMENTwalk the four CISA decision points
1 · ExploitationKEV-DERIVED
NONE
PUBLIC PoC
ACTIVE
Present state only. In KEV → Active. Public exploit (Metasploit/ExploitDB) or well-known method → Public PoC. Import KEV to auto-set. Only Active can reach Act.
2 · AutomatableHUMAN
NO
YES
Can recon→weaponize→deliver→exploit be reliably automated (wormable)? One effective barrier (auth, not internet-exposed, ASLR) = No. Unauth RCE / command injection = likely Yes. Consider chaining.
3 · Technical ImpactCVSS-SUGGESTED
PARTIAL
TOTAL
Total = full control of the component or total info disclosure. Partial = limited control / info exposure; DoS is Partial. Suggestion from CVSS is advisory — you confirm.
4a · Mission PrevalenceHUMAN
MINIMAL
SUPPORT
ESSENTIAL
Role of this asset in mission-essential functions. Essential = directly provides an MEF. Support = supports MEFs for ≥2 entities. Prevalence, not impact. Set per asset; reused when you re-enter the same asset.
4b · Public Well-Being ImpactHUMAN
MINIMAL
MATERIAL
IRREVERSIBLE
Harm to humans if compromised — physical, environmental, financial, psychological. Material = injury/major externalities/bankruptcies. Irreversible = fatalities, ecosystem collapse, social-system destabilization.
Tracked, not scored. Per the CISA guide, mitigation availability/difficulty/type do not change the SSVC decision — captured for VM records only.
DECISIONselect all four points
Mission & Well-being band — (Table 8)
—
awaiting input
Choose Exploitation, Automatable, Technical Impact, Mission, and Well-being to resolve the CISA SSVC decision.
⚠ Escalations — decision changed after exploitation update
ASSESSMENT REGISTER0 saved
| CVE / ASSET | E | A | T | M&W | DECISION |
|---|