BOD 26-04 Decision Lane

KEV → SSVC → Compensating Controls · Tools 02·42·43 merged
GHOST DEFENSE
Tool 47 · Defend Always
KEV NOT LOADED
CVE Input
Pulls CVSS vector + CWE from NVD (via Ghost Worker) and checks the live CISA KEV catalog. You can also fill fields manually — nothing here is required to come from the fetch.
Stage 1 · KEV StatusSourced · CISA KEV
Load KEV and pull a CVE, or import KEV, to resolve exploitation status.
Stage 2 · SSVC DecisionTable 8+9 verbatim
1 · ExploitationKEV-derived
NONE
PUBLIC PoC
ACTIVE
Present state only. In KEV → Active. Public exploit → Public PoC. Only Active can reach Act.
2 · AutomatableHuman
NO
YES
Can an adversary automate all four steps (reconnaissance, weaponization, delivery, exploitation) reliably at scale? Your judgment.
3 · Technical ImpactCVSS-suggested
PARTIAL
TOTAL
Total = full control / total disclosure. Partial = limited; DoS is Partial. CVSS suggestion is advisory — you confirm.
4a · Mission PrevalenceHuman
MINIMAL
SUPPORT
ESSENTIAL
How much does your mission rely on this system? Your judgment.
4b · Public Well-Being ImpactHuman
MINIMAL
MATERIAL
IRREVERSIBLE
Safety/financial/psychological harm to the public if exploited. Mission × Well-being → band via Table 8.
Choose Exploitation, Automatable, Technical Impact, Mission, and Well-being to resolve the CISA SSVC decision.
Stage 3 · Compensating ControlsCWE→NIST/CIS
Unlocks when the decision is ACT (or use “Show anyway”). Compensating controls buy time when you can't patch inside the 3-day window — pulling an asset off the internet is itself a control action that can move it out of the top tier.
DEFEND ALWAYS · Exploitation auto-derived from CISA KEV · Technical Impact suggested from CVSS, human-confirmed · Automatable + Mission + Well-being are human judgments · Controls are candidate families — you confirm feasibility · CVSS/CWE fetched from NVD 2.0 via Ghost Worker, not validated in-page · Not a substitute for patching.