Skip to content

Create a Requirements/Prerequisites Association for Vulnerabilities #100

Open
@andrewbwm

Description

@andrewbwm

Create a Requirements/Prerequisites association between SoftwareVulnerabilities and Data, Information, Application, or any other asset that could fit the concept. The attacker would have to compromise these assets before they are able to attempt to abuse the SoftwareVulnerabilities. The compromise would have to be asset specific FullAccess for Applications and Write for Data/Information might be good candidates.

While some SoftwareVulnerabilities would still have some more nuanced or specific requirements that the coarse design outlined above, but the change would still significantly increase the modelling capabilities of the language.

Something similar could be done for HardwareVulnerabilities if deemed relevant.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions