Vulnerability Decision Brief

Free practitioner tool // Evidence stays in your browser

Vulnerability Decision Brief

Turn a vulnerability record into a defensible response decision. The tool calculates the official CISA SSVC outcome, keeps KEV, EPSS and CVSS as separate signals, surfaces evidence gaps, and produces a one-page handoff for operations or leadership.

  • Official SSVC decision logic
  • No invented composite risk score
  • Exportable operational record
01

Case and public signals

Identify the case. Public lookup sends the CVE identifier to FIRST and downloads CISA’s public KEV catalog from its official GitHub mirror.

Public intelligence
Not requested
02

Local operating context

These facts do not alter the official SSVC calculation. They make the operational handoff specific to your environment.

03

CISA SSVC decision points

Select evidence-supported values. The outcome follows the CISA Stakeholder-Specific Vulnerability Categorization decision table.

04

Detection and incident boundary

Vulnerability handling and incident response are related but not interchangeable. Record the compromise evidence separately.

05

Decision evidence

This measures evidence completeness—not vulnerability risk. Check only work supported by a record.

Evidence completeness controls

Why this is more than a checklist

What this changes for vulnerability teams

The brief connects public intelligence, business context, response logic, and closure evidence without hiding them inside a proprietary score. The result is a decision another team can understand, challenge, execute, and later audit.

01

Consistent decisions

The same five CISA SSVC decision points produce the same official outcome, reducing analyst-to-analyst variation.

02

Signals keep their meaning

CVSS, EPSS, and KEV answer different questions. Keeping them separate prevents a convenient number from concealing uncertainty.

03

A clear incident boundary

Suspected or confirmed compromise is recorded independently, so an urgent patch decision does not replace incident triage.

04

Evidence-ready closure

The handoff records what is known, what is missing, who owns the action, and what will prove that treatment is complete.

  1. IdentifyCase and service
  2. EnrichKEV, EPSS, CVSS
  3. DecideOfficial SSVC outcome
  4. BoundIncident and evidence gaps
  5. HandoffCopy, PDF, or JSON

Method and boundaries

The SSVC outcome is calculated from the official CISA decision table. KEV, EPSS and CVSS are displayed as independent evidence signals; they are not blended into a proprietary score. The operational translation and evidence-readiness assessment are Vetted SecOps practitioner guidance, not part of CISA SSVC and not a substitute for your organization’s risk acceptance, change, or incident-declaration criteria.

Primary references: CISA SSVC, CISA KEV, FIRST EPSS, and NIST SP 800-40 Rev. 4.

Privacy: assessment fields remain in browser memory. Public lookup sends only the CVE identifier to FIRST and downloads the public KEV catalog from CISA’s GitHub mirror; no enterprise assessment fields are transmitted or stored by this page.