Performing Risk Assessments
While the CVSS score provides a standardized measure of a vulnerability's technical severity, a comprehensive Risk Assessment evaluates the actual business impact of the flaw within the context of your specific deployment environment. CVD Portal aligns product risk assessments with the normative 4-stage methodology of FprEN 40000-1-2 Clause 6.4 (RMA-03 to RMA-06):
- Asset Identification (
RMA-03-RQ-01): Map software components, stored data, keys, and user safety assets. - Threat Identification (
RMA-04-RQ-01): Apply STRIDE threat modeling and cross-reference known vulnerabilities from EUVD and GCVE. - Risk Analysis (
RMA-05-RQ-01..03): Estimate impact severity and occurrence likelihood for each threat scenario. - Risk Evaluation & Acceptance (
RMA-06-RQ-01..04): Compare residual risks against pre-established acceptance criteria (RMA-02) and justify any accepted residual risks.
The portal allows you to document the contextual factors that may increase or decrease the practical risk of a vulnerability. This includes analyzing the sensitivity of the data processed by the affected system, the presence of compensating controls (such as Web Application Firewalls or network segmentation), and the criticality of the system to your core business operations. By combining the technical CVSS score with this contextual business analysis, you arrive at a definitive priority level for remediation.
For detailed standard clause guidance, see Clause 6.4 — Product Cybersecurity Risk Assessment.
These formal risk assessments are crucial for justifying remediation timelines, especially when choosing to delay a patch in favor of alternative mitigations. All risk assessment decisions, along with their supporting rationale, are immutably logged within the portal. This provides a robust audit trail that demonstrates to regulators and stakeholders that your organization takes a deliberate, risk-based approach to vulnerability management.