We'll put some notes about our discussion of severity benchmarks in this issue.
Severity benchmarks help us determine weight or effectiveness of elements in the threat model by providing more granularity and systematic metrics for obtain weights and effectiveness scores.
They should be
- Unique
- Mostly not overlapping or co-dependent
- Estimable/non-ambiguous
- Invoked at an appropriate level of the threat model
For this edition, I would suggest that we do not list the same benchmark in a node's children, and that we use the same set of benchmarks for all cousin nodes to ensure that we're doing apples-to-apples comparisons.
We'll put some notes about our discussion of severity benchmarks in this issue.
Severity benchmarks help us determine weight or effectiveness of elements in the threat model by providing more granularity and systematic metrics for obtain weights and effectiveness scores.
They should be
For this edition, I would suggest that we do not list the same benchmark in a node's children, and that we use the same set of benchmarks for all cousin nodes to ensure that we're doing apples-to-apples comparisons.