You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two types of machine readable vulnerability reporting have been used extensively to communicate with customers with affected products.
Secure Advisories - following CSAF profile 4 Security Advisory profile is vulnerability centric reporting on a specif vulnerability and affected products
Vulnerability Disclosure Reports (NIST Guidance in SP 800-161r1) now renamed Vulnerability Advisory Report (VAR) reporting on the vulnerability status of a specific product, typically at the SBOM component level. Two machine readable VDR/VAR formats are available:
Implicit, only listing SBOM components with reported vulnerabilities in a product
Explicit - lists each SBOM component with its vulnerability status including those with no vulnerabilities reported serving as an attestation by a supplier of their vulnerability monitoring activities per product
Both implicit and explicit options of VDR/VAR have open source, free to use machine readable formats available for use that follow NIST SP 800-161r1 RA5 data requirements
The text was updated successfully, but these errors were encountered:
Two types of machine readable vulnerability reporting have been used extensively to communicate with customers with affected products.
Both implicit and explicit options of VDR/VAR have open source, free to use machine readable formats available for use that follow NIST SP 800-161r1 RA5 data requirements
The text was updated successfully, but these errors were encountered: