Not all vulnerabilities are equally dangerous, and organizations with limited resources must fix the most important ones first. The Common Vulnerability Scoring System, or CVSS, provides a standardized way to rate a vulnerability's severity, giving a consistent numeric score. But a score alone is not a priority; effective remediation prioritisation combines CVSS with business context. This lesson covers how CVSS works and, crucially, how to turn scores into a sensible order of fixes that reflects real risk to the organization.
Analogy🏏Cricket
🏏 Think of it like cricket: Active recon is the captain walking out to inspect the pitch on match morning, pressing the surface, checking the grass, watching how the ball behaves in the nets. Unlike studying old footage from afar, this inspection happens on the ground itself and is visible to everyone. Just as that inspection reveals conditions no video could, active scanning reveals live services no public record shows, and just as it happens with the ground's permission, scanning happens only within authorized scope.