CVSS-based vulnerability scoring & SLA enforcement (NVD integration)
Y
Yury E.
Problem
Several customers require CVSS-driven remediation SLAs. Today our risk surveys generate scenarios, but we donāt natively score/track vulnerabilities against CVSS v3.1 nor enforce time-bound fixes.
Proposal
Add first-class CVSS support so teams can ingest CVEs from scanners, calculate/display scores, and auto-enforce remediation SLAs. This aligns with ISO/IEC 27001:2022 A.8.8 ā Management of technical vulnerabilities and strengthens audit evidence.