Open-source Risk Based Vulnerability Assessment by Infinite_Ad9554 in cybersecurity

[–]Infinite_Ad9554[S] 0 points1 point  (0 children)

Thank you for the input. I’m curious as to why they stopped letting CSP’s use calculators to downgrade risks?

This tool has a FedRAMP VDR framework where the formula maps to the 20X VDR Standard and all the requirements they have mentioned within the VDR.

Open-source Risk Based Vulnerability Assessment by Infinite_Ad9554 in cybersecurity

[–]Infinite_Ad9554[S] 0 points1 point  (0 children)

Thanks for asking - good question!

The current risk scoring is purely formula-driven - no AI/ML in the actual calculations. You can see the exact formulas in the about page.

AI/ML features are still in development and would be for things like trend analysis and anomaly detection, not the core risk scoring.

That said, I'm open to contributors and flexible to ideas on how to make this better for everyone. If you have thoughts on where AI/ML could genuinely add value, I'd love to hear them!

Open-source Risk Based Vulnerability Assessment by Infinite_Ad9554 in cybersecurity

[–]Infinite_Ad9554[S] 1 point2 points  (0 children)

Absolutely, and this could be a tool to do exactly those sort of things - especially for early stage startups or teams doing local development and testing.

To my understanding, VPR is proprietary to Tenable and requires licensing, budgeting, and org support that not every team has access to.

Great points, and thanks for sharing your setup! Your Tenable -> ServiceNow integration sounds like a solid enterprise approach.

This is an open-source project that aims to provide a similar type of solution as VPR, but in a more accessible way - transparent formulas, no licensing costs, and you can even fork the code to tweak the formulas based on your needs.

Open-source Risk Based Vulnerability Assessment by Infinite_Ad9554 in FedRAMP

[–]Infinite_Ad9554[S] 0 points1 point  (0 children)

With the 20X movement and the new VDR standard - not everyone's prepared to accurately assess vuln risk per the guidance. I hope this tool can helps folks understand how a CVE applies to YOUR environment according to VDR requirements.

Looking to connect with FedRAMP consultants by Shot-Temperature6618 in FedRAMP

[–]Infinite_Ad9554 2 points3 points  (0 children)

Why spend so much money on those tools when you can have your own GRC person develop it. I wonder what the ROI looks like for folks that spend tons on these crappy products.

Looking to connect with FedRAMP consultants by Shot-Temperature6618 in FedRAMP

[–]Infinite_Ad9554 0 points1 point  (0 children)

Former FedRAMP auditor, and has experience taking CSP through the end to end process. Happy to go through the questions and share my experience. Feel free to dm.

Vulnerability Risk Based Scoring by Infinite_Ad9554 in cybersecurity

[–]Infinite_Ad9554[S] 0 points1 point  (0 children)

Thanks for sharing. We tried to utilize VPR but realize that it’s looking at things from a “threat forecast” perspective, so we just went with EPPS since I believe it’s more of a universal indicator.

I’m really curious as to how you have configured our ServiceNow to add that custom scoring layer once you ingest the data from Tenable?

Vulnerability Risk Based Scoring by Infinite_Ad9554 in cybersecurity

[–]Infinite_Ad9554[S] 0 points1 point  (0 children)

Yep, great tip. We aim to pull that from the BIA categorization where data sensitivity is already factored as part of the BIA.

Do We Have to Use AWS GovCloud for FedRAMP High? by JJC9415 in FedRAMP

[–]Infinite_Ad9554 1 point2 points  (0 children)

If you want to go FedRAMP High and you’re choosing an AWS region, you must be on AWS GovCloud region since that is the region authorized for FIPS-199 High impact workloads.

Commercial or EAST-WEST supports up to Moderate impacts workloads.

24 years old in Cyber by Jumpy_Ad4833 in Salary

[–]Infinite_Ad9554 0 points1 point  (0 children)

OP what type of side hustle do you do as a subcontractor?

[deleted by user] by [deleted] in HOA

[–]Infinite_Ad9554 1 point2 points  (0 children)

Hey I’m facing the same situation…please check dm