Instiq
Chapter 4 · Vulnerability Assessment and Risk Management·v1.0.0·Updated 7/17/2026·~13 min

What's changed: Initial version

4.2Threat intelligence

Key points

Covers CVE, which references known weaknesses by a common name, and CVSS, which scores their severity; the uses and limits of a vulnerability database that collects weaknesses; and information sources such as security reports, news, subscription services, and crowdsourced intelligence—the basics of gathering and using them to judge "which threats deserve attention right now."

Once you find a vulnerability, the next thing you need to know is "how serious is it in the wider world, and how should it be handled." If people describe the same weakness by different names, conversation breaks down. Here CVE, which gives known weaknesses a common name, and CVSS, which scores their severity on a common scale, help. This section covers the uses and limits of a vulnerability database that stores these, plus information sources—vendor security reports, news, subscription services, and community crowdsourced intelligence—and how to gather and use them as material for judging "which threats deserve attention right now."

4.2.1CVE, CVSS, and vulnerability databases

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.