Effective risk
Adjust a CVE's severity for one of your assets, rank which control investment removes the most risk when you cannot patch, and record reviewed exploitability decisions as OpenVEX.
Plan Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.
Try it
Using Ansvar, score CVE-2024-3400 against our edge firewall: it is internet-facing, management access is restricted to a jump host, and GlobalProtect is disabled. Show which rules changed the score and why.More examples:
Using Ansvar, for these five CVEs on our PLC network that we cannot patch this year, simulate which control investment removes the most effective risk and list the findings no control can move.Using Ansvar, record my acceptance of the not_affected disposition for that last result, then export it as an OpenVEX document.What comes back
A score adjusted for your asset, with the rule behind each change, so you can see why the number moved. Ansvar stores none of it: your assistant gets a signed token with each result, and you keep the tokens you want to review or export later.
For developers, the fields to read:
- Adjusted score, the provenance of each changed metric, and the policy rules that fired (
verbose=trueadds the rules that did not fire and why) review_token, orreview_token_unavailablesaying why a result could not be signed- Simulation per investment: findings whose score moves (with before and after vectors), findings that gain a compensating-control marker, reductions the policy vetoes, and findings no control can move
- Review: a signed review event and a new token; export: an OpenVEX document
Which plan
Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.
- Vulnerability assessment runs use the batch scorer and the investment simulation.
- Deferral dossier runs use the batch scorer, the investment simulation and the applicability check.
- ICS advisory-to-risk runs use the single and batch scorers.
Free and Solo do not include effective risk.
Tools
effective_risk_inlinescores one CVE against an asset you describe in the call.effective_risk_inline_batchscores several CVEs the same way.effective_riskscores against a full asset configuration you send.list_scoring_policieslists the rule sets the scorer can apply.simulate_control_investmentranks control investments across a set of findings.record_review_decisionrecords a person's accept or reject decision.export_vexturns reviewed decisions into an OpenVEX document.
Limits
- A simulation is hypothetical and unsigned, never a served score.
- The policy refuses some reductions outright, for example on a CVE on CISA's known-exploited list or a malicious-code weakness; the result shows them as vetoed.
- A control counts as evidenced only when its evidence points at a paragraph of a document you uploaded. You cannot declare it evidenced yourself.
- Only a person signed in to their own session can record a review decision; agent and service credentials are refused.
- Ansvar keeps no asset configurations and no results. Send the configuration with each call.
- An OpenVEX export refuses a statement that is not valid OpenVEX, such as one with no product identifier.