Effective risk

    Adjust a CVE's severity for one of your assets, rank which control investment removes the most risk when you cannot patch, and record reviewed exploitability decisions as OpenVEX.

    Plan Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.

    Try it

    Using Ansvar, score CVE-2024-3400 against our edge firewall: it is internet-facing, management access is restricted to a jump host, and GlobalProtect is disabled. Show which rules changed the score and why.

    More examples:

    Using Ansvar, for these five CVEs on our PLC network that we cannot patch this year, simulate which control investment removes the most effective risk and list the findings no control can move.
    Using Ansvar, record my acceptance of the not_affected disposition for that last result, then export it as an OpenVEX document.

    What comes back

    A score adjusted for your asset, with the rule behind each change, so you can see why the number moved. Ansvar stores none of it: your assistant gets a signed token with each result, and you keep the tokens you want to review or export later.

    For developers, the fields to read:

    • Adjusted score, the provenance of each changed metric, and the policy rules that fired (verbose=true adds the rules that did not fire and why)
    • review_token, or review_token_unavailable saying why a result could not be signed
    • Simulation per investment: findings whose score moves (with before and after vectors), findings that gain a compensating-control marker, reductions the policy vetoes, and findings no control can move
    • Review: a signed review event and a new token; export: an OpenVEX document

    Which plan

    Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.

    • Vulnerability assessment runs use the batch scorer and the investment simulation.
    • Deferral dossier runs use the batch scorer, the investment simulation and the applicability check.
    • ICS advisory-to-risk runs use the single and batch scorers.

    Free and Solo do not include effective risk.

    Tools

    Limits

    • A simulation is hypothetical and unsigned, never a served score.
    • The policy refuses some reductions outright, for example on a CVE on CISA's known-exploited list or a malicious-code weakness; the result shows them as vetoed.
    • A control counts as evidenced only when its evidence points at a paragraph of a document you uploaded. You cannot declare it evidenced yourself.
    • Only a person signed in to their own session can record a review decision; agent and service credentials are refused.
    • Ansvar keeps no asset configurations and no results. Send the configuration with each call.
    • An OpenVEX export refuses a statement that is not valid OpenVEX, such as one with no product identifier.