CVSS support should be a requirement for all vulnerability assessment procurements, and enterprises should urge all IT suppliers to use CVSS scoring when disclosing vulnerabilities.
–John Pescatore, Gartner
The Veracode software ratings system Veracode offers the industry’s first standards-based ratings system for determining security levels in software. The Veracode ratings system provides a pragmatic way for enterprises and Independent Software Vendors (ISVs) to measure, compare and improve application security levels. Standards-based Ratings
Veracode’s Software Security Ratings System is based on respected industry standards including MITRE’s Common Weakness Enumeration (CWE) for classification of software weaknesses and FIRST’s Common Vulnerability Scoring System (CVSS) for severity and ease of exploitability and NIST's definitions of assurance levels. Veracode is the only organization to combine these standards into a meaningful and practical way to assess software security across internally developed and externally purchased applications. Learn more about how Veracode is leveraging CWE, CVSS and NIST to provide a trusted security rating for organizations developing and buying software. |




