| Security Vulnerability Scoring Definition ABE UML Documentation |
Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::Security Vulnerability Scoring Definition ABE
Class SecVulnerabilityScoringMetricDefn
The definition of a metric which may be categorized into three groups (Base, Temporal, and Environmental). These three groups are further decomposed into groupings for exploitability and/or impact which define metrics used to score vulnerability severity. Notes: For example, Base Metrics are grouped into Base Exploitability and Base Impact Metrics. Base Exploitability Metrics include Access Vector, Authentication, and Access Complexity Metrics.
Attributes |
CompositeSecVulScoringMetricDefn | compositeSecVulScoringMetricDefn | |
String | datatype |
A kind of value that the associated SecVulnerabilityScoringMetricValueDefn can take on, such as numeric, text, and so forth.
|
String | description |
A narrative that explains the purpose of the of the SecVulnerabilityMetricDefn.
|
String | name |
A word, term, or phrase by which the SecVulnerabilityMetricDefn is known and distinguished from other SecVulnerabilityMetricDefns. Notes: The name for the metric may be assigned by NIST. Examples include Base Metrics, Temporal Metrics, Environmental Metrics, Exploitability and Impact Metrics.
|
Integer | scoringSequence |
The order in which the score for the metric is calculated. This ensures that a metric's score upon which another is dependent is calculated first. Notes: For example, the Base Exploitability Score is calculated after the Access Vector, Authentication, and Access Complexity scores are calculated. Also, the Base Score has to be calculated from the Base Metrics before scoring the Temporal and/or Environmental Metrics.
|
SecVulnerabilityMetricValueDefn | secVulnerabilityMetricValueDefn | |
SecVulnerabilityScoringMetricDefnAssignment | secVulnerabilityScoringDefnMetric | |
«baseType» TimePeriod | validFor |
The period of time for which a SecVulnerabilityMetricDefn is applicable.
|
Properties:
compositeSecVulScoringMetricDefn
Public CompositeSecVulScoringMetricDefn compositeSecVulScoringMetricDefn
-
Constraints:
-
Properties:
-
datatype
Public String datatype
-
A kind of value that the associated SecVulnerabilityScoringMetricValueDefn can take on, such as numeric, text, and so forth.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecVulnerabilityScoringMetricDefn |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 1 |
Lower Value | |
Multiplicity | None (1) |
Name | datatype |
Name Expression | |
Namespace | SecVulnerabilityScoringMetricDefn |
Opposite | |
Owner | SecVulnerabilityScoringMetricDefn |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::Security Vulnerability Scoring Definition ABE::SecVulnerabilityScoringMetricDefn::datatype |
Stereotype | required |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | |
Visibility | Public |
description
Public String description
-
A narrative that explains the purpose of the of the SecVulnerabilityMetricDefn.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecVulnerabilityScoringMetricDefn |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 1 |
Lower Value | |
Multiplicity | None (1) |
Name | description |
Name Expression | |
Namespace | SecVulnerabilityScoringMetricDefn |
Opposite | |
Owner | SecVulnerabilityScoringMetricDefn |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::Security Vulnerability Scoring Definition ABE::SecVulnerabilityScoringMetricDefn::description |
Stereotype | required |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | |
Visibility | Public |
name
Public String name
-
A word, term, or phrase by which the SecVulnerabilityMetricDefn is known and distinguished from other SecVulnerabilityMetricDefns. Notes: The name for the metric may be assigned by NIST. Examples include Base Metrics, Temporal Metrics, Environmental Metrics, Exploitability and Impact Metrics.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecVulnerabilityScoringMetricDefn |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 1 |
Lower Value | |
Multiplicity | None (1) |
Name | name |
Name Expression | |
Namespace | SecVulnerabilityScoringMetricDefn |
Opposite | |
Owner | SecVulnerabilityScoringMetricDefn |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::Security Vulnerability Scoring Definition ABE::SecVulnerabilityScoringMetricDefn::name |
Stereotype | required |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | |
Visibility | Public |
scoringSequence
Public Integer scoringSequence
-
The order in which the score for the metric is calculated. This ensures that a metric's score upon which another is dependent is calculated first. Notes: For example, the Base Exploitability Score is calculated after the Access Vector, Authentication, and Access Complexity scores are calculated. Also, the Base Score has to be calculated from the Base Metrics before scoring the Temporal and/or Environmental Metrics.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecVulnerabilityScoringMetricDefn |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 1 |
Lower Value | |
Multiplicity | None (1) |
Name | scoringSequence |
Name Expression | |
Namespace | SecVulnerabilityScoringMetricDefn |
Opposite | |
Owner | SecVulnerabilityScoringMetricDefn |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::Security Vulnerability Scoring Definition ABE::SecVulnerabilityScoringMetricDefn::scoringSequence |
Stereotype | |
Template Parameter | |
Type | Integer |
Upper | 1 |
Upper Value | |
Visibility | Public |
secVulnerabilityMetricValueDefn
Public SecVulnerabilityMetricValueDefn secVulnerabilityMetricValueDefn
-
Constraints:
-
Properties:
-
secVulnerabilityScoringDefnMetric
Public SecVulnerabilityScoringMetricDefnAssignment secVulnerabilityScoringDefnMetric
-
Constraints:
-
Properties:
-
validFor
Public «baseType» TimePeriod validFor
-
The period of time for which a SecVulnerabilityMetricDefn is applicable.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecVulnerabilityScoringMetricDefn |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 1 |
Lower Value | |
Multiplicity | None (1) |
Name | validFor |
Name Expression | |
Namespace | SecVulnerabilityScoringMetricDefn |
Opposite | |
Owner | SecVulnerabilityScoringMetricDefn |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::Security Vulnerability Scoring Definition ABE::SecVulnerabilityScoringMetricDefn::validFor |
Stereotype | |
Template Parameter | |
Type | «baseType» TimePeriod |
Upper | 1 |
Upper Value | |
Visibility | Public |
| Security Vulnerability Scoring Definition ABE UML Documentation |