From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Confidentiality, integrity, and availability impact metrics

Confidentiality, integrity, and availability impact metrics

From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1

Start my 1-month free trial

Confidentiality, integrity, and availability impact metrics

- [Instructor] Impact is actually three separate elements in the base metric group. In the vector string, each of these impacts is represented by the letters C for confidentiality, I for integrity, and A for availability. Impact is a critical component of determining the risk of a vulnerability. In the context of the base metric group, this is the impact exploitation of a vulnerability would have on confidentiality, integrity, and/or availability. A vulnerability can have impact on some or all of these components. If an attacker exploits a vulnerability, and as a result, she can get access to files or resources that she shouldn't have access to. That's a confidentiality impact. That's kind of like a guest snooping in your medicine cabinet. Confidentiality impact ranges from high to none. High means that a successful attack results in total loss of confidentiality, or the attack results in the attacker having access…

Contents