<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1c1bb2caa">
    <name type="corporate">
         <namePart>United States Government Publishing Office</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
              <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
        </role>
         <role>
              <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
              <roleTerm authority="marcrelator" type="code">dst</roleTerm>
        </role>
    </name>
    <name type="corporate">
         <namePart>United States</namePart>
         <namePart>Commerce Department</namePart>
         <namePart>National Institute of Standards and Technology (NIST)</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
         <description>Government Organization</description>
    </name>
    <name type="personal">
         <namePart>Mell, Peter.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">government publication</genre>
    <language>
         <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
    </language>
    <extension>
         <collectionCode>GOVPUB</collectionCode>
         <category>Executive Agency Publications</category>
         <branch>executive</branch>
         <dateIngested>2023-10-27</dateIngested>
    </extension>
    <originInfo>
         <publisher>Commerce Department</publisher>
         <dateIssued encoding="w3cdtf">2022-11-15</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <note type="source content type">deposited</note>
         <digitalOrigin>born digital</digitalOrigin>
         <extent>52 digital object pages</extent>
    </physicalDescription>
    <classification authority="sudocs">C 13.</classification>
    <identifier type="uri">https://www.govinfo.gov/app/details/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44</identifier>
    <identifier type="local">P0b002ee1c1bb2caa</identifier>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST Interagency or Internal Reports</title>
        </titleInfo>
    </relatedItem>
    <identifier type="ILS system id">on1389890507</identifier>
    <identifier type="oclc">(OCoLC)1389890507</identifier>
    <recordInfo>
         <recordContentSource authority="marcorg">DGPO</recordContentSource>
         <recordCreationDate encoding="w3cdtf">2023-10-27</recordCreationDate>
         <recordChangeDate encoding="w3cdtf">2026-06-27</recordChangeDate>
         <recordIdentifier source="DGPO">GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44</recordIdentifier>
         <recordOrigin>machine generated</recordOrigin>
         <languageOfCataloging>
              <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    <accessCondition type="GPO scope determination">fdlp</accessCondition>
    <extension>
         <docClass>C13</docClass>
         <accessId>GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44</accessId>
         <uniqueId>a20c2765042908b62ad4d0aec66bca44</uniqueId>
         <ACCode>GOVPUB</ACCode>
         <fedPubName>NIST Interagency or Internal Reports</fedPubName>
         <field name="Note">NOTE: THE “DATE ISSUED” ABOVE MAY DEFAULT TO JANUARY 1ST OF A GIVEN YEAR. TO THE VIEW THE MOST ACCURATE DATE OF ISSUE, REVIEW THE TITLE PAGE OF THE PUBLICATION.</field>
         <description>Interim or final reports on work performed by NIST for outside sponsors (both government and non-government). May also report results of NIST projects of transitory or limited interest, including those that will be published subsequently in more comprehensive form.</description>
         <agency abbrev="NIST">National Institute of Standards and Technology</agency>
         <resultsLineTwoText>Commerce Department. National Institute of Standards and Technology. 2022</resultsLineTwoText>
         <dateIssued>2022-11-15</dateIssued>
    </extension>
    <location>
         <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44</url>
         <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44/pdf/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44.pdf</url>
    </location>
    <titleInfo>
         <title>Measuring the Common Vulnerability Scoring System Base Score Equation</title>
    </titleInfo>
    <subject>
         <topic>Common Vulnerability Scoring System (CVSS)</topic>
         <topic>Computer networks</topic>
         <topic>Computer security</topic>
         <topic>Evidence, Expert</topic>
         <topic>Measurement</topic>
         <topic>Software measurement</topic>
    </subject>
    <name type="personal">
         <namePart>Mell, Peter.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">creator</roleTerm>
        </role>
    </name>
    <name type="personal">
         <namePart>Mell, Peter.</namePart>
    </name>
    <name type="personal">
         <namePart>Spring, Jonathan.</namePart>
    </name>
    <name type="personal">
         <namePart>Dugal, Dave.</namePart>
    </name>
    <name type="personal">
         <namePart>Ananthakrishna, Srividya.</namePart>
    </name>
    <name type="personal">
         <namePart>Casotto, Francesco.</namePart>
    </name>
    <name type="personal">
         <namePart>Fridley, Troy.</namePart>
    </name>
    <name type="personal">
         <namePart>Ganas, Christopher.</namePart>
    </name>
    <name type="personal">
         <namePart>Kundu, Arkadeep.</namePart>
    </name>
    <name type="personal">
         <namePart>Nordwall, Phillip.</namePart>
    </name>
    <name type="personal">
         <namePart>Pushpanathan, Vijayamurugan.</namePart>
    </name>
    <name type="personal">
         <namePart>Sommerfeld, Daniel.</namePart>
    </name>
    <name type="personal">
         <namePart>Tesauro, Matt.</namePart>
    </name>
    <name type="personal">
         <namePart>Turner, Chris.</namePart>
    </name>
    <name type="corporate">
         <namePart>National Institute of Standards and Technology (U.S.)</namePart>
         <namePart>Material Measurement Laboratory</namePart>
    </name>
    <originInfo>
         <place>
              <placeTerm authority="marccountry" type="code">mdu</placeTerm>
        </place>
         <publisher>U.S. Dept. of Commerce, National Institute of Standards and Technology</publisher>
         <dateIssued>2022-11-15.</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <extent>1 online resource (52 pages) : illustrations (color)</extent>
    </physicalDescription>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">technical report</genre>
    <language>
         <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
    </language>
    <abstract>This work evaluates the validity of the Common Vulnerability Scoring System (CVSS) Version 3 &apos;&apos;base score&apos;&apos; equation in capturing the expert opinion of its maintainers. CVSS is a widely used industry standard for rating the severity of information technology vulnerabilities; it is based on human expert opinion. This study is important because the equation design has been questioned since it has features that are both non-intuitive and unjustified by the CVSS specification. If one can show that the equation reflects CVSS expert opinion, then that study justifies the equation and the security community can treat the equation as an opaque box that functions as described. This work shows that the CVSS base score equation closely though not perfectly represents the CVSS maintainers&apos; expert opinion. The CVSS specification itself provides a measurement of error called &apos;&apos;acceptable deviation&apos;&apos; (with a value of 0.5 points). In this work, the distance between the CVSS base scores and the closest consistent scoring systems (ones that completely conform to the recorded expert opinion) is measured. The authors calculate that the mean scoring distance is 0.13 points and the maximum scoring distance is 0.40 points. The acceptable deviation was also measured to be 0.20 points (lower than claimed by the specification). These findings validate that the CVSS base score equation represents the CVSS maintainers&apos; domain knowledge to the extent described by these measurements.</abstract>
    <note type="statement of responsibility">Peter Mell; Jonathan Spring; Dave Dugal; Srividya Ananthakrishna; Francesco Casotto; Troy Fridley; Christopher Ganas; Arkadeep Kundu; Phillip Nordwall; Vijayamurugan Pushpanathan; Daniel Sommerfeld; Matt Tesauro; Chris Turner.</note>
    <note>November 2022.</note>
    <note>Title from PDF title page (viewed January 4, 2023).</note>
    <note type="bibliography">Includes bibliographical references.</note>
    <note type="venue">Approved by the NIST Editorial Review Board on 2022-09-20</note>
    <note type="system details">Mode of access: World Wide Web.</note>
    <note type="system details">Systems requirements: Adobe Acrobat PDF reader.</note>
    <subject authority="lcsh">
         <topic>Evidence, Expert</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Measurement</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Software measurement</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Computer networks</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Computer security</topic>
    </subject>
    <subject>
         <topic>Common Vulnerability Scoring System (CVSS)</topic>
    </subject>
    <relatedItem type="series">
         <titleInfo>
              <title>NISTIR; NIST IR; NIST interagency report; NIST internal report; 8409</title>
        </titleInfo>
    </relatedItem>
    <location>
         <url displayLabel="electronic resource" usage="primary display">https://doi.org/10.6028/NIST.IR.8409</url>
    </location>
    <titleInfo type="alternative">
         <title>Measuring the Common Vulnerability Scoring System base score equation</title>
    </titleInfo>
    <extension>
         <searchTitle>
              <title>Measuring the Common Vulnerability Scoring System base score equation</title>
        </searchTitle>
    </extension>
</mods>