To develop a framework for cloud-native vulnerability management that integrates business risk, asset criticality, and cloud dynamics.
Budget: $30 – $250 USD
I need help with a cybersecurity project. The topic is "Risk-based Prioritization in Cloud-native Vulnerability Management: A Framework for Enhanced Decision-making." Nowadays, CVSS scoring is being used to determine the severity of the vulnerability. Because enterprise systems shift toward cloud-native architectures (including containers, microservices, and serverless technologies), traditional approaches to vulnerability management are not enough to provide aspects of cloud vulnerabilities and security. What I want to show is CVSS scoring is not good enough to decide because it does not reflect dynamic risk factors like system exposure, asset criticality, or business impact. This project aims to bridge that gap by synthesizing a framework that incorporates business risk, asset criticality, threat intelligence, and cloud-native dynamics into a prioritization decision model. Which makes it suitable for organizations using cloud-native infrastructure. I thought maybe I can pick 4 cases of cloud vulnerabilities scored by CVSS but not accurately represent the corporate environment because it is not risk based.
I also need to come up with a network, cloud and endpoint architectural system of a company to prove that these uses cases when applied to my case, shows cvss is not enough in terms of .... and need to consider this architecture and how it applies to these cvss use cases and show cvss is not working for them because ... (for example cvss may rate it as critical for public network but if the system in the company is isolated then it is not really critical, thus cvss is not working in this case). So after these scenarios and showing that cvss is not working and why, I need to suggest how risk assessment should be done in Risk-based Prioritization in Cloud-native Vulnerability Management. For this I have no idea how to create a framework so I need help for that too.
Project goal
To develop a framework for cloud-native vulnerability management that integrates business risk, asset criticality, and cloud dynamics.
Scope of work
- Analyze current CVSS scoring limitations for cloud-native architectures.
- Identify and evaluate case studies of cloud vulnerabilities with a focus on system exposure and asset criticality.
- Design a network, cloud, and endpoint architecture for illustrating CVSS limitations.
- Propose a risk-based prioritization framework for cloud-native environments. - Provide guidelines for incorporating business risk and threat intelligence into the model.
I also need to come up with a network, cloud and endpoint architectural system of a company to prove that these uses cases when applied to my case, shows cvss is not enough in terms of .... and need to consider this architecture and how it applies to these cvss use cases and show cvss is not working for them because ... (for example cvss may rate it as critical for public network but if the system in the company is isolated then it is not really critical, thus cvss is not working in this case). So after these scenarios and showing that cvss is not working and why, I need to suggest how risk assessment should be done in Risk-based Prioritization in Cloud-native Vulnerability Management. For this I have no idea how to create a framework so I need help for that too.
Project goal
To develop a framework for cloud-native vulnerability management that integrates business risk, asset criticality, and cloud dynamics.
Scope of work
- Analyze current CVSS scoring limitations for cloud-native architectures.
- Identify and evaluate case studies of cloud vulnerabilities with a focus on system exposure and asset criticality.
- Design a network, cloud, and endpoint architecture for illustrating CVSS limitations.
- Propose a risk-based prioritization framework for cloud-native environments. - Provide guidelines for incorporating business risk and threat intelligence into the model.