5 ways to fix misleading vulnerability severities with policy
… For example, an organization with a "PCI-DSS" compliance framework can enforce stricter severity treatment for injection vulnerabilities across all PCI-scoped projects, while applying a lighter policy to internal tooling groups: vulnerability management policy : - name : "PCI projects: upgrade inje… …