TechKnowSurge
CompTIA CySA+ 2.3 NIST CSF ID.RA-05 NIST 800-53 RA-3 ISC2 CISSP 1.9
VideoSecurityFree

Vulnerability Analysis and (Re-)Classification

Vulnerability analysis goes beyond running scans — it requires assessing each finding against your organization's specific environment, risk tolerance, and asset value to determine true impact. Standard severity scores like CVSS provide a starting point, but organizations must often reclassify vulnerabilities to reflect their actual exposure.

Complete this video to capture a CTF flag worth 1 point.

About this video

Identifying vulnerabilities is only the first step — the more consequential work is assessing what those vulnerabilities actually mean for the organization. Vulnerability scans and penetration tests generate reports that typically include severity ratings based on frameworks like CVSS, which scores vulnerabilities from 0 to 10 and assigns classifications such as low, medium, high, or critical. These scores offer a useful baseline, but they are calculated from a generalized or external perspective and do not automatically account for the specifics of any given environment. Organizational context plays a significant role in determining true risk. A vulnerability rated critical in a public-facing system may carry far less weight if it exists on an isolated internal network with strong access controls. Conversely, a lower-rated finding could represent a serious threat if it affects high-value assets or touches systems subject to strict regulatory requirements. Environmental variables, exposure factors, the value of affected assets, and the organization's overall risk tolerance all factor into how a vulnerability should ultimately be treated. Because of these variables, security teams are not bound by the severity labels assigned in scan reports. Reclassification is a legitimate and often necessary part of the analysis process, allowing organizations to adjust ratings upward or downward to reflect actual probability of exploitation and realistic impact. The goal is to ensure that remediation efforts are prioritized based on what genuinely matters to the organization, not on generalized scores that may not apply to its specific infrastructure and risk profile.

What you'll learn

What's covered

Vulnerability Analysis Process

Aligned to

CompTIA CySA+
2.3 Given a scenario, analyze data to prioritize vulnerabilities.
NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
NIST 800-53
RA-3 Risk Assessment
ISC2 CISSP
1.9 Understand and apply risk management concepts

Key terms

Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing vulnerabilities in a system.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Exploit
A piece of software or technique that takes advantage of a vulnerability to gain unauthorized access or cause harm.
Common Vulnerability Scoring System
CVSS
Common Vulnerability Scoring System is an open industry standard that provides a numerical score from 0 to 10 representing the severity of a vulnerability, enabling organizations to prioritize remediation efforts based on base, temporal, and environmental metrics.
Risk Tolerance
The level of risk an organization is willing to accept before taking action to reduce or eliminate it. Risk tolerance is determined by leadership and reflects the organization's risk appetite, regulatory environment, and available resources.

Topics

Vulnerability Management Cvss Risk Assessment Vulnerability Analysis Threat Prioritization Cybersecurity

Transcript

Once we've identified vulnerabilities on our network, what we're going to need to do is analyze those vulnerabilities and understand the impact if it were to ever be leveraged.

Assessing the vulnerabilities

When we've discovered vulnerabilities on our network, the next part of our process here is to assess those vulnerabilities, and assess them for the possible impact that they would have to our organization.

This actually could be a fairly simple step. A lot of our vulnerabilities are going to be found through vulnerability scans and pen testing, and usually the reports that are generated from that will give us an idea of how critical these vulnerabilities are. A lot of these systems are going to have some sort of scoring system, and there's a good chance it's the CVSS, that's going to score things on a scale from 0 to 10 on how critical they are and how much we should really pay attention to these vulnerabilities. They also are probably going to have some sort of classification system, where they're going to label things as informational or low, or they're going to label them as high or critical, or somewhere in between.

Your organization's context

Just because that's the rating that they give doesn't necessarily mean that's how it applies to your organization. Your organization has other considerations involved — for instance, the context in which it applies, the context to which these might apply. When they're giving you a rating, just an overall rating, it might be from an external standpoint: that is, how serious it is if they had access to it from an external standpoint. But it could be on an internal network that's well protected, or even an isolated network.

So there are a lot of environmental variables involved with your organization and how things are structured. You could have different exposure factors. You could be part of an industry or an organization that either says it's not that critical, or maybe says it's more critical. Or there could be a way that it could be exploited or weaponized that's different for your company. Maybe it doesn't deal with assets that are all that valuable, or maybe they're very valuable, and so you might recategorize these based off of that. It also has to do with your risk tolerance as a company.

Basically these ratings are a probability that this could happen, how easy it can happen, who can carry it out, and the impact it would be having on your organization. But only you can really fully determine the probability and impact that these have on your organization.

Reclassification

So what you may do is a reclassification. If something comes in as critical, but you analyze it and it has either less of a probability or less of an impact, then maybe you are going to recategorize it to a different category. That is something that you do have the option to do.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →