Table 10 ERS components and baseline weights (practitioner-elicited)
Component | Definition (normalized) | Baseline weight (w, i) | Rationale (practitioner elicitation summary) |
|---|---|---|---|
E | Exploitability signal (EPSS probability for the CVE; else default exploitability prior) | 0.25 | Emphasizes likely-to-be-exploited issues; ranked highest by SOC/IR and vulnerability-management roles |
V | Technical severity (normalized CVSS base score: CVSS/10) | 0.15 | Retains inherent severity while allowing exploitability and context to dominate prioritization |
K | Known exploited indicator (KEV/verified exploitation) | 0.15 | Escalates exposures with verified exploitation pressure and active weaponization signals |
A | Asset criticality (business tiering and data sensitivity, normalized to 0–1) | 0.20 | Ensures prioritization reflects business impact (crown-jewel services/data) and mission disruption |
X | Exposure factor (reachability + attack-path + control gaps, e.g., internet-facing, auth gaps, misconfigurations) | 0.15 | Captures practical reachability and defense-in-depth weaknesses that increase likelihood of compromise |
T | Threat context (campaign/sector targeting; ATT&CK relevance; adversary interest) | 0.10 | Accounts for contextual threat pressure beyond static vulnerability scoring |