Reply to post: Re: The logical next step is the two-dimensional risk rating approach

We're almost into the third decade of the 21st century and we're still grading security bugs out of 10 like kids. Why?

AMBxx Silver badge

Re: The logical next step is the two-dimensional risk rating approach

What tends to happen is that someone comes up with a clever multi-factor way to score the problems. For simplicity, that's then boiled down to a 100 point score. Then the fact that there's no difference between a score of 90 and 91 means it's boiled down to a 10 point score!

Then the 10 point score is considered too simplistic so we have a number after the decimal point...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon