Vulnerability management: prioritising with CVSS v4.0, KEV and EPSS
For vulnerability management, security operations and systems staff who turn scanner output into a remediation order they can defend. It goes deeper than Vulnerability and patch triage: you should already read a finding and know the CVSS rating bands. Covers reading CVSS v4.0 vectors and nomenclature, adjusting Threat and Environmental metrics, using the CISA Known Exploited Vulnerabilities catalog and its feed, the US federal directives behind it (BOD 22-01, revoked and superseded on 10 June 2026 by BOD 26-04), interpreting EPSS probabilities and percentiles, and ranking findings with a written rationale. The directives bind US federal civilian agencies only; other organisations use KEV as guidance. This course isn't legal or compliance advice and doesn't make you an assessor of anyone's compliance; your organisation's vulnerability management policy sets your remediation targets. Ends with a supervisor-graded prioritisation exercise.
- Level
- Intermediate
- Length
- About 100 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Read a CVSS v4.0 vector string and explain what its Base metrics say about exploitation and impact
- Choose the right CVSS nomenclature and adjust Threat and Environmental metrics for your environment
- Use the CISA KEV catalog and BOD 26-04's decision variables to decide remediation urgency
- Interpret EPSS probabilities and percentiles and combine them with KEV and CVSS without misusing them
- Rank a set of findings and write a prioritisation decision with rationale, owners and exceptions
Course outline
- 1.Read a CVSS v4.0 vector stringLesson · 20 min
- 2.Choose the right CVSS nomenclature and adjust Threat and Environmental metricsLesson · 18 min
- 3.Use the CISA KEV catalog and BOD 26-04's decision variablesLesson · 22 min
- 4.Interpret EPSS and combine it with KEV and CVSSLesson · 18 min
- 5.Rank findings and write a prioritisation decisionLesson · 14 min
- 6.Vulnerability management: prioritising with CVSS v4.0, KEV and EPSS: knowledge checkKnowledge check · 14 questions
- 7.Vulnerability management: prioritising with CVSS v4.0, KEV and EPSS: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- FIRST: CVSS v4.0 Specification Document
- FIRST: CVSS v4.0 User Guide
- CISA: Known Exploited Vulnerabilities Catalog
- CISA: Known Exploited Vulnerabilities catalog, JSON feed
- CISA: Known Exploited Vulnerabilities catalog, JSON schema
- CISA: BOD 22-01 Reducing the Significant Risk of Known Exploited Vulnerabilities (revoked, superseded by BOD 26-04)
- CISA: BOD 26-04 Prioritizing Security Updates Based on Risk
- CISA: BOD 26-04 Implementation Guidance
- FIRST: Exploit Prediction Scoring System (EPSS)
- FIRST: EPSS frequently asked questions
- FIRST: Using EPSS (thresholds, combining with KEV and CVSS, common misuses)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.