Task-specific dataset for Augmenting Key Risk Indicators with Key Control Indicators to improve vulnerability remediation decisions
收藏资源简介:
Vulnerability remediation is a constrained decision problem in which organisations must select a small subset of vulnerabilities for immediate treatment under limited patching capacity. Prior work has shown that EPSS is the strongest standalone signal for short-horizon exploitation likelihood, while baseline KRI provides a more risk-aware remediation signal than severity-only approaches; however, neither explicitly incorporates the weakness of controls relevant to current threat exposure. This paper introduces a control-aware extension of KRI that incorporates Key Control Indicators (KCI) derived from incident-informed mappings between cyber incidents, MITRE ATT&CK techniques, CIS safeguards, and CAS-aligned measurement structures represented in the Cyber Catalog. The study integrates 280,661 vulnerabilities, 74,985 incidents, and 79 unique ATT&CK techniques, and evaluates the model under synthetic control-posture conditions. Results indicate that control-aware extension of KRI provide better value for constrained top-k remediation under synthetic conditions when the decision objective is impact-weighted risk reduction rather than exploit-probability estimation alone.



