How to calculate Risk score?

Devi12
Giga Guru

Hi,

I was confused with the risk score calculation for VIT. There are default risk rule is defined to calculate Risk score. in this rule CI criticality, Business criticality and Vulnerability Exploit attack vector weights are 0. I attached the risk rules for each field value:

Devi12_0-1668069563576.pngDevi12_1-1668069596206.png

 

Devi12_2-1668069616446.pngDevi12_3-1668069643956.pngDevi12_4-1668069692143.pngDevi12_5-1668069711261.png

Devi12_6-1668069850721.png

Devi12_7-1668070179005.png

 

 

 

 

 

From above VIT, if I calculate Risk score:

Risk score = (60(75)+30(100)+10(50))/100 = 80. But the risk score is showing on above VIT is 75.

What I missed in my calculation?

 

 

1 REPLY 1

AyanshN
Tera Contributor

Hi @Devi12 ,
Can we calculate risk value in local PDI, if yes can you provide the path or reference for the same.