MIS 10.0 connects vulnerability intelligence to the assets, services and owners that determine your response. Each CVE is traced to the enterprise assets that carry it, the business services that depend on them and the accountable owner who decides — and closure counts only when it is independently verified.
01Do we have it?Match affected products and versions to the asset inventory, CMDB and SBOM evidence.
02Can it be exploited here?Assess reachable code, access paths and verified controls in your environment.
03What happens if it is?Identify affected services, sensitive data and accountable owners. Assess reporting duties if an incident occurs.
Foundation MIS 9.0 governance principlesProposed MIS 10.0 enterprise operating model — not verified deployment statusIllustrative conceptual example, not customer data
MIS 9.0 foundationFoundation
Governed decisions across Know, Reason, Act, Prove and Learn
MIS 9.0 supplies the governing principles. MIS 10.0 extends the evidence and the enterprise context — it does not relax the rules.
01KnowEstablish what exists, what is exposed and which evidence supports it.
02ReasonCombine threat, exposure and business context through versioned policy.
03ActExecute only what an accountable owner has authorised.
04ProveVerify the outcome independently before crediting risk reduction.
05LearnFeed residual risk and evidence gaps into the next assessment.
AI advises
AI advice stays separate from security truth. A model output never becomes an established fact.
People authorise
Human authorisation stays separate from execution. Nothing runs without an accountable approver.
Verification proves
Independent verification supports closure. Executing a change is not the same as proving it worked.
CVE-to-enterprise correlationProposed
Three evidence layers inside one governed chain
Severity, exploit evidence and local exposure stay visible as separate inputs. Every record retains its source, retrieval time and scoring version.
Layer 1
Vulnerability intelligence
Is it real and is it being exploited?
CVE
Identifier from the CVE Program
CPE
Names the affected products and versions
CWE
Classifies the underlying software weakness
CVSS
Technical severity, scoring version and vector
EPSS
30-day exploitation probability in the wild
CISA KEV
Records vulnerabilities with evidence of exploitation
Segmentation, WAF and EDR effectiveness, with evidence age
Layer 3
Business impact & governance
What happens if it is?
Dependent services
Business services the asset supports, directly or downstream
Sensitive data
Personal, financial, health or critical-infrastructure data
Accountable owners
Named owners for the asset and the decision
Applicable policy
Jurisdiction, sector and policy version
Governed enterprise priority — with its evidence and policy version attached
What the evidence can say
ConfirmedObserved directly and backed by current evidence.
InferredDerived from relationships or paths; shown separately from observations.
StaleEvidence older than its freshness window; visible as a coverage gap.
UnknownNot established. Remains an evidence gap until validated — never treated as safe.
A missing feed or missing CVE must never imply that an asset is safe. Unmatched assets, missing relationships and stale evidence remain visible as coverage gaps.
Illustrative Business impact gives the risk an owner
“CVE-X on server Y”→Potential disruption to online lending, exposure of customer data and an accountable service owner
Proposed ingestion controls Proposed
IngestCVE Program, NVD, EUVD, FIRST CVSS / EPSS, CISA KEV and vendor advisories — with source provenance
ReconcileDeduplicate records and surface conflicting product matches
MonitorFreshness, failed connectors and explicit degraded status
Continuous resilience workflowProposed
Continuous reassessment with verified closure
New intelligence and environment changes trigger reassessment. The loop never closes on execution alone.
1
Trigger
New exploit evidence, asset changes, firewall changes or control failures start a reassessment.
2
Assess
Correlate intelligence, exposure and business impact. Evidence supports the priority and recommendation.
3
Authorise
An accountable owner decides under versioned policy. The agent cannot authorise itself.
4
Act
Execute the authorised change, isolation or recorded, expiring risk acceptance.
5
Verify
Independent verification establishes the result before any risk reduction is credited.
6
Carry forward
Residual risk and evidence gaps feed the next assessment.
Freshness
Show the last successful assessment, any processing delay and missed events. Evidence carries its age; a result is only as current as its oldest input.
Coverage
Report which assets, services and feeds were assessed — and which were not. Unknown reachability or impact stays an evidence gap until validated.
Governance and explainabilityProposed
An explainable decision model
Combine separate dimensions through a versioned policy and preserve the decision trace.
Deterministic core
Decisions based on versioned rules and evidence. Replayable from the evidence snapshot and policy version.
Predictive analytics
Labelled as prediction. A forecast never appears as an established fact.
AI advisories
Labelled as advisory and non-authoritative. Advice cannot approve, execute or verify.
Conceptual decision flow, not a calibrated risk formula. Ordinal scores are not multiplied, and EPSS is not the probability that your organisation will be breached — it estimates exploitation activity in the wild. SSVC can guide urgency: Track, Track*, Attend or Act.
Named owners for each evidence dimension
Threat
Owner: Threat Intelligence
CISA KEV listing
EPSS exploitation probability
Public exploit code
ATT&CK-mapped actor intelligence
Regional / sector intelligence
Exposure
Owner: Infrastructure, Cloud & Platform
Internet-facing / partner / internal only
Authentication required to reach it
Code reachability (SBOM, VEX, runtime)
Compensating controls (WAF, EDR)
EASM and CSPM observations with timestamps
Blast radius
Owner: Enterprise Architecture + Business
Technical: attack paths, hops to Tier-0
Business: dependent services, cost
Data scope and potentially applicable obligations
Service relationships with confidence and evidence age
Illustrative One CVE, three enterprise response decisions
Asset
Threat
Exposure
Blast radius
Outcome
Internet-facing VPN gateway, connected to AD
High (KEV, ransomware-linked)
High (unauthenticated, public)
High (path to domain admin, critical data at risk)
Emergency patch or isolation under approved policy. Notify CISO.
Internal app server, segmented subnet
High
Medium (requires internal access)
Medium (one business service, limited data)
Remediate within the approved critical SLA.
Isolated lab system
High
Low (no network path)
Low (no production data)
Patch in the normal cycle or record an approved, expiring acceptance.
Illustrative response policy only. The timeframes are examples, not universal or regulatory deadlines. Validate asset reachability and business impact before acting.
Decision ownership, approvals, expiry and provenance
Risk-based SLAsVersion response policy using exploit evidence and local impact
Canonical inventoryResolve asset identity and retain SBOM and VEX provenance
Ownership at service levelRisk acceptance signed by a business owner, with an expiry
Formal exception processRecord controls, approver, expiry and review triggers
Source provenanceRetain source timestamps and expose conflicting intelligence
Control evidence mappingLink evidence to applicable controls with review ownership
Extend to third partiesTrack supplier components and dependencies by service
Business risk reportingShow critical-service exposure and accepted-risk trends
Automate & verifyAuthorise execution, verify independently, then reassess
Regulatory clocks require an incident trigger Reference
EU
24 hours
NIS2: early warning after awareness of a significant incident, for in-scope entities
Assess national implementation and applicable sector rules
India
6 hours
CERT-In: specified incidents, from noticing or being brought to notice
Assess entity and sector-specific duties separately
US
Rule-specific
BOD 22-01: KEV remediation due dates for FCEB agencies
SEC domestic registrants: generally 4 business days after determining materiality
Proposed policy overlay: record applicability, event trigger, owner and deadline. A CVE finding alone does not start every reporting clock. Route reporting decisions to the accountable legal and incident teams.
Enterprise outcomesProposed
Board visibility into exposure and residual risk
The measures MIS.Enterprise is designed to report. They are definitions, not live figures — no customer or production data is shown on this page.
Critical-service exposureShare of critical services with confirmed exploitable exposure, with coverage gaps.
Time to verified closureFor KEV on critical assets — measured to independent verification, not to ticket closure.
Overdue actions & expiring acceptancesMissed deadlines and risk acceptances approaching expiry, by owner.
Residual-risk trendsVerified change and accepted risk compared across assessments.
Assessment history & evidence coverageWhat changed and why, by run, service and owner — with evidence gaps visible.
Decision trace — what changed, and why? Compare assessments by run, service and owner. Show verified change, accepted risk and evidence gaps.
MIS.Enterprise engagement
Begin with one critical service
Connect its assets, validate exposure, assign decision owners and demonstrate independently verified closure.
1Assess one critical serviceConnect its assets and validate real exposure with evidence.
2Demonstrate the governed workflowAssign decision owners, authorise action and verify closure independently.
3Agree the enterprise rolloutExtend service by service, with the evidence and policy you have seen work.