Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions discover-snyk/getting-started/glossary.md
Original file line number Diff line number Diff line change
Expand Up @@ -434,7 +434,7 @@ Use Snyk PR Checks to prevent new security issues from entering your codebase by

### Priority Score

Snyk scores issues, including vulnerabilities and licenses for Open Source, to help prioritize the treatment of each one. Scores are based on multiple factors, including the CVSS score, and range from 0 (low) to 1000 (high). See [Priority Score](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/priority-score).
A score from 0 to 1,000 that ranks how urgently you need to fix an issue, where a higher score means a more urgent issue. Snyk calculates it from multiple factors, including severity, exploit maturity, reachability, and the availability of a fix. It applies to both vulnerabilities and license issues. Unlike [Severity](glossary.md#severity), the Priority Score is a rank with no defined bands, so a score does not correspond to Critical, High, Medium, or Low. Priority Score applies to Snyk Code and Snyk IaC issues, and to Snyk Open Source and Snyk Container issues when [Risk Score](glossary.md#risk-score) is not enabled. Visit [Priority Score](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/priority-score) and [Priority Score vs Risk Score](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/priority-score-vs-risk-score).

### Project

Expand Down Expand Up @@ -490,9 +490,9 @@ A repository asset is created by discovering the repositories directly in the SC

A cloud infrastructure entity such as an AWS S3 bucket, Identity and Access Management (IAM) role, or Virtual Private Cloud (VPC) flow log.

### Risk score
### Risk Score

A value assigned to an issue, ranging from 0 to 1,000, representing the risk imposed on your environment.
A score from 0 to 1,000 that represents the risk an issue imposes on your environment, based on the potential impact and the likelihood of exploitation. A higher score means greater risk. Like the [Priority Score](glossary.md#priority-score), the Risk Score is a rank with no defined bands, so a score does not correspond to a severity level. Risk Score is in Early Access for Snyk Open Source and Snyk Container, applies to vulnerabilities but not to license issues, and you enable it through Snyk Preview. Where it applies, the Risk Score replaces the Priority Score after the next retest. Visit [Risk Score](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/risk-score) and [Priority Score vs Risk Score](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/priority-score-vs-risk-score).

### Rule

Expand Down Expand Up @@ -562,7 +562,7 @@ A non-human identity used to authenticate automated processes, such as CI/CD pip

### Severity

A severity level is applied to a vulnerability or a license issue, to indicate the risk for that item in an application. See [Severity levels](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/severity-levels).
A level indicating the assessed risk of an issue: Critical, High, Medium, or Low. Each level maps to a defined score range. Snyk determines severity for vulnerabilities from the CVSS Base Score, and for IaC+ misconfigurations from the CCSS Base Score. Snyk Code uses High, Medium, and Low, and does not natively assign Critical. License issues use High, Medium, Low, and None, set by your license policy rather than by a CVSS score. Severity is one of the factors that feed the [Priority Score](glossary.md#priority-score) and the [Risk Score](glossary.md#risk-score), which rank issues but do not map to severity levels. Visit [Severity levels](https://docs.snyk.io/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/severity-levels).

### Skill (Snyk Studio)

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -145,15 +145,15 @@ Some tools use only the single factor of severity to prioritize issues, but this

You can prioritize at the Project level when looking at a specific Project. Enterprise customers can prioritize across all Projects.

Snyk Priority Score and Risk Score rank the [severity](severity-levels.md) of an issue and the urgency of fixing it. For details, see [Priority Score vs Risk Score](priority-score-vs-risk-score.md), [Priority Score](priority-score.md), and [Risk Score](risk-score.md).
Snyk Priority Score and Risk Score rank issues by how urgently you need to fix them. [Severity](severity-levels.md) is a separate label indicating assessed risk, and is one of the factors that feed the scores. For details, visit [Priority Score vs Risk Score](priority-score-vs-risk-score.md), [Priority Score](priority-score.md), and [Risk Score](risk-score.md).

You can [ignore issues](ignore-issues/) and [triage issues](vulnerable-conditions.md) to establish your issue management strategy.

[View exploits](view-exploits.md) to see how vulnerabilities can be taken advantage of. You can then start evaluating and prioritizing vulnerabilities using guidance from the [Snyk Priority Score](priority-score.md) for each issue.

Consider [Malicious packages](malicious-packages.md) and how to address them in your Projects.

You can set up [reachable vulnerability analysis ](reachability-analysis.md)to identify vulnerabilities with a path to your code. This helps you asse are calculated as part of the priority score.
You can set up [reachable vulnerability analysis](reachability-analysis.md) to identify vulnerabilities with a path to your code. Reachability is one of the factors calculated as part of the Priority Score.

[Vulnerabilities with Social Trends](vulnerabilities-with-social-trends.md) are calculated as part of the Priority Score.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,9 @@ nav_context: agnostic

The Snyk Risk score and Priority score are keys to security management. Both types of score help Organizations handle current threats and prepare for future vulnerabilities, leading to a more robust security framework.

The Priority and Risk Scores rank the issues and the urgency of fixing them. Both scores provide a number between 1 and 1000, where 1 means low severity and 1000 means high severity. Snyk uses these numbers to indicate the urgency of remediating a vulnerability.
The Priority Score and the Risk Score rank issues by how urgently you need to fix them. Both run from 0 to 1,000, where a higher number means a more urgent issue.

Both scores are ranks, not severity bands. A score orders one issue against another. It does not correspond to a [severity level](severity-levels.md), and Snyk does not define a score range for Critical, High, Medium, or Low. An issue can therefore carry a Critical severity and still rank below a High severity issue that has a mature exploit, is reachable in your code, or has a fix available.

{% hint style="info" %}
Risk score assesses the potential impact of vulnerabilities, prioritizing those with severe consequences.
Expand All @@ -32,33 +34,41 @@ You can use the following table to decide which type of score works best for you
| -------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ |
| **Availability** | <ul><li>General availability</li></ul> | <ul><li>Early access</li></ul> |
| **Applicability** | <ul><li>Vulnerability issues</li><li>License issues</li></ul> | <ul><li>Vulnerability issues</li></ul> |
| **Snyk coverage** | <ul><li>Snyk Open Source</li><li>Snyk Code</li><li>Snyk Container</li></ul> | <ul><li>Snyk Open Source</li><li>Snyk Container</li></ul> |
| **Coverage** | <ul><li>Project view from Snyk Web UI</li><li>Reports view from Snyk Web UI</li><li>Snyk API</li></ul> | <ul><li>Project view from Snyk Web UI</li><li>Reports view from Snyk Web UI</li><li>Snyk API</li></ul> |
| **Integrations** | <ul><li>Kubernetes</li></ul> | NA |
| **Snyk coverage** | <ul><li>Snyk Open Source</li><li>Snyk Code</li><li>Snyk Container</li><li>Snyk IaC</li></ul> | <ul><li>Snyk Open Source</li><li>Snyk Container</li></ul> |
| **Where it appears** | <ul><li>Project view from Snyk Web UI</li><li>Reports view from Snyk Web UI</li><li>Snyk API</li></ul> | <ul><li>Project view from Snyk Web UI</li><li>Reports view from Snyk Web UI</li><li>Snyk API</li></ul> |
| **Integrations** | <ul><li>Kubernetes</li></ul> | Not supported |
| **Assessment model** | <ul><li>Impact</li><li>Actionability</li></ul> | <ul><li>Impact</li><li>Likelihood</li></ul> |

## Can I map scores to priority levels?

No. Snyk does not publish a mapping from Priority Score or Risk Score values to severity levels. Use a score to order issues against each other, and use the [severity level](severity-levels.md) when you need a named band.

Snyk applies one score threshold operationally. Snyk raises automatic fix pull requests and backlog pull requests for issues that meet or exceed the **Score** threshold set for your Organization, which defaults to 700. This threshold is a configurable automation setting, not a severity band. For more information, visit [Enable automatic fix PRs](../../scan-with-snyk/pull-requests/snyk-pull-or-merge-requests/enable-automatic-fix-prs.md).

If you set your own threshold, review it periodically. A score changes when its contributing factors change, and factors such as the Exploit Prediction Scoring System (EPSS) can change daily.

## When and why to use the Priority Score

The Priority Score tool helps manage vulnerabilities by prioritizing the most urgent issues based on exploitability, ease of mitigation, and potential for exploitation. Use it to first address the critical vulnerabilities and if you want to prioritize the Snyk Code issues (since Risk score is not available for Snyk Code).

* Time-Sensitive Projects - When you are working on Projects with tight deadlines, it is important to address security concerns right away.
* Initial Triage - Priority score quickly identifies and mitigates immediate threats from multiple vulnerabilities.
* Resource Allocation - Teams can allocate security resources to promptly address urgent risks.
* Time-sensitive Projects: when you are working on Projects with tight deadlines, it is important to address security concerns right away.
* Initial triage: Priority Score quickly identifies and mitigates immediate threats from multiple vulnerabilities.
* Resource allocation: teams can allocate security resources to promptly address urgent risks.

Priority Score helps your team quickly prioritize and address urgent Project vulnerabilities to reduce the risk of attacks.

The assessment model used by the Priority score focuses on two factors:

* Impact - Snyk analyses the possibility of a fix to address multiple vulnerabilities. The Priority score increases exponentially with the number of vulnerabilities addressed by a fix.
* Actionability - Snyk analyses how easy it is to remediate a vulnerability.
* Impact - Snyk analyzes the possibility of a fix to address multiple vulnerabilities. The Priority score increases exponentially with the number of vulnerabilities addressed by a fix.
* Actionability - Snyk analyzes how easy it is to remediate a vulnerability.

## When and why to use the Risk score

The Risk Score assesses security threats based on their potential impact and likelihood, allowing for more nuanced vulnerability management.

* Comprehensive Risk Assessment - Use the Risk Score to assess both exploitability and potential damage when evaluating vulnerabilities.
* Long-Term Security Planning - Identifies and prioritizes potential risks, assisting in planning future security infrastructure improvements.
* Stakeholder Communication - The Risk Score is a metric that communicates security risks to non-technical stakeholders, aiding informed decisions on security investments.
* Comprehensive risk assessment: use the Risk Score to assess both exploitability and potential damage when evaluating vulnerabilities.
* Long-term security planning: identifies and prioritizes potential risks, assisting in planning future security infrastructure improvements.
* Stakeholder communication: the Risk Score is a metric that communicates security risks to non-technical stakeholders, aiding informed decisions on security investments.

The Risk Score helps balance immediate threat mitigation with long-term security posture, creating a comprehensive approach to managing vulnerabilities.

Expand All @@ -84,13 +94,13 @@ Scan your source code and apply the following filters to your list of found vuln

* Issue type: Vulnerabilities
* Severity: Critical
* Fixed in available: Yes
* Fixed availability: Yes
* Computed fixability: Fixable
* Exploit maturity: Mature

### Risk score use case

Let's assume that you are integrating a new third-party library into an existing application, and after a scan, you discover that the library has several vulnerabilities. Filter the vulnerabilities using the Risk score to determine which vulnerabilities pose the greatest threat.
Assume you are integrating a new third-party library into an existing application, and after a scan, you discover that the library has several vulnerabilities. Filter the vulnerabilities using the Risk score to determine which vulnerabilities pose the greatest threat.

Remember that Risk score must first be enabled from the [Snyk Preview](https://app.gitbook.com/s/IgtgtomLQ2TUgSKOMSAm/snyk-hierarchy/snyk-preview) screen and can only be applied to Snyk Open Source and Snyk Container.

Expand All @@ -102,7 +112,7 @@ Scan your source code and apply the following filters to your list of found vuln
* Computed fixability: Fixable
* Exploit maturity: Mature

After you apply the filters, you have a list of the most critical vulnerabilities that need to be fixed before safely integrating the third-party library with your application. Fixing these critical issues you are preventing a potential security breach and are also safeguarding the integrity of your application.
After you apply the filters, you have a list of the most critical vulnerabilities that need to be fixed before safely integrating the third-party library with your application. By fixing these critical issues, you prevent a potential security breach and safeguard the integrity of your application.

Given the high severity and the mature exploit, the risk score for this issue would be elevated, indicating an urgent need for action. In this scenario, organizations should prioritize patching this vulnerability immediately due to the high risk of exploitation.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,11 @@ The Snyk Priority Score is determined based on a number of industry-standard cri
Snyk does not use the CVSS score alone to determine priority; other factors are also considered.
{% endhint %}

See [Calculation of Priority Score](priority-score.md#calculation-of-priority-score) for detailed information on how scores are determined.
For detailed information on how Snyk determines scores, visit [Calculation of Priority Score](#calculation-of-priority-score).

You can view Priority Scores in Projects views, Reports, and the API.

There are no settings related to the Priority Score; they are read-only and cannot be hidden. An example follows of Priority Scores displayed in a Project view.
The Priority Score is read-only. You cannot hide it or change how Snyk calculates it.

## View Priority Score for an issue

Expand All @@ -37,7 +37,7 @@ The API endpoint [Get list of latest issues](https://app.gitbook.com/s/IEEjSXQQu

For each issue, Snyk processes and weighs several factors in a proprietary algorithm to produce the score for that issue. These factors include the following:

* [Severity levels](severity-levels.md): calculated using CVSS framework v3.1 scores for an issue.
* [Severity levels](severity-levels.md): based on the CVSS Base Score for the issue. Snyk uses CVSS v4.0 where a v4.0 vector is available, and CVSS v3.1 for vulnerabilities published before Snyk adopted v4.0.
* [Exploit maturity](https://snyk.io/blog/whats-so-wild-about-exploits-in-the-wild-and-how-can-we-prioritize-accordingly/): determined by the industry-leading Snyk security team using manual and automated methods to track which vulnerabilities are exploitable and to what extent. This applies to Snyk Open Source.
* [Reachability](reachability-analysis.md) (the extent to which vulnerabilities are reachable from the code): determined by looking at the code paths called within a Project. This applies to Snyk Open Source.
* [Fixability](../../scan-with-snyk/snyk-open-source/manage-vulnerabilities/vulnerability-fix-types.md) (availability of a fix): defined as having a safer version to upgrade to or a Snyk patch available. For vulnerabilities with neither, developers must either fix the code themselves or use an alternative package. Thus, vulnerabilities with fixes are given a higher Priority Score. This applies to Snyk Open Source.
Expand Down
Loading
Loading