Addressing Unique Vulnerabilities in Biometric Technologies
Dr Ted Dunstone CEO BixeLab
ted@bixelab.com
CVSS impact metrics give equal weight to confidentiality, integrity, and availability, overlooking the unique risk priorities of organizations and the true impact a vulnerability might have,
analysis suggests that around 10% of vulnerabilities are potentially being underrated
JPMorganChase
This relies on standard metrics that do not fully capture the unique aspects of biometric vulnerabilities, such as spoofing attacks or demographic biases
Bias Impact: Evaluate vulnerabilities' effects on specific demographic groups, leading to unequal security.
Utilise Biometric-Specific Metrics:
Enhance Environmental Metrics:
Standardize Reporting of Biometric Vulnerabilities:
1. Attack Vector (AV): Physical (P)
2. Attack Complexity (AC): Low (L)
3. Privileges Required (PR): None (N)
4. User Interaction (UI): Required (R)
5. Scope (S): Unchanged (U)
6. Confidentiality Impact (C): None (N)
7. Integrity Impact (I): High (H)
8. Availability Impact (A): None (N)
Risk Assessment:
System Design:
Policy Development:
Training and Awareness: