MRHS operates a hybrid cloud environment with on-prem hospital systems, clinical workstations, and AWS-hosted patient portals. A recent risk assessment identified seven active vulnerability classes across the infrastructure. Your mission: construct layered mitigation strategies for each threat, then build a data-driven remediation queue that balances CVSS severity, business impact, and exploitability.
Select a target environment, identify the active vulnerability class, then build a layered control stack by assigning Primary and Supporting mitigations. Your selections are evaluated against the Mitigation Selection Framework.
Score and rank 5 active CVEs using a weighted triage formula combining CVSS base score, exploitability (public exploit available?), and business impact (data sensitivity, system criticality). Drag to reorder your final priority queue.
| Vulnerability Class | Primary Mitigation | Supporting Mitigations |
|---|---|---|
| Unpatched OS/App CVE | Patching | Network isolation, compensating controls |
| Default credentials / insecure defaults | Hardening | MFA, network ACLs |
| SQL Injection / XSS | Input Validation | WAF, CSP, parameterized queries |
| Lateral movement after breach | Segmentation | Micro-seg, ZTNA, host-based firewall |
| Ransomware blast radius | Access Control / Least Privilege | Segmentation, immutable backups, EDR |
| Cloud misconfiguration | Cloud Hardening (CSPM) | IaC scanning, least-privilege IAM, audit logs |
| Malware / suspicious file | Isolation / Sandboxing | EDR behavioral detection, app whitelisting |
Your score will appear here after completing Module 1 and Module 2.