Moving Beyond Severity Scores: A VEX-Driven Approach to Safety-Critical System Risk

Moving Beyond Severity Scores: A VEX-Driven Approach to Safety-Critical System Risk
Author: Devashri Datta
Date Published: 26 August 2026
Read Time: 7 minutes

Software supply chain security is becoming more demanding in practice. Organizations are increasingly expected to produce software bills of materials (SBOMs) and Vulnerability Exploitability eXchange (VEX) documents, yet many still struggle to translate these artifacts into clear, defensible risk decisions...

 

Members, login to keep reading.

Not a member but want to read more?
Explore ISACA member benefits today.

Additional resources