The primary mission of the Microsoft Security Response Center (MSRC) is helping our customers operate their systems and networks securely. A major part of this mission involves evaluating customers' reports of suspected vulnerabilities in Microsoft products and, when necessary, ensuring that patches and security bulletins that respond to bona fide reports are produced and disseminated. A previous essay titled "A Tour of the MSRC" describes how we execute this mission on a day-to-day basis.
This document introduces our security bulletin severity rating system. This system is intended to help our customers decide which bulletins release patches that they should apply to avoid impact under their particular circumstances. Inevitably, there will be subjectivity and judgment reflected in any such system. However, both large and small customers have encouraged us to add this sort of information to our bulletins to help them assess risk, and we believe that we should respond to those requests.
|