4 Severity Categories Explained

CISO Governance and Organizational Resilience · 4:25

Listen on 93

Lyrics

[Verse 1]
When vulnerabilities appear in your system's defense
DISA STIG has categories to make perfect sense
Four levels of severity from high down to low
Each one tells you how fast your remediation should go

Cat One is the danger zone, immediate and real
Direct threats to your data that hackers can steal
Confidentiality, integrity, availability too
Thirty days or less is all the time that you have to get through

[Chorus]
Cat One, Cat Two, Cat Three, that's how we grade the risk
High, Medium, Low severity, remember this quick list
Thirty, ninety, one-eighty days to make the fixes right
DISA STIG severity keeps your systems safe and tight

[Verse 2]
Category Two is medium, potential for harm
Could degrade your security and sound the alarm
When combined with other flaws it opens the door
Unauthorized access is what we're watching for

Ninety days to patch it up, that's your window frame
Defense-in-depth protection is the name of the game

[Chorus]
Cat One, Cat Two, Cat Three, that's how we grade the risk
High, Medium, Low severity, remember this quick list
Thirty, ninety, one-eighty days to make the fixes right
DISA STIG severity keeps your systems safe and tight

[Verse 3]
Category Three is low risk but still needs attention
Degrades your defenses and audit prevention
Increases attack surface though not on its own
One hundred eighty days before the issue's outgrown

[Bridge]
From immediate threats to longer-term care
Each category tells you how much time you can spare
High, Medium, Low - the impact's clear to see
Thirty, ninety, one-eighty - that's your remedy

[Chorus]
Cat One, Cat Two, Cat Three, that's how we grade the risk
High, Medium, Low severity, remember this quick list
Thirty, ninety, one-eighty days to make the fixes right
DISA STIG severity keeps your systems safe and tight

[Outro]
Four categories strong, keeping networks secure
DISA STIG severity makes your timeline sure

← Exercise 5.1: Insurance Coverage Audit | 3 Key Terminology →