EUVIMEDEuropean Health Evidence
Uhr 7/7Sources Journal Tree
Easy Demo

Lokaler Crossref-Datenbestand · journal-article

A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity

Carl Anderson

Information · 2026

Vollständiger Abstract

Worum geht es in dieser Arbeit?

Recent industry reporting indicates that meantime to exploit has become negative in several observed datasets, implying that exploitation may occur before patch availability for some classes of vulnerabilities. Adversarial use of artificial intelligence (AI) is a documented accelerant of this trend. This paper addresses the operational problem that follows in healthcare cybersecurity: the volume and velocity of vulnerability disclosure exceed human analytic capacity, which leads practitioners to under-prioritize, or defer entirely, individual Common Vulnerabilities and Exposures (CVEs) at precisely the moment their risk is rising. The study develops and evaluates a purposeful information technology artifact intended to resolve this problem within a mid-sized United States healthcare system. The artifact is a three-application automated CVE intelligence, prioritization, and remediation-tracking pipeline implemented in Microsoft Azure Logic Apps, integrating the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities (KEV) catalog, the Microsoft Security Response Center (MSRC) CVRF API, Microsoft Defender, Claroty xDome, Microsoft Security Copilot, and ServiceNow, and operationalizing the four risk factors codified in CISA Binding Operational Directive (BOD) 26-04. In naturalistic operations across six CISA Weekly Vulnerability Summary bulletins, the artifact processed 12,855 unique CVE references and reduced them to 1640 environment-relevant findings, an 87.2 percent exposure-first reduction, before expensive per-CVE enrichment and ticketing. The findings indicate that governed automation demonstrably increases CVE coverage, reduces low-value enrichment volume, and produces a deterministic, BOD 26-04-conformant prioritization that is fully traceable in the SharePoint tracker, where every assigned tier is reconstructable from its KEV, ransomware, xDome-exploited, EPSS, CVSS, and exposure inputs. Because no controlled before-and-after time-and-motion study was conducted and no independent ground-truth exploitation labels were collected, three distinct outcomes remain future validation targets rather than demonstrated results: analyst productivity, comparative predictive prioritization accuracy against independent ground-truth exploitation outcomes, and remediation speed. The contribution reported here is therefore operational scale, coverage, and auditable prioritization traceability, not measured improvement in analyst decision-making or patient-safety outcomes.

Bibliografischer Nachweis

Publikationsdaten

Autor:innen
Carl Anderson
Quelle
Information
Publikation
2026-01-01
Band / Ausgabe
Nicht angegeben
Seiten
Nicht angegeben
ISSN / ISBN
2078-2489
Zitationen
0 laut Crossref
Referenzen
0 hinterlegt

Zitieren

Zitierfähiger Nachweis

Carl Anderson (2026). A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity. Information. https://doi.org/10.3390/info17090846
RIS BibTeX CSL-JSON

Kontext

Themen, Förderung und Nutzung

Lizenzhinweise: Lizenz 1