Once Labor Day passes, I always get a little sad knowing that summer is coming to an end. Goodbye extended sunshine, pool days, and sundress weather. As the daylight hours start to shorten, the one bright side is getting to say hello to football again.
Since September is my month to push out some content, I wanted to do something football-related to mark the start of the regular season and continue the FedRAMP and football theme from my last blog. Sadly, I’m not in any fantasy football leagues this year. I have been spending time getting familiar with the FedRAMP 20x rules so I can help clients that need to make the transition. While going through them, I realized that some of the Vulnerability Evaluation and Reporting (VER) requirements have pretty good parallels to football.
Finding a weakness in the offense is only part of it. The defense still has to figure out if that weakness can be exploited. Maybe there’s a mismatch. Maybe there’s a path into the backfield. Maybe the defense is showing pressure, but you don’t know whether it’s actually coming. And even if they can make the play, what happens if they do?
The same idea applies when evaluating vulnerabilities. Finding a vulnerability is important, but the finding alone doesn’t tell you everything you need to know. You have to look at it in the context of your environment. Is it likely exploitable? Is it internet-reachable? Do you have evidence showing exploitation can’t be automated? And what is the impact to government customers if it’s successfully exploited?
There are multiple requirements under VER, including requirements for both evaluating and reporting vulnerabilities, but for this post I’m focusing on four of the required evaluations that I think work especially well with football.
Can They Take Advantage of the Weakness?
Let’s say there’s a weakness in the protection and Aaron Donald is lined up in a position to potentially take advantage of it. The three-time NFL Defensive Player of the Year is back from retirement and looking to wreak havoc on offensive lines again. A quick look at his social media and you can see that he still isn’t taking any days off from the gym in the last two years since retirement. He casually does chest presses with 150-pound dumbbells in each hand, so I can only imagine what it feels like to get tackled by him. Nobody wants that. If he managed to get through the line and was coming right at us, we’d probably all sound a little like Geno Smith yelling, “Oh my God,” in the viral mic’d-up clip.
The weakness alone doesn’t tell you whether the defense can actually exploit it. Maybe there’s help built into the protection. Maybe the offense double-teams Donald or a tight end stays in to help block. Or maybe Donald has exactly the matchup he’s looking for. Whether he can realistically take advantage of that weakness depends on what’s happening around it.
That’s also the idea behind VER-EVA-ELX, Evaluate Exploitability. FedRAMP requires providers to evaluate vulnerabilities in the context of their cloud service offering and determine whether they’re likely exploitable. Just because a vulnerability exists doesn’t mean exploitation is likely. There may be circumstances required to exploit it that just aren’t realistic based on how the environment actually operates.
Is There a Path?
Imagine a defensive tackle lined up inside with an offensive lineman directly in front of him. At first glance, there doesn’t seem to be a clear opening. But after the snap, the defensive end crashes inside and pulls the blocker with him. The defensive tackle loops around into the opening and suddenly has a way into the backfield. He didn’t start with a direct path, but that didn’t mean there wasn’t another way in.
That same idea of not needing a direct path can help explain VER-EVA-EIR, Evaluate Internet-Reachability. FedRAMP focuses on whether a vulnerability is internet-reachable, which isn’t necessarily the same thing as asking whether the vulnerable resource is directly accessible from the internet. Something could be deeper within the environment and still be internet-reachable. If something originating from the internet can make its way through other parts of the system and ultimately reach and trigger the vulnerability, there’s still a path to it. That’s really the question here. Not just, “Is this resource directly exposed to the internet?” but, “Can something from the internet still reach and trigger the vulnerability, even indirectly?”
Assume They’re Coming
Of course, you don’t always know where the pressure is actually coming from. Maybe Fred Warner walks toward the line and starts showing pressure. He could blitz. He could also drop back into coverage. Unless the offense has something telling them otherwise, leaving Warner unaccounted for and just hoping he drops back probably isn’t the best idea. You prepare for the possibility that he’s coming. FedRAMP takes a similar approach with VER-EVA-AIA, Assume It’s Automatable.
The football comparison isn’t really about automation itself. It’s about what you assume when you don’t have evidence telling you otherwise. FedRAMP requires providers to assume exploitation can be automated unless they have evidence proving otherwise. That doesn’t mean exploitation is definitely going to happen, just like Warner showing pressure doesn’t mean he’s definitely going to blitz. It just means you shouldn’t assume the easier scenario without something to back it up. Until you know otherwise, you account for the pressure.
What Happens If the Defense Makes the Play?
Figuring out whether the defense can take advantage of a weakness is only part of it. What happens if they actually do? We’ve already seen two interceptions in the first two games of the regular season that had very different consequences.
Early in the second quarter against the Rams, Brock Purdy underthrew a pass to George Kittle that was intercepted by Quentin Lake. It ended the 49ers’ drive, but San Francisco had plenty of time to recover. Purdy went on to ball out and throw three touchdown passes. The 49ers won 27–7.
The night before, the Patriots weren’t nearly as lucky. New England was down 13–10 and driving late in the fourth quarter against Seattle. With 24 seconds left, Drake Maye threw into the endzone and Josh Jobe intercepted the pass, essentially ending the game.
Both quarterbacks threw interceptions. But the impact on the game was very different. The potential impact matters too, which is the idea behind VER-EVA-EPA, Estimate Potential Agency Impact. FedRAMP requires providers to look at what successful exploitation could mean for government customers and assign a Potential Agency Impact N-rating, or PAIN. The ratings range from N1, where exploitation could have minimal customer effects, to N5, where it could have debilitating effects on more than one agency.
Obviously, football interceptions don’t translate directly into PAIN ratings. But I think these two plays are a good way to explain why the potential impact of exploitation needs to be looked at separately from whether exploitation is possible in the first place. Two vulnerabilities could both be exploitable but have very different potential impacts depending on what they affect, how serious the effects could be for customers, and how many agencies could be affected.
Putting It All Together
The evaluation requirements under VER add important context to a vulnerability finding. Is it likely exploitable? Is it reachable from the internet, even indirectly? What should you assume when you don’t have evidence telling you otherwise? And what could happen to federal customers if exploitation is successful? Looking at those things together gives you a better picture of the risk the vulnerability could pose to federal customers.
NorthWatch, 38North’s compliance operations platform, has a VDR/VER module that ingests scanner output and evaluates vulnerabilities in the security context of each CSP’s environment. It uses that context to calculate PAIN ratings and applicable response deadlines, track vulnerability status, and support VDR/VER reporting.
Whether you’re reading a defense or evaluating vulnerabilities in a cloud environment, finding the weakness is only the beginning. What matters is what that weakness actually means in context.



