What is security context?
Security context is the environmental and relational information—asset role, exposure, identity privilege, business impact, threat relevance—that determines whether a finding actually matters.
What is security context?
Short answer
Security context is the environmental and relational information that determines whether a finding actually matters: asset role, exposure, identity privilege, business impact, control coverage, and active threat relevance.
Explanation
The same vulnerability identifier can be urgent on one asset and irrelevant on another. Context answers where, who, what is reachable, and what is already exploited in the wild—not just what CVE is it.
Without context, teams sort by generic severity and waste cycles on findings that are technically true but operationally low impact.
Common mistake
Equating CVSS with organizational risk. CVSS describes a vulnerability in isolation; context describes your environment.
Authority references
- Security Context —
KID-GLS-0003 - Canonical Data Model —
KID-ARC-0001(entities carrying context)
Related
- Understanding Security Context —
KID-CON-0006 - Context Matters More Than Severity —
KID-CON-0003