CVE Decaf: Brewing Better and More Actionable Data Quality @FIRSTdotorg
CVE Decaf: Brewing Better and More Actionable Data Quality  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Jerry Gamblin (Cisco, US), Jay Jacobs (Empirical Security, US)

Anyone who has tried to ingest vulnerability data knows that it’s often incomplete, inconsistent, and rather difficult to operationalize. With the CVE program entering its “data quality” era, we need to begin efforts to define and measure data quality. In this talk I will introduce a Data Quality Assessment Framework (DQAF - pronounced “decaf”) for CVE and vulnerability data that draws on established information-quality research, but is tailored to the realities of CNAs, NVD, vendors, and downstream consumers. The framework separates the quality of the record design (what the schema can express) from the quality of record instances (how well CNAs actually populate those fields), and scores multiple dimensions such as completeness, accuracy, consistency and machine-usability.

---

Jerry Gamblin is a prominent voice in the vulnerability management community and the creator of RogoLabs.net, an innovation lab for security data science. He serves on the EPSS SIG and contributes to various CVE Program working groups. An international speaker and researcher, Jerry’s work focuses on the practical application of data science to solve complex vulnerability challenges.

Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS) and co-chair of the EPSS special interest group at FIRST. He also serves as the chair of the Consumer Working Group within the CVE program. Prior to his current roles, he was the Chief Data Scientist at Cyentia for several years and produced dozens of data-driven industry reports. He also served as the lead data scientist at Verizon working on the Data Breach Investigations report from 2010-2015 and he also served on the board of directors for the Society of Information Risks Analysts (SIRA) where he co-founded the non-profit dedicated to advancing risk management practices.
CVE Decaf: Brewing Better and More Actionable Data QualityLeveraging AI to Review and Strengthen Your Incident Response Plan: A Proof of ConceptWho Did It? Getting Started with Threat Actor ProfilingFIRSTCON26 Event RecapEpisode 59: Julie Agnes Sparks and Greg Foss, Datadog, FIRSTCON26 SpeakersHow Attackers Reconstruct You: Measuring Identity Exposure Across Four Attack SurfacesDealing With Uncertainty: Scenario Planning for Cybersecurity Decision-MakingEpisode 60: Mars Cheng, TXOne Networks Inc., FIRSTCON26 SpeakerThe Party Isnt Over: Uncovering Konfetys Novel Evil Twin Technique2026 FIRST CTI Conference - Day 2 Plenary Sessions - Live StreamImproving Security Across Nations with FIRST: Ken van Wyk, FIRST MemberTabletop Lessons from 3 Decades and 2 Continents
FIRST |

CVE Decaf: Brewing Better and More Actionable Data Quality

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER