Uploaded May 2026 | Updated September 2026, 1 hour ago
Jerry Gamblin (Cisco, US), Jay Jacobs (Empirical Security, US)
Anyone who has tried to ingest vulnerability data knows that it’s often incomplete, inconsistent, and rather difficult to operationalize. With the CVE program entering its “data quality” era, we need to begin efforts to define and measure data quality. In this talk I will introduce a Data Quality Assessment Framework (DQAF - pronounced “decaf”) for CVE and vulnerability data that draws on established information-quality research, but is tailored to the realities of CNAs, NVD, vendors, and downstream consumers. The framework separates the quality of the record design (what the schema can express) from the quality of record instances (how well CNAs actually populate those fields), and scores multiple dimensions such as completeness, accuracy, consistency and machine-usability.
---
Jerry Gamblin is a prominent voice in the vulnerability management community and the creator of RogoLabs.net, an innovation lab for security data science. He serves on the EPSS SIG and contributes to various CVE Program working groups. An international speaker and researcher, Jerry’s work focuses on the practical application of data science to solve complex vulnerability challenges.
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS) and co-chair of the EPSS special interest group at FIRST. He also serves as the chair of the Consumer Working Group within the CVE program. Prior to his current roles, he was the Chief Data Scientist at Cyentia for several years and produced dozens of data-driven industry reports. He also served as the lead data scientist at Verizon working on the Data Breach Investigations report from 2010-2015 and he also served on the board of directors for the Society of Information Risks Analysts (SIRA) where he co-founded the non-profit dedicated to advancing risk management practices.
Jerry Gamblin (Cisco, US), Jay Jacobs (Empirical Security, US)
Anyone who has tried to ingest vulnerability data knows that it’s often incomplete, inconsistent, and rather difficult to operationalize. With the CVE program entering its “data quality” era, we need to begin efforts to define and measure data quality. In this talk I will introduce a Data Quality Assessment Framework (DQAF - pronounced “decaf”) for CVE and vulnerability data that draws on established information-quality research, but is tailored to the realities of CNAs, NVD, vendors, and downstream consumers. The framework separates the quality of the record design (what the schema can express) from the quality of record instances (how well CNAs actually populate those fields), and scores multiple dimensions such as completeness, accuracy, consistency and machine-usability.
---
Jerry Gamblin is a prominent voice in the vulnerability management community and the creator of RogoLabs.net, an innovation lab for security data science. He serves on the EPSS SIG and contributes to various CVE Program working groups. An international speaker and researcher, Jerry’s work focuses on the practical application of data science to solve complex vulnerability challenges.
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS) and co-chair of the EPSS special interest group at FIRST. He also serves as the chair of the Consumer Working Group within the CVE program. Prior to his current roles, he was the Chief Data Scientist at Cyentia for several years and produced dozens of data-driven industry reports. He also served as the lead data scientist at Verizon working on the Data Breach Investigations report from 2010-2015 and he also served on the board of directors for the Society of Information Risks Analysts (SIRA) where he co-founded the non-profit dedicated to advancing risk management practices.










