Priority bands
Priority bands turn RPS into workflow language. They are policy-neutral: DevSecure tells you the external priority; your organization maps that to its own internal policy.
critical_priority
- Meaning
- Confirmed or strongly indicated external risk.
- Typical signal pattern
- CISA KEV listing, very high EPSS percentile, severe CVSS impact, public exploit evidence, or strong patch/exposure signals.
- Recommended action
- Review against your internal critical-priority process.
high_priority
- Meaning
- High exploitation likelihood or strong severity evidence.
- Typical signal pattern
- High EPSS, high CVSS, credible exploit reporting, broad software exposure, or strong advisory coverage.
- Recommended action
- Review promptly and verify whether the affected component is exposed in your environment.
medium_priority
- Meaning
- Meaningful risk, but with less immediate signal alignment.
- Typical signal pattern
- Moderate EPSS, relevant CVSS impact, partial evidence coverage, or uncertainty about exploitability and exposure.
- Recommended action
- Validate applicability, track ownership, and monitor for signal movement.
low_priority
- Meaning
- Lower external priority.
- Typical signal pattern
- Lower EPSS, no KEV listing, limited exploit evidence, or low practical exposure based on available signals.
- Recommended action
- Track through the normal backlog and revisit if signals change.
informational
- Meaning
- Useful context without immediate prioritisation pressure.
- Typical signal pattern
- Contextual source data, low-risk advisory metadata, or evidence that helps explain ranking without raising the band.
- Recommended action
- Keep as reference material for audit, reporting, or future review.
unknown
- Meaning
- Not enough information, unsupported input, or CVE not found.
- Typical signal pattern
- Missing source records, sparse enrichment, or a CVE identifier that DevSecure Intelligence cannot resolve.
- Recommended action
- Verify source data manually before using the item in a workflow.
The recommended_next_step field gives a workflow hint such as review_against_internal_sla, verify_applicability, monitor, or no_action_recommended.
For full response fields, see API Reference: PrioritizeRankedItem.