Documentation/Priority bands

Priority bands

Priority bands turn RPS into workflow language. They are policy-neutral: DevSecure tells you the external priority; your organization maps that to its own internal policy.

critical_priority

Meaning
Confirmed or strongly indicated external risk.
Typical signal pattern
CISA KEV listing, very high EPSS percentile, severe CVSS impact, public exploit evidence, or strong patch/exposure signals.
Recommended action
Review against your internal critical-priority process.

high_priority

Meaning
High exploitation likelihood or strong severity evidence.
Typical signal pattern
High EPSS, high CVSS, credible exploit reporting, broad software exposure, or strong advisory coverage.
Recommended action
Review promptly and verify whether the affected component is exposed in your environment.

medium_priority

Meaning
Meaningful risk, but with less immediate signal alignment.
Typical signal pattern
Moderate EPSS, relevant CVSS impact, partial evidence coverage, or uncertainty about exploitability and exposure.
Recommended action
Validate applicability, track ownership, and monitor for signal movement.

low_priority

Meaning
Lower external priority.
Typical signal pattern
Lower EPSS, no KEV listing, limited exploit evidence, or low practical exposure based on available signals.
Recommended action
Track through the normal backlog and revisit if signals change.

informational

Meaning
Useful context without immediate prioritisation pressure.
Typical signal pattern
Contextual source data, low-risk advisory metadata, or evidence that helps explain ranking without raising the band.
Recommended action
Keep as reference material for audit, reporting, or future review.

unknown

Meaning
Not enough information, unsupported input, or CVE not found.
Typical signal pattern
Missing source records, sparse enrichment, or a CVE identifier that DevSecure Intelligence cannot resolve.
Recommended action
Verify source data manually before using the item in a workflow.

The recommended_next_step field gives a workflow hint such as review_against_internal_sla, verify_applicability, monitor, or no_action_recommended.

For full response fields, see API Reference: PrioritizeRankedItem.