Setting expectations around rewards is important to avoid confusion down the disclosure process. By providing the environmental scores (correcting scores for Confidentiality, Integrity, and Availability) help correct the CVSS per asset. Some assets simply don't have access to any confidential information or can be offline for no reason without impact anything. This should be allowed to be reflected not to set the correct expectations, but also direct hackers to the interesting assets that they can hack.
This should be an optional field, as some attack surfaces are too big or unknown to correctly assess the environmental scores.
With the current format it might be slightly harder to add this field, but it could look something like this:
In-Scope: gratipay.com (CVSS:3.0/CR:L/IR:L/AR:L)
Setting expectations around rewards is important to avoid confusion down the disclosure process. By providing the environmental scores (correcting scores for Confidentiality, Integrity, and Availability) help correct the CVSS per asset. Some assets simply don't have access to any confidential information or can be offline for no reason without impact anything. This should be allowed to be reflected not to set the correct expectations, but also direct hackers to the interesting assets that they can hack.
This should be an optional field, as some attack surfaces are too big or unknown to correctly assess the environmental scores.
With the current format it might be slightly harder to add this field, but it could look something like this: