Standards and evidence scope
See how DNN Defender uses NIST, OWASP and CVSS in reports, the evidence behind each mapping, and the boundary between an assessment aid and a formal certification.
Not rated yet
DNN Defender reports operational evidence in familiar security frameworks so administrators can
prioritize work and explain it consistently. A report must state the observation period, DNN and
Defender versions, enabled mode, source freshness, missing evidence, and the finding's actual
outcome. Framework alignment does not certify the site or its owner.
| Reference |
Use in DNN Defender |
Evidence to include |
Limit |
| NIST CSF 2.0 |
Organize posture and control capability |
WAF mode, scan/FIM health, open findings, response actions |
A module report is not an organizational CSF assessment or certification |
| NIST SP 800-61 Rev. 3 |
Structure incident preparation, detection, response and recovery |
UTC timeline, scope, containment, recovery validation and owner |
The module does not replace an incident response plan or forensic investigation |
| OWASP ASVS 5.0 and OWASP Top 10 |
Classify web-application controls and failure modes |
Endpoint, authorization, upload, logging and configuration evidence |
A scanner finding is not an ASVS verification certificate |
| FIRST CVSS 4.0 |
Quote authoritative vulnerability severity where published |
Official CVE/GHSA source and vector, affected range and fixed version |
CVSS severity is not the WAF threat score of an ordinary request |
Every advisory row separates version exposure, request evidence, current control state
and actual outcome. A vulnerable DNN version does not prove that the site was attacked. An
observed WAF event does not mean the request was blocked. A FIM hash match establishes integrity
against an approved baseline, not that the baseline was malware-free. A report that lacks a scan,
runtime observation, or recovery check must mark that dimension unverified.
Use the report as an evidence-backed operational assessment. Organizational compliance, a full
penetration test, eradication of an old compromise, and certification require additional work and
independent scope.
Was this page helpful?