The VPR framework is a much more *modern framework* in vulnerability management - developed by Tenable, an industry solutions provider for vulnerability management. This framework is considered to be risk-driven; meaning that vulnerabilities are given a **score with a heavy focus on the risk** a vulnerability poses to the organisation itself, rather than factors such as impact (like with [[Common Vulnerability Scoring System|CVSS]]).
Unlike CVSS, VPR scoring takes into account the *relevancy of a vulnerability*. For example, no risk is considered regarding a vulnerability if that vulnerability does not apply to the organisation (i.e. they do not use the software that is vulnerable). VPR is also considerably **dynamic in its scoring**, where the risk that a vulnerability may pose can change almost daily as it ages.