The Common Vulnerability Scoring System (CVSS) is what the organization should use to calculate the severity of the risk from using an old version of Apache Log4j software component. CVSS provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. Reference: CompTIA Cloud+ Study Guide (Exam CV0-004) - Chapter on Risk Management