Abstract. In this paper our original methodology of applying ontologybased logic into decision support system for security management in heterogeneous networks is presented. Such decision support approach is used by the off-network layer of security and resiliency mechanisms developed in the INTERSECTION Project. Decision support application uses knowledge about networks vulnerabilities to support off-network operator to manage and control in-networks components such as probes, intrusion detection systems, Complex Event Processor, Reaction and Remediation. Hereby, both IV O (Intersection Vulnerability Ontology) as well as PIV OT - decision support system based on the vulnerability ontology are presented.