Vulnerability
Definition
A weakness in an asset or in a control protecting that asset, which a threat could exploit to cause harm. Examples: an unpatched operating system, a server room without fire suppression, a database accessible without authentication, a process that lacks segregation of duties.
- Field
- Information security, risk management
- Definition
- A weakness in an asset or its control that a threat could exploit
- Examples
- Unpatched OS, missing fire suppression, unauthenticated database access
- Relationship
- Risk arises from threat, vulnerability, and asset value together
- Reference catalogue
- CVE and NVD track publicly known software vulnerabilities
Common questions
How does a vulnerability differ from a threat in risk terminology?+
A threat is the potential source of harm, such as an attacker or a fire, while a vulnerability is the weakness that lets the threat cause damage. Risk exists only where a threat can act on a vulnerability affecting an asset of value.
Why do auditors classify a missing segregation-of-duties control as a vulnerability rather than just a policy gap?+
Because it creates a concrete exploitable weakness, a single employee with both initiation and approval authority over a transaction, that a threat such as an insider committing fraud can act on directly, not merely a documentation shortfall.
Can a vulnerability exist with zero associated risk?+
In principle yes, if no realistic threat exists to exploit it or the asset has no value worth attacking, though in practice most vulnerabilities are treated as carrying at least residual risk because threat landscapes change.
Related terms
- Threat
- A potential cause of an unwanted incident that could harm an asset. Threats may be natural (flood, fire), environmental (power failure), human...
- Asset Inventory (Asset Register)
- A structured record listing every information asset in scope, together with its owner, custodian, physical or logical location, classification level, criticality rating,...
- Asset Owner
- The person or role accountable for ensuring an asset is appropriately classified, protected, and reviewed. The owner is typically a business manager...
- Availability
- The property that systems and data are accessible to authorised users when needed. Protected by redundancy, backup, failover, and incident response capabilities....
- Classification Tier
- A label assigned to an asset or data type indicating its sensitivity and the handling rules that apply. Common tiers are Public,...
- Confidentiality
- The property that information is not disclosed to unauthorised individuals, processes, or devices. Protected by access controls, encryption, and need-to-know policies. Breached...
- Information Asset
- Anything that has value to the organisation by virtue of the information it contains or the information function it performs. Includes data,...
- Integrity
- The property that information is accurate, complete, and has not been modified without authorisation. Protected by cryptographic hashing, digital signatures, and change...
- Non-Repudiation
- The property that a party cannot deny having performed an action. Provided by digital signatures, timestamped audit logs, and certified delivery receipts....
Explained in these topics
- The CIA Triad and Security FundamentalsA weakness in a system, process, or control that a threat could exploit. Vulnerabilities arise from software bugs, misconfiguration, procedural gaps, or physic...
- Risk Identification and Asset Classification