Relationship between Threats, Vulnerabilities, Assets, and Risks: Threats, vulnerabilities, assets, and risks are interrelated components of risk management. An asset is something of value to an organization. A threat is a potential event that could cause harm or damage to the asset. Vulnerability refers to the weaknesses in a system or process that could be exploited by threats. Finally, risk is the potential for loss or damage when a threat exploits a vulnerability. Therefore, risk arises from the combination of the asset’s vulnerabilities, the threats it faces, and the impact the realization of these threats would have on the organization.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D2: Information security risk management | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index