Generated on 2014/06/19 at 04:57:59 AM


Type List | Item List

Dictionary / Knowledge Item Item: Distinguish Risk, Threat, Vulnerability



Acronym or Abbreviation
Alias or Synonym
Key Words
Description (HTML)
  • Asset – People, property, and information.
    An asset is what we’re trying to protect.
  • Threat – Anything that can exploit a vulnerability, intentionally or accidentally, and obtain, damage, or destroy an asset.
    A threat is what we’re trying to protect against.
  • Vulnerability – Weaknesses or gaps in a security program that can be exploited by threats to gain unauthorized access to an asset.
    A vulnerability is a weakness or gap in our protection efforts.
  • Risk – The potential for loss, damage or destruction of an asset as a result of a threat exploiting a vulnerability.
    Risk is the intersection of assets, threats, and vulnerabilities.

    Why is it important to understand the difference between these terms? If you don’t understand the difference, you’ll never understand the true risk to assets. You see, when conducting a risk assessment, the formula used to determine risk is….

    A + T + V = R
    That is, Asset + Threat + Vulnerability = Risk.

    Risk is a function of threats exploiting vulnerabilities to obtain, damage or destroy assets. Thus, threats (actual, conceptual, or inherent) may exist, but if there are no vulnerabilities then there is little/no risk. Similarly, you can have a vulnerability, but if you have no threat, then you have little/no risk.

    Accurately assessing threats and identifying vulnerabilities is critical to understanding the risk to assets. Understanding the difference between threats, vulnerabilities, and risk is the first step.

  • Source Description Threat Analysis Group, LLC
    Source URL http://www.threatanalysis.com/blog/?p=43
    Document No document attached...
    Item Quality Status (Item Quality Status) Acceptable
    Updated by webea.09
    Updated on 2014-04-15 21:54:32
    is referenced by is referenced by
    ERM 2: Identify and Score RisksProcess ERM 2: Identify and Score Risks
    ERM: Enterprise Risk Management Process
    Financial Stability RiskRisk Financial Stability Risk