Threat, vulnerability, and risk
Like all the previous chapters, we will start this chapter by learning about the definitions of threat, vulnerability, and risk.
A threat could be anything (a human, malicious code, a bot, a natural disaster, and so on) that could impact an asset and adversely affect it in a manner that can result in harm. Threats employ threat actors to exploit a vulnerability and a threat vector is the path or route that’s used by the adversary to gain access to the target.
A vulnerability is a weakness in the design, implementation, operation, or internal control of a process, which could expose the system or an asset to adverse threats from threat events.
When a threat exploits a vulnerability and adversely affects the system, it is considered a risk.
It is important to note that threats will always exist and there is little that an organization can do to limit the number of threats. However, organizations can always choose to apply sufficient...