The relationship between threats, vulnerabilities, and risk
A risk manager needs to understand the relationship between threat, vulnerability, and risk. In addition, a risk manager should also understand the impact of threat actors and threat vectors and how they result in risk to assets.
Any threat by itself could not result in risk. It needs a vulnerability that it can exploit to cause risk to the system. A threat also needs a threat actor, which will materialize the threat by using a threat vector. The threat vector will then materialize the vulnerability and cause risk, which will harm the asset.
The following figure shows the relationship between the key concepts of threats, vulnerabilities, risks, and assets:
Figure 7.1 – Relationship between threat, vulnerability, and risk
Let’s detail this with the help of an example. The scenario in our example is of malicious software being installed and propagated on all the machines on a...