Threat, Vulnerability, and Risk
Threat, vulnerability, and risk are three important concepts that are required to understand the risk management life cycle concretely. Risk practitioners must know these concepts off the top of their heads as they come in extremely handy at the time of risk assessment and threat modeling, both of which we’ll learn about later in this book.
This chapter aims to introduce the concepts of threat, vulnerability, and risk, understand the relationship between each, and learn about threat modeling and the threat landscape. We will also learn about vulnerability and control analysis and vulnerability sources, and briefly touch on building a vulnerability management program.
In this chapter, we will cover the following topics:
- Threat, vulnerability, and risk
- The relationship between threat, vulnerability, and risk
- Understanding threat modeling
- Vulnerability analysis
- Tools for identifying vulnerabilities
- Vulnerability...