Cybersecurity Word Crimes: Threat vs Vulnerability vs Risk
The purpose of this article is to help cybersecurity leaders up their game by gaining a baseline understanding of threats vs vulnerabilities vs risks.
Threat, vulnerability and risk management practices are meant to achieve a minimum level of protection?- this equates to a reduction in the total risk due to the protections offered by implemented controls. Think of this as a "risk management ecosystem" as it pertains to your overall security & compliance efforts. These ecosystem components have unique meanings that need to be understood to?reasonably protect people, processes, technology and data.
Risk Management Ecosystem
Understanding the context of how these components integrate can lead to more meaningful discussions and practical risk management activities. The diagram below is meant to show those interactions. It also helps show that compensating controls (e.g., POA&M items) are not bad, since compensating controls can help reasonably mitigate deficiencies.
You can?click on the image below for a PDF version?that helps visualize this risk management ecosystem, based on how these unique components interact.
领英推荐
Contextual Definitions
Please be a good person and avoid "word crimes" since words matter in compliance:
About ComplianceForge
ComplianceForge?specializes in cybersecurity and data privacy documentation solutions. We offer solutions for:
Please visit us at?https://www.complianceforge.com?to learn more about how we can help your organization with its cybersecurity and data privacy documentation.