Definitions Flashcards
Vulnerability
A weakness in a device, system, application or process that might allow an attack to take place. They are internal factors that can be controlled by cyber pros.
Threat
An outside force that may exploit a vulnerability
Risk
The combination of a threat and a corresponding vulnerability.
Risk = Threat x Vulnerability
Both of these factors must be present before a situation poses a risk to the security of an organization.
Adversarial Threat
Individuals, groups, and organizations that are attempting to deliberately undermine the security of an organization. When evaluating an adversarial threat, cyber pros should consider the capability of the threat actor to engage in attacks, the intent of the threat actor, and the likelihood that the threat will target the organization. Adversarial threats can also include insider, as well as external threats.
Accidental Threat
These occur when individuals doing their routine work mistakenly perform an action that undermines security.
Structural Threat
These occur when equipment, software, or environmental controls fail due to the exhaustion of resources, exceeding their operational capabilities, or simply failing due to age.
Environmental Threats
These occur when natural or man-made disasters occur that are outside of the control of the organization.
Technical Controls
Systems, devices, software, and settings that work to enforce confidentiality, integrity, and availability requirements.
Operational Controls
Practices and procedures that bolster cybersecurity.