home/dictionary/Vulnerability Assessment

Vulnerability Assessment

nouncandidate·updated May 12, 2026

Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.

Framework senses

NY DFS Part 500 (NYCRR Title 23, Chapter 1, Part 500)1 senseview framework →
§1
The purpose of this task is to systematically examine an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
NERC CIP-010-2 (Config Change Management & Vulnerability) v21 senseview framework →
§1
The purpose of this task is to systematically examine an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
NERC CIP-003-6 (Security Management Controls) v61 senseview framework →
§1
The purpose of this task is to systematically examine an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
Systematic examination of systems to identify, quantify, and prioritize the security deficiencies of the systems.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
Formal description and evaluation of the vulnerabilities in an information system.
§2 · sense_2_pending_review
Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
NIST SP 800-531 senseview framework →
§1
Formal description and evaluation of the vulnerabilities in an information system.
NIST SP 800-53A1 senseview framework →
§1
Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
NIST SP 800-371 senseview framework →
§1
Formal description and evaluation of the vulnerabilities in an information system.