home/dictionary/vulnerability

vulnerability

nounverified·updated May 9, 2026

Weakness in a component of a system, particularly information assets, system security procedures, internal controls, or implementation, that could be exploited or triggered by human action or natural events.

Framework senses

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1 · extended_definition_available
A characteristic or specific weakness that renders an organization or asset (such as information or an information system) open to exploitation by a given threat or susceptible to a given hazard.
ISACA Cybersecurity Glossary1 senseview framework →
§1
A weakness in the design, implementation, operation or internal control of a process that could expose the system to adverse threats from threat events
NIST Cybersecurity Framework1 senseview framework →
§1
A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
FFIEC Cybersecurity Assessment Tool, Baseline, May 20171 senseview framework →
§1
A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
NERC CIP-010-2 (Config Change Management & Vulnerability) v21 senseview framework →
§1
A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
NERC CIP-007-6 (System Security Management) v61 senseview framework →
§1
A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures1 senseview framework →
§1
A weakness, susceptibility or flaw in a system that an attacker can access and exploit to compromise system security. Vulnerability arises from the confluence of three elements: the presence of a susceptibility or flaw in a system; an attacker’s access to that flaw; and an attacker’s capability to exploit the flaw.
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
A hardware, firmware, or software flaw that leaves an information system open to potential exploitation; a weakness in automated system security procedures, administrative controls, physical layout, internal controls, etc., that could be exploited to gain unauthorized access to information or to disrupt critical processing.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
§2 · sense_2_pending_review
A weakness in a system, application, or network that is subject to exploitation or misuse.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source.
NIST SP 800-531 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
NIST SP 800-53A1 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
NIST SP 800-371 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
FIPS PUB 2001 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
NIST SP 800-601 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
NIST SP 800-1151 senseview framework →
§1
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
NIST SP 800-611 senseview framework →
§1
A weakness in a system, application, or network that is subject to exploitation or misuse.
Wordset Dictionary2 sensesview framework →
§1
susceptibility to injury or attack
§2
the state of being vulnerable or exposed
TSP Section 1001 senseview framework →
§1 · glossary
Weakness in a component of a system, particularly information assets, system security procedures, internal controls, or implementation, that could be exploited or triggered by human action or natural events.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
DR-088 backfill from the noun definition column