vulnerability information
Actionable intelligence about identified weaknesses in systems, products, or processes — encompassing details such as flaw descriptions, severity ratings, affected components, and steps needed to exploit or remediate the weakness. Authority documents across the field treat it as a broad input category to risk management: NIST SP 800-53 repeatedly pairs it with threat information as a refined input that "facilitates the selection of additional security controls" and as a basis to "appropriately modify the controls based on… known threat and vulnerability information." CIS Controls likewise directs defenders to "monitor public and private industry sources for new threats and vulnerability information" as a continuous feed into vulnerability management. At its most specific, NIST's CSRC glossary also recognizes a narrower subtype — *technical* vulnerability information — defined as a "detailed description of a weakness to include the implementable steps… necessary to exploit that weakness," confirming that the broader expression subsumes multiple levels of detail, from high-level advisories through full exploitation guidance.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- Actionable intelligence about identified weaknesses in systems, products, or processes — encompassing details such as flaw descriptions, severity ratings, affected components, and steps needed to exploit or remediate the weakness. Authority documents across the field treat it as a broad input category to risk management: NIST SP 800-53 repeatedly pairs it with threat information as a refined input that "facilitates the selection of additional security controls" and as a basis to "appropriately modify the controls based on… known threat and vulnerability information." CIS Controls likewise directs defenders to "monitor public and private industry sources for new threats and vulnerability information" as a continuous feed into vulnerability management. At its most specific, NIST's CSRC glossary also recognizes a narrower subtype — *technical* vulnerability information — defined as a "detailed description of a weakness to include the implementable steps… necessary to exploit that weakness," confirming that the broader expression subsumes multiple levels of detail, from high-level advisories through full exploitation guidance.DR-088 backfill from the noun definition column