home/glossary/weakness

weakness

nounid 4647·updated May 12, 2026
candidate

An exception noted in tests of properly designed internal controls that may indicate ineffectiveness. Management must consider the extent of a weakness in such cases. Weaknesses can be classified as a simple deficiency, significant deficiency, or a material weakness.

Classifications

Entity Type

Vulnerability0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

Regulated80%llm-generatedllm:claude-haiku-4-5

Information Class

90%llm-generatedllm:claude-haiku-4-5

Variants

plural
weaknesses
possessive
weakness's
pluralpossessive
weaknesses'

Framework definitions

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
A shortcoming or imperfection in software code, design, architecture, or deployment that, under proper conditions, could become a vulnerability or contribute to the introduction of vulnerabilities.
FFIEC IT Examination Handbook - Audit, April 20121 senseview framework →
§1
An exception noted in tests of properly designed internal controls that may indicate ineffectiveness. Management must consider the extent of a weakness in such cases. Weaknesses can be classified as a simple deficiency, significant deficiency, or a material weakness.
NY DFS Part 500 (NYCRR Title 23, Chapter 1, Part 500)1 senseview framework →
§1
An exception noted in tests of properly designed internal controls that may indicate ineffectiveness. Management must consider the extent of a weakness in such cases. Weaknesses can be classified as a simple deficiency, significant deficiency, or a material weakness.

Outgoing relationships

related

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.