Knowledge / vulnerability concepts acsc-glossary

Vulnerability

A weakness in requirements, design, build, or operations that can be tripped or abused and break the security policy.

VULNERABILITY MANAGEMENT LOOPDiscoverPrioritiseRemediateVerifyPrioritise with KEV, exposure, and asset value -- not CVSS alone.

A vulnerability is a weakness — in what you asked for, how you designed it, how it was built, or how it is run — that can be triggered by accident or on purpose and violate the system's security policy. Missing MFA is a vulnerability. So is an unpatched library.

Finding them is assessment. Ranking and fixing them is management. A scanner PDF is neither if nobody owns the tickets.

Fact source: ASD's ACSC glossary.