vulnerability
termsecuritygovernance & risk
A defect that allows someone to do something the system was meant to prevent.
A vulnerability is not a risk on its own: risk needs a reachable path, a motivated party and something worth reaching. That is why the count of open findings is a poor management number and the count of exploitable, exposed, high-value ones is a useful one. The awkward corollary is that most estates cannot fix everything, so a programme that does not prioritise is choosing by accident - and the choice is being made whether or not anyone writes it down.
Also known as: cve, flaw