1. Santos
O. (2020). CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide. Cisco Press. In the context of risk management
the guide defines a vulnerability as "a weakness in a system or its design that could be exploited by a threat" and risk as "the likelihood of a threat agent exploiting a vulnerability and the corresponding impact." (Chapter 23
"Risk Management
" Section: "Threats
Vulnerabilities
and Exploits").
2. National Institute of Standards and Technology (NIST). (2012). Guide for Conducting Risk Assessments (NIST Special Publication 800-30
Revision 1).
Vulnerability is defined as a "flaw or weakness in system security procedures
design
implementation
or internal controls that could be exercised... and result in a security breach..." (Section 2.2.3
Page 8).
Risk is defined as "a measure of the extent to which an entity is threatened by a potential circumstance or event
and is typically a function of: (i) the adverse impacts [damage] that would arise... and (ii) the likelihood of occurrence." (Section 2.2.1
Page 7).