Definition should state that
- vulnerability refers to a flaw in a system that can leave it open to attack; may also refer to any type of weakness in a computer system, in a set of procedures, or in anything that leaves information security exposed to a threat
- threat is any potential malicious act or event that could compromise the confidentiality, integrity, or availability of a computer system, network, or device
- risk is the likelihood that a vulnerability will occur and that a loss occurs if that vulnerability is exploited
- attack is any malicious activity that deliberately attempts to exploit a vulnerability.