Differentiation should include
- defining asset as it relates to a secure environment (e.g., servers, data, sensitive information)
- explaining the types of threats (e.g., cyber, technical failures)
- explaining
- how a vulnerability can result in a threat
- how eliminating a vulnerability can eliminate a threat.