# Vulnerability **Entity class:** Risk-engineering concept ## Definition A **vulnerability** is a weakness or condition in a system, procedure, control, implementation, relationship, or environment that can be exploited or triggered by a threat source. In a sociotechnical system, the weakness may lie in software, credentials, supervision, trust, placement, permissions, physical design, or organizational procedure. ## Relevance to this collection The relevant human-centered distinction is that the person is usually the threat source, while the configuration of [[wiki/Trusted Access|trusted access]], reachable assets, and insufficient controls is the vulnerability. A person can simultaneously embody the vulnerability-bearing condition when those properties are inseparable from the person's placement. ## Relationships - **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]]. - **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]]. ## Sources / Provenance - [NIST Computer Security Resource Center, “Vulnerability” glossary](https://csrc.nist.gov/glossary/term/vulnerability) (accessed 2026-09-23). **As of:** 2026-09-23