# Vulnerability
**Entity class:** Risk-engineering concept
## Definition
A **vulnerability** is a weakness or condition in a system, procedure, control, implementation, relationship, or environment that can be exploited or triggered by a threat source. In a sociotechnical system, the weakness may lie in software, credentials, supervision, trust, placement, permissions, physical design, or organizational procedure.
## Relevance to this collection
The relevant human-centered distinction is that the person is usually the threat source, while the configuration of [[wiki/Trusted Access|trusted access]], reachable assets, and insufficient controls is the vulnerability. A person can simultaneously embody the vulnerability-bearing condition when those properties are inseparable from the person's placement.
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]].
## Sources / Provenance
- [NIST Computer Security Resource Center, “Vulnerability” glossary](https://csrc.nist.gov/glossary/term/vulnerability) (accessed 2026-09-23).
**As of:** 2026-09-23