The Security Risk Management Guide offers definitions of terms like risk, threat, and vulnerability in various documents readers would recognize. Microsoft clearly delineates between threats and vulnerabilities. NIST defines a vulnerability as a flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system’s security policy. Microsoft offers separate appendices with common threats, catastrophic incidents, and common threats. Their threats include malicious persons, and non-malicious persons, all of their own.”]
Source: https://taosecurity.blogspot.com/2005/05/risk-threat-and-vulnerability-101-in.html

