Potential impact resulting from a threat exploiting a vulnerability.

Manipulating people to obtain information or access.

Protection of individual devices and endpoints.

Period when a service is unavailable.

Deliberate attempt to compromise a system.

Repeatedly trying possible credentials or keys.

Processes for restoring systems after major failures.

All possible points through which a system can be attacked.

Using stolen credentials against other services.

Ability to maintain critical operations during disruption.