Week 15 · overview

Week 15: Vulnerability Is Not the Same as Risk

A vulnerability describes a weakness or condition. Risk asks what that weakness means in this system, with this exposure, these assets, these controls, and these consequences.

This week teaches students to prioritize instead of panic. You will separate vulnerability, exposure, likelihood, impact, control strength, uncertainty, and remediation effort, then produce a defensible risk register for the fictional Northstar system.

This week

  1. A Weakness Needs Context — connect vulnerability to asset, exposure, required function, and existing controls.
  2. Risk Scores Are Inputs, Not Decisions — interpret severity frameworks carefully and add local architecture context.
  3. Prioritization Is a Defensible Tradeoff — rank remediation work, record rationale, exceptions, compensating controls, and retest evidence.

Evidence artifact

Create a Risk and Remediation Register with at least six findings, contextual risk rationale, priority, owner, chosen treatment, verification plan, and residual risk.