The paper critiques common myths surrounding threats and vulnerabilities in security assessments, clarifying that threats are not vulnerabilities and that both threat assessments (TAs) and vulnerability assessments (VAs) are essential for effective risk management. It emphasizes the importance of understanding concrete vulnerabilities over speculative threats and addresses the shortcomings of prevalent tools in finding vulnerabilities. Additionally, the author warns against confusing features with vulnerabilities and underscores that the ultimate goal of TAs and VAs is to improve security, not to certify it.
Related topics: