StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 2: Information security risk management

Vulnerability and control deficiency analysis

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A vulnerability is a weakness that a threat could exploit. It may be technical, such as missing patches, default credentials or misconfigured cloud storage, or non-technical, such as an untrained team, a weak process or a single person holding critical knowledge. Risk exists where a relevant threat meets a vulnerability in an asset that matters. Vulnerability analysis finds these weaknesses so the risk can be assessed and treated, and it is one of the main inputs to the risk register.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan