> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage Threats and Vulnerabilities

> Import threats from the catalog, create vulnerabilities, and assign both to a risk scenario.

A threat and a vulnerability together form a risk's scenario: the threat is
what can occur, the vulnerability is what makes it possible. Both are kept as
their own, reusable entries and can be used in several risks.

## Create or import a threat

*Threat* opens the create dialog with the fields *Name* (required),
*Category*, and *Description*.

*Import* opens the *Threat Catalog*: catalogs appear as blocks with their
entries, already-imported ones are locked. The search field filters by name
and reference. After confirming, the toast names the total number of threats
imported across all selected catalogs.

<Note>
  If only saving the description fails, the threat still exists without a
  description, and a warning message says so. Add the description on the detail
  page. The same applies to vulnerabilities.
</Note>

## Create a vulnerability

*Vulnerability* opens the same kind of dialog with *Name* (required),
*Category*, and *Description*. Vulnerabilities have no catalog import and no
*Source* field.

## Creating from within a risk

Both dialogs can also be opened from the risk creation wizard and from the
scenario section of the risk detail page. The new entry is linked to the risk
immediately.

<Note>
  Creating and relating are separate operations: if only the relation fails,
  the newly created threat or vulnerability still exists, a warning names the
  reason, and the dialog closes anyway. A second attempt would otherwise create
  a duplicate entry.
</Note>

## An entry's detail page

The detail page carries *Category* and description, both editable. There is
no status, due date, or recurrence here — those belong to the control, not to
the threat or vulnerability.

The *Risks* tab lists the risks that use the entry, each row with assessment,
lifecycle status, and owner. A vulnerability also
carries the *Affected Assets* tab, listing the systems directly linked to it —
regardless of whether a risk already builds on it.

<Note>
  Both detail pages also carry the *Relations* tab. It shows all of the entry's
  relations, while *Risks* and *Affected Assets* each show only one kind — an
  empty *Risks* tab does not mean the entry is unlinked.
</Note>

## Deleting

Both lists offer the bulk action *Delete*. Linked risks remain — only the
threat or vulnerability itself is removed.

## Related

[Create and Assess Risks](/docs/en/isms/assess-risks) requires at least one threat
and one vulnerability for a risk's scenario. Fields and columns at a glance are
in the [ISMS Reference](/docs/en/isms/reference).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.