As described in the standard terminology above, threats become risks through potentially exploiting a specific vulnerability of an asset. For example, the threat of losing data could incur by a faulty hardware storage device or a user deleting data by accident through a standard application function that was applied without intention. These different methods that could cause a threat to an asset is sometimes called attack vector in literature.