The delta between the amount of force that an attacker can assert on a system and the amount of resistance the set of implemented controls can resist that force. It is usually computed based on the value of the asset and the probability of an attack being successful