Communication network security risk exposure management systems and
methods are disclosed. Risks to a communication network are determined by
analyzing assets of the communication network and vulnerabilities
affecting the assets. Assets may include physical assets such as
equipment or logical assets such as software or data. Risk analysis may
be adapted to assess risks to a particular feature of a communication
network by analyzing assets of the communication network which are
associated with that feature and one or more of vulnerabilities which
affect the feature and vulnerabilities which affect the assets associated
with the feature. A feature may be an asset itself or a function or
service offered in the network and supported by particular assets, for
example.