Qualitative risk analysis
Also known as: qualitative risk assessment
Rating risks with words or simple scales, such as low, medium and high, based on judgement rather than exact figures.
Draft - this entry has not been reviewed yet.
Formal
A risk assessment method that scores likelihood and impact on ordered scales (for example 1-5 or low-high), usually by the judgement of people who know the systems, and often shows the result in a heat map.
In plain English
Like a mountain guide calling a slope "probably fine, but deadly if it slides" - quick and useful, even without an exact percentage.
In practice
The partners of an architect firm rate "a laptop with client drawings is left on the train" as medium likelihood and high impact, colour it orange on the chart and add one line on why.
Why it matters
It is fast, cheap and easy for leaders to read, but scores can hide guessing, so the reasons behind each rating should be written down.
Technical deep dive
Qualitative analysis stands or falls with its scale definitions, which ISO 31000:2018 and ISO/IEC 27005:2022 treat as part of the risk criteria agreed before any scoring. Each level needs an anchored descriptor, not a bare word: likelihood tied to frequency bands or expected occurrences over a time window, consequence tied to thresholds per impact type, such as revenue lost, hours of outage, records exposed or regulatory sanction. Without anchors, "likely" is read very differently by different people; research on verbal probability expressions, going back to Sherman Kent's work on estimative language at the CIA, shows wide spread in the numeric probability people attach to the same word.
NIST SP 800-30 Rev. 1 gives the most detailed public template. Appendix D rates adversarial threat sources on capability, intent and targeting; Appendix G builds overall likelihood from the likelihood of a threat event being initiated or occurring and the likelihood of it resulting in adverse impact; Appendix H covers impact; and Appendix I combines the two into a risk level. Each scale has five levels, Very Low to Very High, with optional semi-quantitative equivalents on a 0-100 or 0-10 range. Semi-quantitative scoring is still ordinal judgement expressed as numbers, and arithmetic on it inherits the weaknesses of heat-map multiplication.
Reliability depends on process. Scores should come from people who know the systems and the business, ideally scored independently first and then discussed, as in a Delphi round, so that anchoring on the most senior voice is reduced. Recording a confidence level and a one-line rationale per rating makes later review possible and exposes guessing. Consistency across business units requires shared scales and occasional calibration sessions where teams score the same reference scenarios.
The method's strengths are speed, low data requirements and output that leaders read easily, which is why most ISO/IEC 27001 risk assessments are qualitative. Its limits are equally clear: ratings cannot be added across risks, cannot be compared directly with the cost of a control, and invite false precision when averaged or multiplied. A common hybrid is to screen the whole register qualitatively and then move the handful of risks tied to large investment or insurance decisions into quantitative analysis, where likelihood and impact are expressed as probability distributions and money.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Qualitative risk analysis
Relationships
- A kind of
- Risk assessment
- Requires
- RiskLikelihoodImpact
- Don't confuse with
- Quantitative risk analysis
- Used with
- Risk heat map
Sources & further reading
Standards & official texts
- NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 5
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…