Risk assessment
Also known as: risk analysis
Working out what could go wrong, how likely it is and how much harm it would do, so the biggest risks get handled first.
Draft - this entry has not been reviewed yet.
Formal
The step in risk management that finds each risk by pairing an asset with a threat and a vulnerability, then rates it by likelihood and impact. It can be done with numbers or with scales such as low, medium and high.
In plain English
Before a picnic you ask what could spoil it, how likely that is and how bad it would be - then you bring an umbrella rather than worrying about bears.
In practice
The owner of a small Danish web shop lists its payment system, customer data and warehouse, scores each threat from 1 to 5 for likelihood and impact, and puts the results on a heat map for the board.
Why it matters
Without it, decisions rest on gut feeling and the latest headline; a written assessment also shows auditors and authorities that the choices were made on purpose.
Technical deep dive
In ISO terminology risk assessment is the umbrella for three sub-steps: risk identification, risk analysis and risk evaluation (ISO 31000:2018 clauses 6.4.2 to 6.4.4; ISO/IEC 27005:2022 clauses 7.2 to 7.4). Analysis determines likelihood and consequence and thereby the level of risk; evaluation compares that level with the risk criteria to decide which risks need treatment and in what order. Using "risk analysis" as a synonym for the whole activity, as is common in everyday usage, blurs the distinction, and in Danish practice risikovurdering and risikoanalyse are likewise used loosely.
ISO/IEC 27001:2022 separates defining the process from running it. Clause 6.1.2 requires a defined assessment process with established acceptance criteria and criteria for performing assessments, producing consistent, valid and comparable results, identifying risks to confidentiality, integrity and availability within scope, assigning risk owners, and analysing and evaluating those risks. Clause 8.2 then requires assessments to be performed at planned intervals or when significant changes are proposed or occur, with the results retained as documented information. ISO/IEC 27005:2022 describes two identification approaches: an event-based approach working from risk sources and strategic scenarios, and an asset-based approach enumerating assets, threats and vulnerabilities in detail. It also replaced the older term incident scenario with risk scenario.
NIST SP 800-30 Rev. 1 structures assessment as prepare, conduct, communicate and maintain, and places it on the three tiers defined in SP 800-39: organisation, mission or business process, and information system. Its risk model links threat sources, threat events, vulnerabilities and predisposing conditions, likelihood and impact, with example scales in Appendices D to I. The method can be qualitative, semi-quantitative or quantitative; the choice affects precision and cost but not the underlying structure.
Neighbouring activities differ in object and output. A vulnerability assessment lists concrete technical weaknesses but does not by itself rate business risk; threat modelling analyses a design for what could go wrong, typically at development time; a business impact analysis measures impact over time without considering likelihood; and a GDPR data protection impact assessment under Art. 35 rates risk to the rights and freedoms of data subjects rather than to the organisation. A risk assessment consumes all four as inputs. Typical failures are scoring without agreed criteria, registers describing systems instead of business consequences, and one-off assessments never repeated when the environment changes.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk assessment
Relationships
- Part of
- Risk management
- Consists of
- Risk identification
- Requires
- RiskLikelihoodImpactAsset
- Mandated by
- CER Directive
Sources & further reading
Standards & official texts
- NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments · NIST
- ISO/IEC 27005:2022 - Guidance on managing information security risks · ISO/IEC
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…