Home/Glossary/Risk Assessment

Risk Assessment

A systematic process of identifying, analyzing, and evaluating cybersecurity risks to inform treatment decisions.

Risk & ResilienceAlso called: "cyber risk assessment", "information security risk assessment"

Risk assessments prioritize security investments based on business impact.

Risk formula

Risk = Likelihood × Impact

Assessment steps

  1. Identify assets: Systems, data, processes.
  2. Identify threats: Ransomware, insider threats, natural disasters.
  3. Identify vulnerabilities: Unpatched software, weak controls.
  4. Analyze likelihood: Probability of exploitation.
  5. Analyze impact: Business consequences if realized.
  6. Calculate risk: Combine likelihood and impact.
  7. Prioritize: Focus on high-risk scenarios.

Risk treatment options

  • Avoid: Eliminate the activity.
  • Mitigate: Implement controls to reduce risk.
  • Transfer: Insurance or outsourcing.
  • Accept: Acknowledge and monitor.

Frameworks

  • NIST RMF (Risk Management Framework).
  • ISO 27005 (Information Security Risk Management).
  • FAIR (Factor Analysis of Information Risk).