166 terms · 75/46/45
Defense № 041 · class: governance

Risk Assessment

Systematic process of identifying, analyzing, and prioritizing cyber risks.

Term

description · examples · notes

Systematic process of identifying, analyzing, and prioritizing cyber risks.

Description

Covers identification of assets, threats, vulnerabilities, and potential impact.

Result is a risk register with priorities for treatment (mitigation, transfer, acceptance).

Methodologies include NIST RMF, ISO 27005, FAIR, and OCTAVE.

Regular reassessment is necessary as threats and infrastructure change.

What people often say

  • Risk assessment is not a one-time task — it requires continuous updates.
  • It is impossible to eliminate all risks — the goal is managing them to an acceptable level.

Covers / does not cover

Covers

  • Risk identification and classification
  • Quantitative and qualitative analysis
  • Risk treatment prioritization

Does not cover

  • Technical control implementation
  • Operational threat monitoring
  • Automated vulnerability detection

Mentioned in the news

Composite

Threats

reduces 3

Threats it reduces. Select one to open its page.

Techniques

neutralizes 3

Techniques it neutralizes. Select one to open its page.