Risk Assessment
Systematic process of identifying, analyzing, and prioritizing cyber risks.
Term
description · examples · notesSystematic process of identifying, analyzing, and prioritizing cyber risks.
Description
Covers identification of assets, threats, vulnerabilities, and potential impact.
Result is a risk register with priorities for treatment (mitigation, transfer, acceptance).
Methodologies include NIST RMF, ISO 27005, FAIR, and OCTAVE.
Regular reassessment is necessary as threats and infrastructure change.
What people often say
- Risk assessment is not a one-time task — it requires continuous updates.
- It is impossible to eliminate all risks — the goal is managing them to an acceptable level.
Covers / does not cover
Covers
- Risk identification and classification
- Quantitative and qualitative analysis
- Risk treatment prioritization
Does not cover
- Technical control implementation
- Operational threat monitoring
- Automated vulnerability detection
Mentioned in the news
Threats
reduces 3Threats it reduces. Select one to open its page.
Techniques
neutralizes 3Techniques it neutralizes. Select one to open its page.