Systematic process of identifying and evaluating risks to determine appropriate responses.
Risk assessment identifies assets, threats, and vulnerabilities; evaluates the likelihood of threats exploiting vulnerabilities; and determines potential impact. Risk assessments can be qualitative (High/Medium/Low ratings), quantitative (numerical probability and financial impact), or hybrid. Results inform risk treatment decisions—which risks to mitigate, accept, transfer, or avoid. Regular risk assessment is required by frameworks like ISO 27001 and is fundamental to effective security management.
Why It Matters
The DSC Perspective:
Risk assessment is the foundation of risk-based security. Without understanding your risks, you can't prioritise effectively. Regular assessment ensures your understanding stays current as your environment changes.
