Skip to content
atlas

Risk assessment

Also known as: risk analysis

Working out what could go wrong, how likely it is and how much harm it would do, so the biggest risks get handled first.

Draft - this entry has not been reviewed yet.

Formal

The step in risk management that finds each risk by pairing an asset with a threat and a vulnerability, then rates it by likelihood and impact. It can be done with numbers or with scales such as low, medium and high.

In plain English

Before a picnic you ask what could spoil it, how likely that is and how bad it would be - then you bring an umbrella rather than worrying about bears.

In practice

The owner of a small Danish web shop lists its payment system, customer data and warehouse, scores each threat from 1 to 5 for likelihood and impact, and puts the results on a heat map for the board.

Why it matters

Without it, decisions rest on gut feeling and the latest headline; a written assessment also shows auditors and authorities that the choices were made on purpose.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Define scope and criteria first - which processes and systems are covered, the likelihood and consequence scales, and the level at which risk is acceptable.
  2. List the critical assets (processes, information, systems, suppliers) with their owners, working from an up-to-date system overview.
  3. For each asset, identify relevant threats and vulnerabilities, using threat and vulnerability catalogues and the current SAMSIK threat assessment as input.
  4. Describe each risk as a scenario with a business consequence, for example customer data leaked after phishing, not just as a system name.
  5. Rate likelihood and consequence for each scenario on the agreed scales, taking existing controls into account; the SAMSIK risk assessment template is a free starting point.
  6. Evaluate the results against the acceptance criteria and rank the risks that need treatment.
  7. Document the assessment, have the risk owners sign it off and present the top risks to management.
  8. Repeat the assessment at planned intervals and when significant changes occur (ISO 27001 clause 8.2), and keep earlier versions for comparison.

Common pitfalls

  • Scoring risks without agreed criteria, so the same risk gets different ratings from different people.
  • Treating a vulnerability scan or a DPIA as the risk assessment instead of as inputs to it.
  • Rating on gut feeling alone, without using incident history or threat intelligence.
  • Doing it once for certification and never updating it when systems or threats change.

Good guides

Technical deep dive

In ISO terminology risk assessment is the umbrella for three sub-steps: risk identification, risk analysis and risk evaluation (ISO 31000:2018 clauses 6.4.2 to 6.4.4; ISO/IEC 27005:2022 clauses 7.2 to 7.4). Analysis determines likelihood and consequence and thereby the level of risk; evaluation compares that level with the risk criteria to decide which risks need treatment and in what order. Using "risk analysis" as a synonym for the whole activity, as is common in everyday usage, blurs the distinction, and in Danish practice risikovurdering and risikoanalyse are likewise used loosely.

ISO/IEC 27001:2022 separates defining the process from running it. Clause 6.1.2 requires a defined assessment process with established acceptance criteria and criteria for performing assessments, producing consistent, valid and comparable results, identifying risks to confidentiality, integrity and availability within scope, assigning risk owners, and analysing and evaluating those risks. Clause 8.2 then requires assessments to be performed at planned intervals or when significant changes are proposed or occur, with the results retained as documented information. ISO/IEC 27005:2022 describes two identification approaches: an event-based approach working from risk sources and strategic scenarios, and an asset-based approach enumerating assets, threats and vulnerabilities in detail. It also replaced the older term incident scenario with risk scenario.

NIST SP 800-30 Rev. 1 structures assessment as prepare, conduct, communicate and maintain, and places it on the three tiers defined in SP 800-39: organisation, mission or business process, and information system. Its risk model links threat sources, threat events, vulnerabilities and predisposing conditions, likelihood and impact, with example scales in Appendices D to I. The method can be qualitative, semi-quantitative or quantitative; the choice affects precision and cost but not the underlying structure.

Neighbouring activities differ in object and output. A vulnerability assessment lists concrete technical weaknesses but does not by itself rate business risk; threat modelling analyses a design for what could go wrong, typically at development time; a business impact analysis measures impact over time without considering likelihood; and a GDPR data protection impact assessment under Art. 35 rates risk to the rights and freedoms of data subjects rather than to the organisation. A risk assessment consumes all four as inputs. Typical failures are scoring without agreed criteria, registers describing systems instead of business consequences, and one-off assessments never repeated when the environment changes.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Risk assessment

Relationships

Mandated by
CER Directive

Sources & further reading

Standards & official texts

  • NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments · NIST
  • ISO/IEC 27005:2022 - Guidance on managing information security risks · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.