Risk Assessment

Nota di ambito (SN) (en)

The process of identifying risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation, arising through the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.
SOURCE: SP 800-53; SP 800-53A; SP 800-37


The process of identifying, prioritizing, and estimating risks. This includes determining the extent to which adverse circumstances or events could impact an enterprise. Uses the results of threat and vulnerability assessments to identify risk to organizational operations and evaluates those risks in terms of likelihood of occurrence and impacts if they occur. The product of a risk assessment is a list of estimated potential impacts and unmitigated vulnerabilities. Risk assessment is part of risk management and is conducted throughout the Risk Management Framework (RMF).
SOURCE: CNSSI-4009

Risk Assessment

Data di creazione
03-Ott-2019
Termine accettato
03-Ott-2019
Descendant terms
0
More specific terms
0
Alternative terms
0
Related terms
0
Note
1
Metadata
Cerca
  • Cerca Risk Assessment  (Wikipedia)
  • Cerca Risk Assessment  (Google búsqueda exacta)
  • Cerca Risk Assessment  (Google scholar)
  • Cerca Risk Assessment  (Google images)
  • Cerca Risk Assessment  (Google books)