An assessment connects assets and dependencies to the threats that could affect them, the weaknesses that could enable those threats, the likelihood of each scenario, and the consequences if it occurs. Outputs may be qualitative, quantitative, or mixed, but they should be explicit about scope, assumptions, evidence, and confidence.
The assessment is an input to decision-making, not a decision itself. It informs which risks are treated, transferred, avoided, or accepted, who accepts them, and when the analysis must be refreshed as systems, threats, and obligations change.
Key points
Scope and contextDefine the assets, boundaries, threat landscape, assumptions, applicable criteria, and decision the assessment must support before collecting evidence.
AnalysisIdentify relevant threats, vulnerabilities, existing controls, likelihood drivers, and impact dimensions such as confidentiality, integrity, availability, safety, legal, and financial harm.
Evaluation and useCompare results against risk criteria, document treatment choices and residual-risk acceptance, assign owners, and feed findings into control design and programs such as business impact analysis.
Important limitationA risk assessment is an estimate produced under stated assumptions, not a measurement of actual risk. Unidentified assets, optimistic likelihood judgments, outdated threat information, or scope gaps can make the results misleading even when the method is sound.