# What is a Risk Assessment?

> A risk assessment is the structured process of identifying what could go wrong — the threats, vulnerabilities, likelihoods, and impacts relevant to an asset, system, or organization — so that treatment decisions can be prioritized and justified.

- Canonical URL: https://yellowcube.eu/glossary/risk-assessment/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

An assessment connects assets and dependencies to the threats that could affect them, the weaknesses that could enable those threats, the likelihood of each scenario, and the consequences if it occurs. Outputs may be qualitative, quantitative, or mixed, but they should be explicit about scope, assumptions, evidence, and confidence.

The assessment is an input to decision-making, not a decision itself. It informs which risks are treated, transferred, avoided, or accepted, who accepts them, and when the analysis must be refreshed as systems, threats, and obligations change.

### Key points

- **Scope and context:** Define the assets, boundaries, threat landscape, assumptions, applicable criteria, and decision the assessment must support before collecting evidence.
- **Analysis:** Identify relevant threats, vulnerabilities, existing controls, likelihood drivers, and impact dimensions such as confidentiality, integrity, availability, safety, legal, and financial harm.
- **Evaluation and use:** Compare results against risk criteria, document treatment choices and residual-risk acceptance, assign owners, and feed findings into control design and programs such as business impact analysis.
- **Important limitation:** A risk assessment is an estimate produced under stated assumptions, not a measurement of actual risk. Unidentified assets, optimistic likelihood judgments, outdated threat information, or scope gaps can make the results misleading even when the method is sound.

### Related terms

[Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Business impact analysis (BIA)](<https://yellowcube.eu/glossary/business-impact-analysis/>) · [Vulnerability assessment](<https://yellowcube.eu/glossary/vulnerability-assessment/>) · [Threat modeling](<https://yellowcube.eu/glossary/threat-modeling/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>)

### Sources

[NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments](https://csrc.nist.gov/pubs/sp/800/30/r1/final) · [NIST IR 8286r1, Integrating Cybersecurity and Enterprise Risk Management](https://csrc.nist.gov/pubs/ir/8286/r1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

