security risk
A measure of potential harm to an organization's information assets, operations, individuals, or mission — jointly determined by the likelihood that a threat will exploit a vulnerability and the severity of the resulting adverse impact. Per the NIST CSRC Glossary, drawing from NIST SP 800-160v1r1 and ISO Guide 73, it is formally defined as "the effect of uncertainty on objectives pertaining to asset loss and the associated consequences." In information-system contexts, NIST elaborates this as risk arising through loss of confidentiality, integrity, or availability of information or systems, considering impacts to organizational operations and assets, individuals, other organizations, and the Nation. The field uses the expression operationally as an assessable and manageable quantity: risk is the potential for harm when a threat exploits a vulnerability, expressed as a function of threat source, threat event, vulnerability, predisposing conditions, and impact, and practitioners apply it at every tier — from individual systems to enterprise missions — to prioritize controls, justify countermeasures, and drive risk-treatment decisions.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A measure of potential harm to an organization's information assets, operations, individuals, or mission — jointly determined by the likelihood that a threat will exploit a vulnerability and the severity of the resulting adverse impact. Per the NIST CSRC Glossary, drawing from NIST SP 800-160v1r1 and ISO Guide 73, it is formally defined as "the effect of uncertainty on objectives pertaining to asset loss and the associated consequences." In information-system contexts, NIST elaborates this as risk arising through loss of confidentiality, integrity, or availability of information or systems, considering impacts to organizational operations and assets, individuals, other organizations, and the Nation. The field uses the expression operationally as an assessable and manageable quantity: risk is the potential for harm when a threat exploits a vulnerability, expressed as a function of threat source, threat event, vulnerability, predisposing conditions, and impact, and practitioners apply it at every tier — from individual systems to enterprise missions — to prioritize controls, justify countermeasures, and drive risk-treatment decisions.DR-088 backfill from the noun definition column