home/glossary/risk assessment

risk assessment

nounverified·updated Aug 28, 2026

The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system. [21]

polysemousMWENIST SP 800-172r3

Senses

SANS Glossary of Security Terms

A Risk Assessment is the process by which risks are identified and the impact of those risks determined.

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexiconextended definition available

The product or process which collects information and assigns values to risks for the purpose of informing priorities, developing or comparing courses of action, and informing decision making.

ISACA Cybersecurity Glossary

A process used to identify and evaluate risk and its potential effects Scope Note: Risk assessments are used to identify those items or areas that present the highest risk, vulnerability or exposure to the enterprise for inclusion in the IS annual audit plan. Risk assessments are also used to manage the project delivery and project benefit risk.

FFIEC Cybersecurity Assessment Tool, Baseline, May 2017

A prioritization of potential business disruptions based on severity and likelihood of occurrence. The risk assessment includes an analysis of threats based on the impact to the institution, its customers, and financial markets, rather than the nature of the threat.

FFIEC IT Examination Handbook - Audit, April 2012

The purpose of this task is to support the identification, prioritization, and estimation of risks to organizational operations, organizational assets, individuals, other organizations, and the Nation through the operation of an information system and assign a value to assets, threat frequency, and consequences.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

The process of identifying risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation, arising through the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 2 pending review

The process of identifying, prioritizing, and estimating risks. This includes determining the extent to which adverse circumstances or events could impact an enterprise. Uses the results of threat and vulnerability assessments to identify risk to organizational operations and evaluates those risks in terms of likelihood of occurrence and impacts if they occur. The product of a risk assessment is a list of estimated potential impacts and unmitigated vulnerabilities. Risk assessment is part of risk management and is conducted throughout the Risk Management Framework (RMF).

NIST SP 800-171r3glossary

The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. [55]

Classifications

Entity Type

Process0%rule-basedmulti_axis_classifier_low_confidence.v1
?unassignedlast reviewed

Sensitivity

Regulated80%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Variants

synonym
assessment of the impact of the envisaged processing operations on the protection of personal data
plural
risk assessments
possessive
risk assessment's
pluralpossessive
risk assessments'