risk

nounverified·updated May 9, 2026

A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of (i) the adverse impact or magnitude of harm that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence. [18]

polysemousNIST SP 800-172r3

Senses

SANS Glossary of Security Terms

Risk is the product of the level of threat with the level of vulnerability. It establishes the likelihood of a successful attack.

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon

The potential for an unwanted or adverse outcome resulting from an incident, event, or occurrence, as determined by the likelihood that a particular threat will exploit a particular vulnerability, with the associated consequences.

ISACA Cybersecurity Glossary

The combination of the probability of an event and its consequence. (ISO/IEC 73)

NIST Cybersecurity Framework

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: • the adverse impacts that would arise if the circumstance or event occurs; and • the likelihood of occurrence. Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and consider the adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.

Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary

The potential that events, expected or unanticipated, may have an adverse effect on a financial institution's earnings, capital, or reputation.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 2 pending review

The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 3 pending review

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (1) the adverse impacts that would arise if the circumstance or event occurs; and (2) the likelihood of occurrence. Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 4 pending review

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. Adverse impacts to the Nation include, for example, compromises to information systems that support critical infrastructure applications or are paramount to government continuity of operations as defined by the Department of Homeland Security.]

NIST SP 800-53

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and consider the adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.

Systems and software engineering —Vocabulary

An uncertain event or condition that, if it occurs, has a positive or negative effect on a project's objectives

Information Technology - Governance of IT - Governance implications of the use of artificial intelligence by organizations

effect of uncertainty on objectives

NIST AI RMF 1.0

The composite measure of an event’s probability of occurring and the magnitude or degree of the consequences of the corresponding event. The impacts, or consequences, of AI systems can be positive, negative, or both and can result in opportunities or threats (Adapted from: iso 31000:2018 )

An Introductin to Information Security

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.

Wordset Dictionary

a venture undertaken without regard to possible loss or injury

Wordset Dictionary

the probability of being exposed to an infectious agent

Wordset Dictionary

the probability of becoming infected given that exposure to an infectious agent has occurred

Wordset Dictionary

a source of danger

NIST SP 800-171r3glossary

A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [13]

TSP Section 100glossary

The possibility that an event will occur and adversely affect the achievement of objectives.

Classifications

Entity Type

Metric85%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

synonym
dangerendangermenthazardjeopardyperilrisk of exposurerisk of infection
alternatephrasing
Risk
plural
risks
possessive
risk's
pluralpossessive
risks'