home/glossary/risk analysis

risk analysis

nounid 3905·updated May 12, 2026
candidate

The process of identifying the risks to system security and determining the likelihood of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.

polysemousMWE

Classifications

Entity Type

Process0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

80%llm-generatedllm:claude-haiku-4-5

Information Class

85%llm-generatedllm:claude-haiku-4-5

Variants

synonym
analysis and quantification of the potential impact and consequences of these risks
plural
risk analyses
possessive
risk analysis's
pluralpossessive
risk analyses'

Framework definitions

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
The systematic examination of the components and characteristics of risk.
NIST Cybersecurity Framework1 senseview framework →
§1
The purpose of this task is to examine and identify the risks to the system, determine the probability of occurrence, analyze the related vulnerabilities of the system, the resulting impact, and the additional safeguards that mitigate this impact.
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
The process of identifying risks, determining their probability and impact, and identifying areas needing safeguards.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
The process of identifying the risks to system security and determining the likelihood of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.
§2 · sense_2_pending_review
Examination of information to identify the risk to an information system. See Risk Assessment.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Examination of information to identify the risk to an information system. See Risk Assessment.
NIST SP 800-271 senseview framework →
§1
The process of identifying the risks to system security and determining the likelihood of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.

Outgoing relationships

related

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.