risk analysis
Term · Cybersecurity · MLC-T-CYB-003593
1. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. A part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.
2. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.
3. The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact. Part of risk management, synonymous with risk analysis. Incorporates threat and vulnerability analyses.
4. The process of identifying risks to organizational operations (including mission, functions, images, and reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.
5. The process of identifying, estimating, and prioritizing risks to organizational operations (i.e., mission, functions, image, reputation), organizational assets, individuals, and other organizations that result from the operation of a system. A risk assessment is part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls that are planned or in place. It is synonymous with “risk analysis.”
6. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system.
7. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.
8. Process to comprehend the nature of risk and to determine the level of risk.
9. Overall process of risk identification, risk analysis, and risk evaluation.
10. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system.
11. A systematic examination of risk using disciplined processes, methods, and tools. A risk assessment provides an environment for decision makers to evaluate and prioritize risks continuously and to recommend strategies to remediate or mitigate those risks.
12. The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.
13. See risk analysis
14. The process of identifying risks to organizational operations
(including mission, functions, image, reputation), organizational
assets, individuals, other organizations, and the Nation, resulting
from the operation of an information system. Part of risk
management, incorporates threat and vulnerability analyses,
and considers mitigations provided by security controls planned
or in place.
15. Risk management includes threat and vulnerability analyses as well as analyses of adverse effects on individuals arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.
16. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses and analyses of privacy problems arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.
17. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.
18. The process of identifying security risks, determining their magnitude, and identifying areas needing safeguards. Risk analysis is part of risk management.
19. The process of identifying the risks to system security and determining the likelihood of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.
20. See risk analysis.
| Identifier | MLC-T-CYB-003593 |
|---|---|
| Field | Cybersecurity |
| Synonyms | risk assessment |
| References | NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-39 (adapted); NIST SP 800-188 from NIST SP 800-39; NIST SP 800-82r3 from NIST SP 800-39 (adapted); NIST SP 800-175A; NIST SP 800-63-4; NIST SP 800-63A-4; NIST SP 800-172r3 from 44 U.S.C., Sec. 3552; CNSSI 4009-2022; NIST SP 800-160 Vol. 2 [Superseded] from ISO Guide 73; NIST SP 800-160 Vol. 1 from ISO Guide 73; NIST SP 800-160 Vol. 2 Rev. 1 from ISO Guide 73; NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-171 Rev. 2 [Superseded] from NIST SP 800-30; NIST SP 800-37 Rev. 2 from NIST SP 800-30 Rev. 1; NIST SP 800-53 Rev. 5 from NIST SP 800-39; NIST SP 800-172 [Superseded] from NIST SP 800-30 Rev. 1; NIST SP 800-171 Rev. 1 [Superseded]; NIST SP 800-53A Rev. 5 from NIST SP 800-39; NIST SP 800-172A [Superseded] from NIST SP 800-30 Rev. 1; NIST SP 800-171r3 from NIST SP 800-30 Rev. 1; CNSSI 4009-2015 from NIST SP 800-39; CNSSI 4009-2022 from DoDD 3020.40; NIST IR 8323r1 from NIST SP 800-30 Rev. 1; NIST IR 8441 from NIST SP 800-30 Rev. 1; NIST SP 800-33 [Withdrawn]; NIST SP 1800-21C; NIST SP 800-33 [Withdrawn]; NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-39 (Adapted); NIST SP 800-53 Rev. 5 from NISTIR 8062 (Adapted); NIST SP 800-53A Rev. 5 from NISTIR 8062 (Adapted); NIST SP 800-53B from NIST SP 800-39; NIST IR 8401 from NIST SP 800-30 Rev. 1; NIST SP 1800-11B from NIST SP 800-30 Rev. 1; NIST SP 1800-30B from NIST SP 800-30 Rev. 1; NIST SP 1800-34B from NIST SP 800-30 Rev. 1; NISTIR 4734; NIST SP 800-27 Rev. A [Withdrawn]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003593",
"term": "risk analysis",
"field": "Cybersecurity",
"definition": "1. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. A part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.\n\n2. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n3. The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact. Part of risk management, synonymous with risk analysis. Incorporates threat and vulnerability analyses.\n\n4. The process of identifying risks to organizational operations (including mission, functions, images, and reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.\n\n5. The process of identifying, estimating, and prioritizing risks to organizational operations (i.e., mission, functions, image, reputation), organizational assets, individuals, and other organizations that result from the operation of a system. A risk assessment is part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls that are planned or in place. It is synonymous with “risk analysis.”\n\n6. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system.\n\n7. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n8. Process to comprehend the nature of risk and to determine the level of risk.\n\n9. Overall process of risk identification, risk analysis, and risk evaluation.\n\n10. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system.\n\n11. A systematic examination of risk using disciplined processes, methods, and tools. A risk assessment provides an environment for decision makers to evaluate and prioritize risks continuously and to recommend strategies to remediate or mitigate those risks.\n\n12. The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.\n\n13. See risk analysis\n\n14. The process of identifying risks to organizational operations\n(including mission, functions, image, reputation), organizational\nassets, individuals, other organizations, and the Nation, resulting\nfrom the operation of an information system. Part of risk\nmanagement, incorporates threat and vulnerability analyses,\nand considers mitigations provided by security controls planned\nor in place.\n\n15. Risk management includes threat and vulnerability analyses as well as analyses of adverse effects on individuals arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.\n\n16. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses and analyses of privacy problems arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.\n\n17. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.\n\n18. The process of identifying security risks, determining their magnitude, and identifying areas needing safeguards. Risk analysis is part of risk management.\n\n19. The process of identifying the risks to system security and determining the likelihood of occurrence, the resulting impact, and the additional safeguards that mitigate this impact. Part of risk management and synonymous with risk assessment.\n\n20. See risk analysis.",
"synonyms": [
"risk assessment"
],
"references": [
"NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-39 (adapted)",
"NIST SP 800-188 from NIST SP 800-39",
"NIST SP 800-82r3 from NIST SP 800-39 (adapted)",
"NIST SP 800-175A",
"NIST SP 800-63-4; NIST SP 800-63A-4",
"NIST SP 800-172r3 from 44 U.S.C., Sec. 3552",
"CNSSI 4009-2022",
"NIST SP 800-160 Vol. 2 [Superseded] from ISO Guide 73; NIST SP 800-160 Vol. 1 from ISO Guide 73; NIST SP 800-160 Vol. 2 Rev. 1 from ISO Guide 73; NIST SP 800-160v1r1 from ISO Guide 73",
"NIST SP 800-171 Rev. 2 [Superseded] from NIST SP 800-30; NIST SP 800-37 Rev. 2 from NIST SP 800-30 Rev. 1; NIST SP 800-53 Rev. 5 from NIST SP 800-39; NIST SP 800-172 [Superseded] from NIST SP 800-30 Rev. 1; NIST SP 800-171 Rev. 1 [Superseded]; NIST SP 800-53A Rev. 5 from NIST SP 800-39; NIST SP 800-172A [Superseded] from NIST SP 800-30 Rev. 1; NIST SP 800-171r3 from NIST SP 800-30 Rev. 1",
"CNSSI 4009-2015 from NIST SP 800-39; CNSSI 4009-2022 from DoDD 3020.40; NIST IR 8323r1 from NIST SP 800-30 Rev. 1; NIST IR 8441 from NIST SP 800-30 Rev. 1",
"NIST SP 800-33 [Withdrawn]; NIST SP 1800-21C",
"NIST SP 800-33 [Withdrawn]",
"NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-39 (Adapted)",
"NIST SP 800-53 Rev. 5 from NISTIR 8062 (Adapted); NIST SP 800-53A Rev. 5 from NISTIR 8062 (Adapted)",
"NIST SP 800-53B from NIST SP 800-39; NIST IR 8401 from NIST SP 800-30 Rev. 1",
"NIST SP 1800-11B from NIST SP 800-30 Rev. 1; NIST SP 1800-30B from NIST SP 800-30 Rev. 1; NIST SP 1800-34B from NIST SP 800-30 Rev. 1",
"NISTIR 4734",
"NIST SP 800-27 Rev. A [Withdrawn]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/risk-analysis/"
}
Record 3,593 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.