MLchartDataset catalogue

risk

Term · Cybersecurity · MLC-T-CYB-003590

1. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.

2. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.
[Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. Adverse impacts to the Nation include, for example, compromises to information systems that support critical infrastructure applications or are paramount to government continuity of operations as defined by the Department of Homeland Security.]

3. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.

4. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [Note: System-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. Adverse impacts to the Nation include, for example, compromises to systems that support critical infrastructure applications or are paramount togovernment continuity of operations as defined by the Department of Homeland Security.]

5. A measure of the likelihood and the consequence of events or acts that could cause a system compromise, including the unauthorized disclosure, destruction, removal, modification, or interruption of system assets.

6. Risk that arises through the loss of confidentiality, integrity, or availability of information or information systems considering impacts to organizational operations and assets, individuals, other organizations, and the Nation.

7. The highest acceptable probability for an inauthentic message to pass the decryption-verification process.

8. The level of potential impact on an organization operations (including mission, functions, image, or reputation), organization assets, or individuals of a threat or a given likelihood of that threat occurring.

9. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of (i) the adverse impacts that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence.

10. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of the adverse impacts that would arise if the circumstance or event occurs; and the likelihood of occurrence.

11. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.
[Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.]

12. The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.

13. The net negative impact of the exercise of a vulnerability, considering both the probability and the impact of occurrence. Risk management is the process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level.

14. The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.

15. Effect of uncertainty on objectives.

16. The level of impact on agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an information system, given the potential impact of a threat and the likelihood of that threat occurring.

17. A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of (i) the adverse impact or magnitude of harm that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence.

18. A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.

19. effect of uncertainty on objectives. Note: risk is often expressed in terms of a combination of the consequences of an event (including changes in circumstances) and the associated likelihood of occurrence.

20. the relative impact that an exploited vulnerability would have to a user’s environment.

21. An ISCM capability that focuses on reducing the successful exploits of the other non-meta capabilities that occur because the risk management process fails to correctly identify and prioritize actions and investments needed to lower the risk profile.

22. A measure of the extent to which an organization is threatened by a potential circumstance or event, and typically a function of the following:
a. The adverse impacts that would arise if the circumstance or event occurs; and
b. The likelihood of occurrence. Likelihood is influenced by the ease of exploit and the frequency with which an assessment object is being attacked at present.

23. See Capability, Manage and Assess Risk.

24. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.]

25. A measure of the extent to which an entity or individual is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.

26. The effect of uncertainty on objectives.

27. The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals that result from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.

Table 1. Record
IdentifierMLC-T-CYB-003590
FieldCybersecurity
SynonymsCapability, Manage and Assess Risk; Information System-Related Security Risk
ReferencesCNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-171Ar3 from OMB Circular A-130 (2016); NIST SP 800-171r3 from OMB Circular A-130 (2016); NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016); NISTIR 8228; NIST SP 800-137 from FIPS 200 (Adapted); NIST SP 1800-11B from NIST SP 800-30 Rev. 1; NIST SP 1800-21B from NIST SP 800-30 Rev. 1; NIST SP 1800-30B from NIST SP 800-30 Rev. 1; NIST SP 1800-34B from NIST SP 800-30 Rev. 1; NIST SP 800-188 from CNSSI 4009-2022; NIST Cybersecurity Framework Version 1.1; NIST IR 8323r1 from NIST SP 800-37 Rev. 2; NIST IR 8401 from NIST SP 800-37 Rev. 2; NIST IR 8441 from NIST SP 800-37 Rev. 2; NIST Privacy Framework Version 1.0 from NIST SP 800-30 Rev. 1; NISTIR 7621 Rev. 1; NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-39; NIST SP 800-30 Rev. 1; NIST SP 800-12 Rev. 1; NIST SP 800-28 Version 2; NIST SP 800-30 Rev. 1; NIST SP 800-38C; NIST SP 800-79-2; NIST SP 1800-17b; NIST SP 1800-17c; NIST SP 800-160 Vol. 2 Rev. 1 from OMB Circular A-130 (2016), CNSSI 4009-2022; NIST SP 800-39; NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200 (Adapted); NIST SP 800-60 Vol. 2 Rev. 1 from FIPS 200 (Adapted); NIST SP 1800-15B; NIST SP 1800-15C; NIST SP 1800-10B from FIPS 200; NIST SP 1800-25B from FIPS 200; NIST SP 1800-26B from FIPS 200; NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-221 from OMB Circular A-11; NIST SP 800-82r3 from FIPS 200 (adapted); NIST SP 800-172r3 from NIST SP 800-39; NIST SP 800-172Ar3 from OMB Circular A-130 (2016); NISTIR 8053; NISTIR 7435; NISTIR 8011 Vol. 1; NISTIR 8170; NISTIR 8062 from NIST SP 800-30 Rev. 1; NISTIR 8286 from OMB Circular A-11; NIST IR 8270; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-003590",
  "term": "risk",
  "field": "Cybersecurity",
  "definition": "1. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.\n\n2. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.\n[Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. Adverse impacts to the Nation include, for example, compromises to information systems that support critical infrastructure applications or are paramount to government continuity of operations as defined by the Department of Homeland Security.]\n\n3. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.\n\n4. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [Note: System-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. Adverse impacts to the Nation include, for example, compromises to systems that support critical infrastructure applications or are paramount togovernment continuity of operations as defined by the Department of Homeland Security.]\n\n5. A measure of the likelihood and the consequence of events or acts that could cause a system compromise, including the unauthorized disclosure, destruction, removal, modification, or interruption of system assets.\n\n6. Risk that arises through the loss of confidentiality, integrity, or availability of information or information systems considering impacts to organizational operations and assets, individuals, other organizations, and the Nation.\n\n7. The highest acceptable probability for an inauthentic message to pass the decryption-verification process.\n\n8. The level of potential impact on an organization operations (including mission, functions, image, or reputation), organization assets, or individuals of a threat or a given likelihood of that threat occurring.\n\n9. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of (i) the adverse impacts that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence.\n\n10. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of the adverse impacts that would arise if the circumstance or event occurs; and the likelihood of occurrence.\n\n11. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.\n[Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.]\n\n12. The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.\n\n13. The net negative impact of the exercise of a vulnerability, considering both the probability and the impact of occurrence. Risk management is the process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level.\n\n14. The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.\n\n15. Effect of uncertainty on objectives.\n\n16. The level of impact on agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an information system, given the potential impact of a threat and the likelihood of that threat occurring.\n\n17. A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of (i) the adverse impact or magnitude of harm that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence.\n\n18. A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.\n\n19. effect of uncertainty on objectives. Note: risk is often expressed in terms of a combination of the consequences of an event (including changes in circumstances) and the associated likelihood of occurrence.\n\n20. the relative impact that an exploited vulnerability would have to a user’s environment.\n\n21. An ISCM capability that focuses on reducing the successful exploits of the other non-meta capabilities that occur because the risk management process fails to correctly identify and prioritize actions and investments needed to lower the risk profile.\n\n22. A measure of the extent to which an organization is threatened by a potential circumstance or event, and typically a function of the following:\na. The adverse impacts that would arise if the circumstance or event occurs; and\nb. The likelihood of occurrence. Likelihood is influenced by the ease of exploit and the frequency with which an assessment object is being attacked at present.\n\n23. See Capability, Manage and Assess Risk.\n\n24. A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.]\n\n25. A measure of the extent to which an entity or individual is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.\n\n26. The effect of uncertainty on objectives.\n\n27. The level of impact on organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals that result from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.",
  "synonyms": [
    "Capability, Manage and Assess Risk",
    "Information System-Related Security Risk"
  ],
  "references": [
    "CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-171Ar3 from OMB Circular A-130 (2016); NIST SP 800-171r3 from OMB Circular A-130 (2016); NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016); NISTIR 8228",
    "NIST SP 800-137 from FIPS 200 (Adapted)",
    "NIST SP 1800-11B from NIST SP 800-30 Rev. 1; NIST SP 1800-21B from NIST SP 800-30 Rev. 1; NIST SP 1800-30B from NIST SP 800-30 Rev. 1; NIST SP 1800-34B from NIST SP 800-30 Rev. 1; NIST SP 800-188 from CNSSI 4009-2022; NIST Cybersecurity Framework Version 1.1; NIST IR 8323r1 from NIST SP 800-37 Rev. 2; NIST IR 8401 from NIST SP 800-37 Rev. 2; NIST IR 8441 from NIST SP 800-37 Rev. 2; NIST Privacy Framework Version 1.0 from NIST SP 800-30 Rev. 1; NISTIR 7621 Rev. 1; NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-39; NIST SP 800-30 Rev. 1",
    "NIST SP 800-12 Rev. 1",
    "NIST SP 800-28 Version 2",
    "NIST SP 800-30 Rev. 1",
    "NIST SP 800-38C",
    "NIST SP 800-79-2",
    "NIST SP 1800-17b; NIST SP 1800-17c",
    "NIST SP 800-160 Vol. 2 Rev. 1 from OMB Circular A-130 (2016), CNSSI 4009-2022",
    "NIST SP 800-39",
    "NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200 (Adapted); NIST SP 800-60 Vol. 2 Rev. 1 from FIPS 200 (Adapted)",
    "NIST SP 1800-15B; NIST SP 1800-15C",
    "NIST SP 1800-10B from FIPS 200; NIST SP 1800-25B from FIPS 200; NIST SP 1800-26B from FIPS 200",
    "NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-221 from OMB Circular A-11",
    "NIST SP 800-82r3 from FIPS 200 (adapted)",
    "NIST SP 800-172r3 from NIST SP 800-39",
    "NIST SP 800-172Ar3 from OMB Circular A-130 (2016)",
    "NISTIR 8053",
    "NISTIR 7435",
    "NISTIR 8011 Vol. 1",
    "NISTIR 8170",
    "NISTIR 8062 from NIST SP 800-30 Rev. 1",
    "NISTIR 8286 from OMB Circular A-11",
    "NIST IR 8270",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/risk/"
}

Record 3,590 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.