Risk Assessment
The risk assessment aims to draw a risk picture for the organization. This includes
threats directed at the organization, the internal and external vulnerabilities the organization
faces, and the harm that will come to the organization if a threat exploits a
given vulnerability. The likelihood of the harm occurring is also evaluated and
calculated in the risk assessment.
The organization’s leaders determine various components in the risk assessment
strategy, including the tools, techniques, and methodologies that will be used to
develop the risk assessment; assumptions and constraints to the risk assessment;
and the roles and responsibilities for various positions within the risk management
process. The leadership also defines assumptions related to the risk picture, how risk
and threat information is collected, the frequency of risk assessments at each tier, and