Risk analysis
Risk analysis investigates and draws upon:
The information on risks generated during risk identification
The effectiveness and reliability of controls
Additional information from the statement of context
Supporting statistical data, results of predictive modelling or expert judgement
The risk criteria developed during establishing the context.
The aim of risk analysis is to gain an understanding of the nature of each risk, including the magnitude of its consequences and their likelihoods, and therefore to derive the level of risk.
Risk analysis enables each risk (or group of risks when considered in the aggregate) to be evaluated in order to determine whether risk treatment is needed.