• Risk assessment involves determining the likelihood that
the vulnerability is a risk to the organization
• Each vulnerability can be ranked by the scale
• Sometimes calculating anticipated losses can be helpful
in determining the impact of a vulnerability