2.4 Determine Likelihood of Occurrence
Estimate the likelihood that a threat will exploit a vulnerability. Likelihood of occurrence is based on a number of factors that include system architecture, system environment, information system access and existing controls; the presence, motivation, tenacity, strength and nature of the threat; the presence of vulnerabilities; and the effectiveness of existing controls.
Refer to this table to when estimating the likelihood that the threat will be realized and exploit the vulnerability on the system.
Likelihood of Occurrence Levels
Likelihood
Description
Negligible
Unlikely ever to occur
Very Low
Likely to occur two/three times every five years
Low
Likely to occur once every year or less
Medium
Likely to occur once every six months or less
High
Likely to occur once per month or less
Very High
Likely to occur multiple times per month
Extreme
Likely to occur multiple times per day