4.4 Determining the likelihood of the threats
The determination of risk for a particular threat/vulnerability pair is:
• the likelihood of a given threat-source’s attempt to exercise a given vulnerability
• the magnitude of the impact should the threat-source successfully exercise the vulnerability
• the adequacy of planned or existing security controls for reducing or eliminating the risk.
The risk scale of Low, Medium and High, represents the degree or level of risk to which an IT system, facility, or procedure might be exposed if a given vulnerability were exercised. The risk scale also presents actions that senior management, the mission owners, must take for each risk level. This is represented by the table below
Risk Scale Risk Description and Necessary Actions
High If an observation or finding is evaluated as a high risk, there is a strong need for corrective measures. An existing system may continue to operate, but a corrective action plan must be put in place as soon as possible.
Medium If an observation is rated as medium risk, corrective actions are needed and a plan must be developed to incorporate these actions within a reasonable period of time.
Low If an observation is described as low risk, the system’s DAA must determine whether corrective actions are still required or decide to accept the risk.