Difference between revisions of "Risk"

From CIPedia
Jump to navigation Jump to search
(ISO/IEC 27000:2014)
(See also)
Line 24: Line 24:
 
==See also==
 
==See also==
 
* [[Residual Risk]]
 
* [[Residual Risk]]
 +
* [[Risk Management]]
  
 
==Notes==
 
==Notes==

Revision as of 17:16, 21 May 2014

Definitions

Official European Definition

Other International Definitions

UNISDR

The combination of the probability of an event and its negative consequences [1].

National Definitions

USA

The potential for an unwanted outcome resulting from an incident, event, or occurrence, as determined by its likelihood and the associated consequences [2].

Standard Definition

ISO/IEC 27000:2014

Effect of uncertainty on objectives [3](based on the ISO Guide 73:2009[4]).

  • An effect is a deviation from the expected — positive or negative.
  • Uncertainty is the state, even partial, of deficiency of information related to, understanding or * knowledge of, an event (2.25), its consequence, or likelihood.
  • Risk is often characterized by reference to potential events and consequences, or a combination of these.
  • Risk is often expressed in terms of a combination of the consequences of an event (including changes in circumstances) and the associated likelihood of occurrence.
  • In the context of information security management systems, information security risks can be expressed as effect of uncertainty on information security objectives.
  • Information security risk is associated with the potential that threats will exploit vulnerabilities of an information asset or group of information assets and thereby cause harm to an organization.

See also

Notes