Difference between revisions of "Risk"
Jump to navigation
Jump to search
(→Other Definitions) |
(→Standard Definitions) |
||
Line 60: | Line 60: | ||
* [[Information Security|Information security]] risk is associated with the potential that [[threat|threats]] will exploit [[vulnerability|vulnerabilities]] of an information [[asset]] or group of information assets and thereby cause [[harm]] to an organization.</big> | * [[Information Security|Information security]] risk is associated with the potential that [[threat|threats]] will exploit [[vulnerability|vulnerabilities]] of an information [[asset]] or group of information assets and thereby cause [[harm]] to an organization.</big> | ||
<br /> | <br /> | ||
− | |||
==== ISO/IEC 31000:2009 ==== | ==== ISO/IEC 31000:2009 ==== | ||
{{definition|Effect of uncertainty on objectives. <ref name="ISO31000-09"> [http://www.iso.org/iso/home/store/catalogue_tc/catalogue_detail.htm?csnumber=43170 ISO/IEC 31000:2009, Risk management -- Principles and guidelines]</ref>}} | {{definition|Effect of uncertainty on objectives. <ref name="ISO31000-09"> [http://www.iso.org/iso/home/store/catalogue_tc/catalogue_detail.htm?csnumber=43170 ISO/IEC 31000:2009, Risk management -- Principles and guidelines]</ref>}} | ||
<br /> | <br /> | ||
+ | ====BS 25999-2==== | ||
+ | {{definition|Something that might happen and its effect(s) on the achievement of objectives. <ref>British Standard BS 25999-2</ref>}}<br /> | ||
==See also== | ==See also== |
Revision as of 13:00, 29 May 2015
Contents
Definitions
European Definitions
The possibility of loss, damage or injury having regard to the value placed on the asset by its owner/operator and the impact of loss or change to the asset, and the likelihood that a specific vulnerability will be exploited by a particular threat. [1]
The probability of adverse effects caused by a hazardous phenomenon or substance in an organism, a population, or an ecological system. [2]
International Definitions
NATO CEP / EAPC
The level of risk is a condition of two factors: (1) the value placed on the asset by its owner/operator and the impact of loss or change to the asset, and (2) the likelihood that a specific vulnerability will be exploited by a particular threat.
UNISDR
National Definitions
Australia
The chance of something happening that will have an impact on objectives. It is measured in terms if likelihood and consequence. [5]
[6] provides three other Australian definitions of risk.
Canada
Risk is the combination of the likelihood and the consequence of a specified hazard being realized. [7]
Risk refers to the vulnerability, proximity or exposure to hazards, which affects the likelihood of adverse impact.
Czech Republic
Risk is either defined as: (1) Danger, possibility of damage, loss, failure. (2) Effect of uncertainty to achieve objectives. (3) Possibility that a certain threat would utilize vulnerability of an asset or group of assets and cause damage to an organization. [8]
(1) Nebezpečí, možnost škody, ztráty, nezdaru. (2) Účinek nejistoty na dosažení cílů. (3) Možnost, že určitá hrozba využije zranitelnosti aktiva nebo skupiny aktiv a způsobí organizaci škodu.
Germany
Likelihood of a serious danger which (a) constitutes a threat to human life, (b) will impair the health of a large number of people, or (c) affects economic activity, public services and technical infrastructures and may cause damage to the environment, in particular animals and plants, the soil, the water, the atmosphere and cultural and material assets. [9]
United Kingdom (UK)
Risk is a measure of the significance of a potential emergency in terms of its assessed likelihood and impact. [10]
United States
DHS
The potential for an unwanted outcome resulting from an incident, event, or occurrence, as determined by its likelihood and the associated consequences. [11]
NIST
The level of impact on organizational operations (including mission,functions, image, or reputation), organizational assets, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring. [12]
Other Definitions
Ontario (Canada)
Risk is the product of the probability of the occurrence of a hazard and its consequences. [13]
Risque: produit de la probabilité qu’un danger se produise et de ses conséquences. [13]
Standard Definitions
ISO/IEC 27000:2014
- An effect is a deviation from the expected — positive or negative.
- Uncertainty is the state, even partial, of deficiency of information related to, understanding or * knowledge of, an event (2.25), its consequence, or likelihood.
- Risk is often characterized by reference to potential events and consequences, or a combination of these.
- Risk is often expressed in terms of a combination of the consequences of an event (including changes in circumstances) and the associated likelihood of occurrence.
- In the context of information security management systems, information security risks can be expressed as effect of uncertainty on information security objectives.
- Information security risk is associated with the potential that threats will exploit vulnerabilities of an information asset or group of information assets and thereby cause harm to an organization.
ISO/IEC 31000:2009
Effect of uncertainty on objectives. [16]
BS 25999-2
Something that might happen and its effect(s) on the achievement of objectives. [17]
See also
Notes
- ↑ EC COM(2006) 787 final, Directive of the Council on the identification and designation of European Critical Infrastructure and the assessment of the need to improve their protection, EC, Brussels 12.12.2006.
- ↑ European Commission's CBRN Glossary, 2012
- ↑ NATO EAPC(SCEPC) lexicon 2003.
- ↑ 2009 UNISDR Terminology on Disaster Risk Reduction, United Nations International Strategy for Disaster Reduction (UNISDR), Geneva, Switzerland, May 2009.
- ↑ Glossary of the Government of Queensland
- ↑ Australian Emergency Management Glossary, Emergency Management Australia (1998)
- ↑ [http://www.publicsafety.gc.ca/cnt/rsrcs/pblctns/mrgnc-mngmnt-frmwrk/index-eng.aspx An Emergency Management Framework for Canada (Second Edition)
- ↑ Act No. 181 of 23 July 2014 On Cyber Security and Change of Related Acts (Act on Cyber Security)
- ↑ http://www.kritis.bund.de/SharedDocs/Downloads/Kritis/EN/Baseline%20Protection%20Concept.pdf Protection of Critical Infrastructures – Baseline Protection Concept: Recommendation for Companies, BMI.
- ↑ Glossary - Revision to Emergency Preparedness, Cabinet Office (2012)
- ↑ DHS Risk Lexicon 2010 Edition, September 2010
- ↑ NISTIR 7298 rev 2: Glossary of Key Information Security Terms, May 2013/FIPS 200
- ↑ 13.0 13.1 Province of Ontario’s Emergency Management Glossary of Terms
- ↑ ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary
- ↑ ISO Guide 73:2009 Risk management -- Vocabulary
- ↑ ISO/IEC 31000:2009, Risk management -- Principles and guidelines
- ↑ British Standard BS 25999-2