Difference between revisions of "Risk Analysis"
Jump to navigation
Jump to search
(→Council Directive 2008/114/EC) |
(→Australia) |
||
Line 11: | Line 11: | ||
==== Australia ==== | ==== Australia ==== | ||
{{definition| Risk analysis is a systematic use of available information to determine how often specified [[event|events]] may occur and the magnitude of their likely [[Consequence|consequences]]. <ref name="MAIMAus">[https://www.em.gov.au/Documents/Manual03-AEMGlossary.PDF Australian Emergency Management Glossary, Emergency Management Australia (1998)]</ref>}}<br /> | {{definition| Risk analysis is a systematic use of available information to determine how often specified [[event|events]] may occur and the magnitude of their likely [[Consequence|consequences]]. <ref name="MAIMAus">[https://www.em.gov.au/Documents/Manual03-AEMGlossary.PDF Australian Emergency Management Glossary, Emergency Management Australia (1998)]</ref>}}<br /> | ||
+ | |||
+ | {{definition|Process to comprehend the nature of risk and to determine the level of [[risk]]. <ref> [http://www.risknz.org.nz/files/3114/0868%2F4596%2F5050-2010.pdf Australia AS NZS 5050 (2010)]</ref>}}<br /> | ||
====Czech Republic==== | ====Czech Republic==== |
Revision as of 11:58, 29 May 2015
Contents
Definitions
European Definitions
Council Directive 2008/114/EC
The consideration of relevant threat scenarios, in order to assess the vulnerability and the potential impact of disruption or destruction of critical infrastructure. [1]
National Definitions
Australia
Risk analysis is a systematic use of available information to determine how often specified events may occur and the magnitude of their likely consequences. [2]
Czech Republic
Process of understanding the nature of risks and establishing a risk level. [4]
United States
The process of identifying risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation, arising through the operation of an information system.[5]
Standard Definition
ISO/IEC 27000:2014 and ISO 31000:2009
Process to comprehend the nature of risk and to determine the level of risk (based on the ISO Guide 73:2009) [6] [7]
Level of risk is expressed in terms of the combination of consequences and their likelihood.
- Risk analysis provides the basis for Risk Evaluation and decisions about Risk Treatment.
- Risk analysis includes Risk Estimation.
See also
Notes
- ↑ Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection.
- ↑ Australian Emergency Management Glossary, Emergency Management Australia (1998)
- ↑ Australia AS NZS 5050 (2010)
- ↑ Cyber Security Explanatory Glossary (2013)
- ↑ NISTIR 7298 rev 2: Glossary of Key Information Security Terms, May 2013
- ↑ ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary
- ↑ ISO/IEC 31000:2009, Risk management -- Principles and guidelines