Difference between revisions of "Risk Analysis"

From CIPedia
Jump to navigation Jump to search
m
Line 20: Line 20:
 
====Czech Republic====
 
====Czech Republic====
 
{{definition|Process of understanding the nature of risks and establishing a risk level. <ref> [http://www.govcert.cz/download/nodeid-3555/ Cyber Security Explanatory Glossary (2013)]</ref>}}<br />
 
{{definition|Process of understanding the nature of risks and establishing a risk level. <ref> [http://www.govcert.cz/download/nodeid-3555/ Cyber Security Explanatory Glossary (2013)]</ref>}}<br />
 +
====India====
 +
{{definition|Risk analysis is the process of identifying security risks, determining their magnitude, and identifying areas needing safeguards. <ref>[http://www.dgqadefence.gov.in/documents/pdf/cyber-security-policy-dgqa-2015.pdf India's DGQA Cyber Security Policy (2015)] </ref>}}Note: Only a trier of fact (someone with the authority to resolve disputes) can make an ultimate determination of non-repudiation. <br />
 
==== Luxembourg ====
 
==== Luxembourg ====
 
{{definition|Analyse de risques: examen des scénarios de menace pertinents destiné à évaluer les vulnerabilities [[Critical Infrastructure|d'infrastructures critiques]] et les [[Impact|impacts]] potentiels de leur arrêt ou destruction. <ref>[http://www.legilux.public.lu/rgl/2012/A/0449/A.pdf Règlement grand-ducal du 12 mars 2012 portant application de la directive 2008/114/CE du Conseil du 8 décembre 2008 ]</ref>}} <br />
 
{{definition|Analyse de risques: examen des scénarios de menace pertinents destiné à évaluer les vulnerabilities [[Critical Infrastructure|d'infrastructures critiques]] et les [[Impact|impacts]] potentiels de leur arrêt ou destruction. <ref>[http://www.legilux.public.lu/rgl/2012/A/0449/A.pdf Règlement grand-ducal du 12 mars 2012 portant application de la directive 2008/114/CE du Conseil du 8 décembre 2008 ]</ref>}} <br />
====India====
+
 
{{definition|Risk analysis is the process of identifying security risks, determining their magnitude, and identifying areas needing safeguards. <ref>[http://www.dgqadefence.gov.in/documents/pdf/cyber-security-policy-dgqa-2015.pdf India's DGQA Cyber Security Policy (2015)] </ref>}}Note: Only a trier of fact (someone with the authority to resolve disputes) can make an ultimate determination of non-repudiation. <br />
 
 
====United States====
 
====United States====
 
{{definition|The process of identifying [[risk|risks]] to organizational operations (including mission, functions, image, or reputation), organizational [[Asset|assets]], individuals, other organizations, and the Nation, arising through the operation of an information system. <ref name="NISTIR7298"> [http://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7298r2.pdf NISTIR 7298 rev 2: Glossary of Key Information Security Terms, May 2013]</ref>}}<br />
 
{{definition|The process of identifying [[risk|risks]] to organizational operations (including mission, functions, image, or reputation), organizational [[Asset|assets]], individuals, other organizations, and the Nation, arising through the operation of an information system. <ref name="NISTIR7298"> [http://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7298r2.pdf NISTIR 7298 rev 2: Glossary of Key Information Security Terms, May 2013]</ref>}}<br />

Revision as of 01:56, 28 June 2015

Definitions

European Definitions

Council Directive 2008/114/EC

The consideration of relevant threat scenarios, in order to assess the vulnerability and the potential impact of disruption or destruction of critical infrastructure. [1]


National Definitions

Australia

Risk analysis is a systematic use of available information to determine how often specified events may occur and the magnitude of their likely consequences. [2]


Process to comprehend the nature of risk and to determine the level of risk. [3]


Canada

A process to comprehend the nature of a risk and to determine its level. [4]

Processus mis en œuvre pour comprendre la nature d’un risqué et pour déterminer son niveau. [5]


Czech Republic

Process of understanding the nature of risks and establishing a risk level. [6]


India

Risk analysis is the process of identifying security risks, determining their magnitude, and identifying areas needing safeguards. [7]

Note: Only a trier of fact (someone with the authority to resolve disputes) can make an ultimate determination of non-repudiation.

Luxembourg

Analyse de risques: examen des scénarios de menace pertinents destiné à évaluer les vulnerabilities d'infrastructures critiques et les impacts potentiels de leur arrêt ou destruction. [8]


United States

The process of identifying risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation, arising through the operation of an information system. [9]


Standard Definition

ISO/IEC 27000:2014 and ISO 31000:2009

Process to comprehend the nature of risk and to determine the level of risk (based on the ISO Guide 73:2009) [10] [11]

Level of risk is expressed in terms of the combination of consequences and their likelihood.


See also

Notes