Difference between revisions of "Risk Analysis"

From CIPedia
Jump to navigation Jump to search
Line 2: Line 2:
 
=== European Definitions ===
 
=== European Definitions ===
 
==== [[EU|Council Directive 2008/114/EC]] ====  
 
==== [[EU|Council Directive 2008/114/EC]] ====  
{{definition|The consideration of relevant [[threat]] scenarios, in order to assess the [[vulnerability]] and the potential [[impact]] of [[disruption]] or [[destruction]] of [[Critical Infrastructure|critical infrastructure]]. <ref> [http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2008:345:0075:0082:EN:PDF Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection.]</ref>}}
+
{{definition|The consideration of relevant [[threat]] scenarios, in order to assess the [[vulnerability]] and the potential [[impact]] of [[disruption]] or [[destruction]] of [[Critical Infrastructure|critical infrastructure]]. <ref> [http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2008:345:0075:0082:EN:PDF Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection.]</ref>}}<br />
 +
====[[ENISA]]====
 +
{{definition|Risk Analysis is the systematic use of information to identify sources and to estimate the [[risk]] (refers to [[ISO|ISO/IEC Guide 73]]). <ref name="ENISAGlos"> [http://www.enisa.europa.eu/activities/risk-management/current-risk/risk-management-inventory/glossary ENISA Risk Glossary]</ref>}}<br />
  
 
<!---
 
<!---
Line 57: Line 59:
 
[[Category:Risk]]
 
[[Category:Risk]]
 
[[Category:Analysis]]
 
[[Category:Analysis]]
{{#set:defined by=EU|defined by=Australia|defined by=Canada|defined by=Czech Republic|defined by=Finland|defined by=India|defined by=Luxembourg|defined by= Netherlands|defined by=United States|defined by=ISO}}
+
{{#set:defined by=EU|defined by=ENISA|defined by=Australia|defined by=Canada|defined by=Czech Republic|defined by=Finland|defined by=India|defined by=Luxembourg|defined by= Netherlands|defined by=United States|defined by=ISO}}

Revision as of 00:26, 21 July 2015

Definitions

European Definitions

Council Directive 2008/114/EC

The consideration of relevant threat scenarios, in order to assess the vulnerability and the potential impact of disruption or destruction of critical infrastructure. [1]


ENISA

Risk Analysis is the systematic use of information to identify sources and to estimate the risk (refers to ISO/IEC Guide 73). [2]



National Definitions

Australia

Risk analysis is a systematic use of available information to determine how often specified events may occur and the magnitude of their likely consequences. [3]


Process to comprehend the nature of risk and to determine the level of risk. [4]


Canada

A process to comprehend the nature of a risk and to determine its level. [5]

Processus mis en œuvre pour comprendre la nature d’un risqué et pour déterminer son niveau. [6]


Czech Republic

Proces pochopení povahy rizika a stanovení úrovně rizika. [7]

Process of understanding the nature of risks and establishing a risk level. [8]


Finland

Riskianalyysi: toiminta, jossa tunnistetaan riskit ja arvioidaan vahinkotapahtuman todennäköisyys sekä odotettavissa olevat vahingot.

Risk analysis is the action for identifying risk and estimating the probability of a damaging event as well as anticipated damages. -unofficial translation- [9]


India

Risk analysis is the process of identifying security risks, determining their magnitude, and identifying areas needing safeguards. [10]


Luxembourg

Analyse de risques: examen des scénarios de menace pertinents destiné à évaluer les vulnerabilities d'infrastructures critiques et les impacts potentiels de leur arrêt ou destruction. [11]


Netherlands

Risk analysis is a method which takes stock of the risk, which risk factors are unacceptable, and which measures can mitigate the risk.

Risicoanalyse is een methode die inventariseert welke risico's er zijn, welke daarvan onacceptabel zijn en welke maatregelen de risico's kunnen reduceren. [12]


United States

The process of identifying risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation, arising through the operation of an information system. [13]


Standard Definition

ISO/IEC 27000:2014 and ISO 31000:2009

Process to comprehend the nature of risk and to determine the level of risk (based on the ISO Guide 73:2009) [14] [15]

Level of risk is expressed in terms of the combination of consequences and their likelihood.


See also

Notes