Difference between revisions of "Risk Analysis"

From CIPedia
Jump to navigation Jump to search
(Created page with "==Definitions== === Official European Definition === The consideration of relevant threat scenarios, in order to assess the vulnerability and the potential impact ...")
 
Line 11: Line 11:
  
 
===Standard Definition===
 
===Standard Definition===
 +
=== ISO/IEC 27000:2014 ====
 +
Process to comprehend the nature of [[risk]] and to determine the level of risk (based on the ISO Guide 73:2009) <ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref>. Level of risk is expressed in terms of the combination of [[consequence|consequences]] and their [[likelihood]].
 +
* Risk analysis provides the basis for [[Risk Evaluation]] and decisions about [[Risk Treatment]].
 +
* Risk analysis includes [[Risk Estimation]].
 +
  
 
==See also==
 
==See also==
 
* [[Risk]]
 
* [[Risk]]
 +
* [[Risk Estimation]]
 +
* [[Risk Evaluation]]
 +
* [[Risk Treatment]]
 +
 
==Notes==
 
==Notes==
 
<references />
 
<references />

Revision as of 17:05, 21 May 2014

Definitions

Official European Definition

The consideration of relevant threat scenarios, in order to assess the vulnerability and the potential impact of disruption or destruction of critical infrastructure [1].

Other International Definitions

National Definitions

Standard Definition

ISO/IEC 27000:2014 =

Process to comprehend the nature of risk and to determine the level of risk (based on the ISO Guide 73:2009) [2]. Level of risk is expressed in terms of the combination of consequences and their likelihood.


See also

Notes