Risk Evaluation

From CIPedia
Revision as of 20:44, 1 January 2017 by Eluiijf (talk | contribs)
Jump to navigation Jump to search

Definitions

European Definitions

ENISA

Risk Evaluation is the process of comparing the estimated risk against given risk criteria to determine the significance of risk (refers to ISO/IEC Guide 73). [1]


European Project Definitions

CIPRNet project

The CIPRNet project [2] uses the following definition:

risk evaluation is the process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable.



Other International Definitions

UNISDR

Évaluation des risques: Méthodologie pour déterminer la nature et l’étendue des risques à travers une analyse dis risques potentiels et l’évaluation des conditions existantes de la vulnérabilité qui, associées, pourrait affecter les populations, établissements, servies, subsistance. [3]


Evaluación del riesgo: Una metodología para determinar la naturaleza y el grado de riesgo a través del análisis de posibles amenazas y la evaluación de las condiciones existentes de vulnerabilidad que conjuntamente podrían dañar potencialmente a la población, la propiedad, los servicios y los medios de sustento expuestos, al igual que el entorno del cual dependen. [4]


Penilaian Risiko : Metodologi bagi menentukan kejadian dan punca risiko dengan menganalisis potensi bahaya – bahaya berlaku dan menilai kerentanan sedia ada, kerana apabila bergabung, ia berpotensi membahayakan orang awam, harta benda, perkhidmatan, kehidupan dan alam sekitar yang sangat diperlukan. [5]



National Definitions

Australia

Risk evaluation is the process in which judgements are made on the tolerability of the risk on the basis of risk analysis and taking into account factors such as socioeconomic and environmental aspects. [6]


Risk evaluation is the process used to prioritise risks. [6]


Process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. [7]



Bosnia and Herzegovina

Evaluacija rizika je proces upoređivanja rezultata analize rizika sa kriterijumima rizika da se utvrdi da li se rizik i/ili njegova veličina mogu tolerisati. (ISO 31010) [8]



Canada

The process of comparing the results of risk analysis with risk criteria to determine whether a risk and/or its magnitude is acceptable or tolerable. [9]

Processus de comparaison des résultats de l’analyse de risques avec les critères de risque afin de déterminer si un risque ou son importance sont acceptables ou tolérables. [10]



Finland

Risk evaluation is a part of Risk Management in which, on the basis of Risk Analysis information, the effect and tolerability of risks are considered and through which information basis for decision making in Risk Management is formed.

Riskin merkityksen arviointi / riskin arvottaminen: riskienhallinnan osa, jossa riskianalyysin tietojen pohjalta pohditaan riskien vaikutusta ja siedettävyyttä ja jonka avulla muodostetaan tietopohja riskienhallinnan päätöksen tekoa varten. [11]



Netherlands

[Dutch] Risicobeoordeling is het proces waarin de resultaten van de risicoanalyse worden vergeleken met het maximaal te accepteren risico. [12]



Switzerland

Die Risikobewertung umfasst den Prozess des Entscheidungsträgers und/oder der betroffenen Gemeinschaft, bei dem festgestellt wird, ob die definierten Schutzziele eingehalten sind. [13]

L’appréciation des risques englobe le processus appliqué par le décideur et/ou la collectivité concernée pour vérifier si les objectifs de protection définis sont remplis. [14]

La ponderazione dei rischi è il processo adottato dall’organo decisionale e/o dalla comunità per appurare se gli obiettivi di protezione predefiniti sono stati raggiunti. [15]



Standard Definition

ISO/IEC 27000:2014 and ISO 31000:2009

Process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. [16] [17]
(based on the ISO Guide 73:2009[18])

  • Risk criteria are the terms of reference against which the significance of risk is evaluated. [18]. They are based on organizational objectives, and external and internal context, and can be derived from standards, laws, policies and other requirements.
  • Risk evaluation assists in the decision about risk treatment.

See also

Notes