Risk assessment identifies risks, analyzes their likelihood and impact, and evaluates them against the organization's criteria so they can be prioritized. The purpose is to choose and fund controls in proportion to risk. There are three broad ways to analyze risk: qualitative, quantitative and semi-quantitative. The CISM exam expects you to know how each works, its strengths and weaknesses, and when each fits. Whatever the method, a good assessment follows the same steps: define scope and criteria; identify assets and their value, threats, vulnerabilities and existing controls; estimate likelihood and impact; evaluate the results against appetite; and record them with owners. It is repeated periodically and whenever significant change occurs.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.