What is the difference between a risk assessment and a risk analysis?
Security+ Flashcards: Governance, Risk, Compliance, Frameworks, Security Policies
Audio flashcard · 0:24Nortren·
What is the difference between a risk assessment and a risk analysis?
0:24
A risk assessment is the overall process of identifying threats, vulnerabilities, and potential impacts to an organization's assets, resulting in a prioritized list of risks. It answers what can go wrong, how likely it is, and how bad it would be. Risk analysis is a component within the assessment that evaluates the likelihood and impact of identified risks, either qualitatively using ratings like high, medium, and low, or quantitatively using monetary values.
csrc.nist.gov