MemotivaSecurity+ Flashcards: Governance, Risk, Compliance, Frameworks, Security Policies

What is the difference between a risk assessment and a risk analysis?

Security+ Flashcards: Governance, Risk, Compliance, Frameworks, Security Policies

Audio flashcard · 0:24

Nortren·

What is the difference between a risk assessment and a risk analysis?

0:24

A risk assessment is the overall process of identifying threats, vulnerabilities, and potential impacts to an organization's assets, resulting in a prioritized list of risks. It answers what can go wrong, how likely it is, and how bad it would be. Risk analysis is a component within the assessment that evaluates the likelihood and impact of identified risks, either qualitatively using ratings like high, medium, and low, or quantitatively using monetary values.
csrc.nist.gov