Risk assessment methodologies
An IT risk manager should be hands-on when it comes to performing a risk analysis. The results of a risk analysis directly impact the risk response and, consequently, the resources allocated to each risk area. Therefore, the risk manager should be able to guide and perform the risk analysis and propose a risk response.
There are two primary types of risk analysis—qualitative risk analysis and quantitative risk analysis.
As the name suggests, qualitative risk analysis is based on qualitative parameters such as High, Medium, Low, and Very Low to depict the level of risk. These parameters are assigned to each risk scenario according to their likelihood and impact based on the experience and expertise of the group conducting the risk analysis and therefore may result in subjective outcomes.
On the contrary, quantitative risk analysis is more measured and aims to provide the monetary value at risk if the risk scenario materializes. This type...