The risk is assessed by identifying the vulnerabilities and threats, and then determining the likelihood and also the impact it brings.
A critical grade vulnerability in a web server has a higher risk in a public facing website than one in an internal website that is accessed only by the employees.
Even though the vulnerability might have a critical score, the associated risk varies depending on the organizations and the place it is deployed.
There are two important things to remember when assessing the risk:
- Determining the likelihood
- Defining the impact