There are two different approaches to risk management and they are qualitative and quantitative risk assessments. Let's look at both of them:
- Qualitative Risk Analysis: Qualitative risk analysis is when the risk is evaluated as a high, medium, or low risk.
- Quantitative Risk Analysis: Quantitative risk analysis is where you look at the high qualitative risks and give them a number value so that you can associate them with a cost for the risk.
In this example, we are going to grade a risk and its probability from 1 - 9, with 1 being low and 9 being high. If we look at the impact of losing a mail server, the qualitative risk analysis would say that it is high, but the probability of losing it would be low:
Qualitative | Probability | Quantitative risk |
9 | 3 | 9*3=27 |