Identifying threats and choosing the right approach
When conducting a risk assessment, the first step is identifying potential threats your organization may encounter. This list should include the following:
- Threat: A threat refers to any situation or event that has the potential to cause harm to your organization’s operations, resources, reputation, personnel, other organizations, or even national security through an information system
- Threat source: The intent and method aimed at intentionally exploiting a vulnerability or a situation that may accidentally lead to vulnerability exploitation
- Description: A brief narrative that defines the threat and threat source pairing, ensuring consistent application of this information throughout the risk management process
The choice between qualitative and quantitative risk assessments depends on the organization’s needs and the evaluated risks. Organizations may choose to use a combination of both qualitative...