The idea
Cybersecurity risk concerns potential harm arising from threats and vulnerabilities. Likelihood and impact help inform priorities; a risk score is an aid to judgement, not a precise prediction.
- An asset is something valuable that needs protecting.
- A threat has the potential to cause harm.
- A vulnerability is a weakness that could be exploited.
- A control helps modify the risk.
A fictional example
An unpatched internet-facing service may expose an organisation to compromise. The priority depends on the weakness, exposure, available exploitation and the consequences for the service and its users.
Responding to risk
Options include reducing, avoiding, sharing or accepting risk. Decisions should have an accountable owner. Remaining risk needs to be understood and reviewed when circumstances change.