ELI5: What is Risk Assessment?

It’s like looking at all the things that could go wrong on a field trip and figuring out which ones to worry about most. Crossing a busy road? That’s high risk. Getting a mosquito bite? Not great, but not a big deal. A risk assessment helps a company look at each danger, decide how likely it is to happen and how bad it would be, and then focus on fixing the scariest ones first.

Overview

A risk assessment is the evaluation phase of risk management where identified threats and vulnerabilities are analyzed to determine their likelihood and potential impact. Organizations use qualitative, quantitative, or hybrid approaches to rank risks and decide which ones require immediate attention. Regular risk assessments ensure that the security posture adapts to evolving threats.

Key Concepts

  • Qualitative risk assessment — uses subjective ratings (high, medium, low) based on expert judgment; faster but less precise
  • Quantitative risk assessment — uses numerical values and formulas; more precise but requires reliable data
    • Asset Value (AV) — dollar value of the asset
    • Exposure Factor (EF) — percentage of asset lost in an incident
    • Single Loss Expectancy (SLE) — AV x EF
    • Annualized Rate of Occurrence (ARO) — how often the threat is expected per year
    • Annualized Loss Expectancy (ALE) — SLE x ARO
  • heat map — visual tool plotting likelihood vs. impact
  • Threat assessment — evaluating threat sources and their capabilities
  • Vulnerability assessment — identifying weaknesses that could be exploited
  • Ad hoc vs. recurring vs. continuous — assessments may be triggered by events, scheduled, or ongoing
  • Environmental factors — internal (staffing, technology) and external (regulatory, geopolitical)

Exam Tips

Remember

Quantitative = numbers and dollar values. Qualitative = categories and expert opinion. The exam loves SLE/ALE/ARO calculations. If ALE > cost of control, implement the control.

Connections

Practice Questions

Scenario

See case-risk-assessment for a practical DevOps scenario applying these concepts.