Module 2~8 min
Assessing Risk
Security teams can't eliminate every possible danger, so they focus on understanding and managing risk instead.
What You'll Learn
- What risk means in a security context
- How likelihood and impact relate to risk
- Why organizations prioritize risks
What Risk Means
Risk describes the potential for loss or harm when a threat exploits a vulnerability. It's typically thought of as a combination of how likely something is to happen and how much damage it would cause.
Prioritizing Risk
Because no organization has unlimited resources, security teams prioritize the risks that are both likely and damaging, addressing those first.
Example
A rare but catastrophic risk and a common but minor risk might both get attention, but a common and catastrophic risk would typically be addressed first.
Key Concepts
RiskLikelihoodImpact
Key Takeaways
- Risk combines the likelihood of an event with its potential impact
- Organizations prioritize risks rather than trying to eliminate everything
- The most likely and damaging risks are usually addressed first
Knowledge Check
Risk is typically thought of as a combination of what two factors?