Risk Analysis
What is Risk Analysis?
The systematic examination of risk components including threat sources, vulnerabilities, likelihood, and potential impact to understand and characterize risk.
Terms that appear alongside risk analysis
Each of these is named in at least one of the same controls as risk analysis. The number is how many controls name both.
- risk assessment 15 shared controls
- audit 13 shared controls
- vulnerability 9 shared controls
- compliance 9 shared controls
- integrity 9 shared controls
- availability 8 shared controls
- authentication 7 shared controls
- due diligence 7 shared controls
Frameworks that govern risk analysis
What the standards actually require on risk analysis
Requirements naming risk analysis across 6 standards, quoted from the control text.
Establish and maintain a program of risk analysis and oversight covering operations and automated systems, to identify and minimise sources of operational risk through appropriate controls and procedures and through systems that are reliable, secure and have a...
CFTC-SS-1 · Program of Risk Analysis and Oversight →Combine likelihood and impact determinations to assign a risk level to each threat and vulnerability pairing using a defined risk matrix.
RA-RISK · Risk Analysis: Determine the Level of Risk →If periodic scans are used to meet 5.3.2, the frequency is defined in the entity's targeted risk analysis.
5.3.2.1 · Periodic scan frequency per targeted risk analysis →LkSG Sections 4-5 - risk management system + risk analysis. SECTION 4 RISK MANAGEMENT SYSTEM: companies must establish an APPROPRIATE + EFFECTIVE risk management system to identify + prevent + mitigate + remediate human rights and environmental risks arising f...
LkSG-Sec4-RiskMgmt-Sec5-RiskAnalysis · Section 4 Risk Management System + Section 5 Annual Risk Analysis →Analyse identified AI risks considering causes, consequences, controls, uncertainty, and AI-specific characteristics.
23894-6.4.3 · AI Risk Analysis →Requirement defined in ISO 31000:2018, clause 6.4.3 (Risk analysis). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-31000-2018::6.4.3 · Risk analysis →Questions people ask about risk analysis
What is Risk Analysis?
Why is Risk Analysis important for compliance?
Which compliance frameworks address Risk Analysis?
Where can I learn more about Risk Analysis?
See how Risk Analysis applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.