Skip to content

Risk Assessment

What is Risk Assessment?

The process of identifying, analysing, and evaluating risks. Includes identifying assets and threats, assessing likelihood and impact, and determining risk treatment options.

Risk Management

What the standards actually require on risk assessment

Requirements naming risk assessment across 6 standards, quoted from the control text.

Article 25 establishes the MEMBER STATE cybersecurity risk assessment - the third level of the four-level cascade. Member State competent authorities conduct national cybersecurity risk assessments for their in-scope electricity entities, building on the Union...

NCCS-Art.25_26 · Member State cybersecurity risk assessment (NCCS Articles 25-26) - third level of the cascade
ISO 22301:20198 controls

Run and maintain the processes that establish what disruption would cost the organization over time and what could cause it, and refresh both whenever the organization or its operating context changes significantly.

iso-22301-2019::8.2 · Business impact analysis and risk assessment
C5 (Germany)7 controls

Assess each planned change for its potential effect on the system components involved and assign it a risk category and priority, which then determine how deeply it is tested and what approvals it must carry.

C5-DEV-05 · Risk assessment, categorisation and prioritisation of changes

16 CFR 314.4(b) risk assessment. REQUIREMENT: financial institution must conduct a WRITTEN RISK ASSESSMENT to identify reasonably foreseeable internal + external risks to the security + confidentiality + integrity of customer information that could result in u...

FTC-Safeguards-Risk-Assessment · Written Risk Assessment (16 CFR 314.4(b))

Suppliers identified as high risk by a cyber supply chain risk assessment are not used.

ISM-1567 · Suppliers identified as high risk by a cyber supply chain risk assessment are not used.

Risk assessment procedures. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.

BSI-13 · Risk assessment procedures

Questions people ask about risk assessment

What is Risk Assessment?
The process of identifying, analysing, and evaluating risks. Includes identifying assets and threats, assessing likelihood and impact, and determining risk treatment options.
Why is Risk Assessment important for compliance?
Risk Assessment is a key concept in Risk Management. Understanding risk assessment helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Risk Assessment?
Key concepts related to Risk Assessment include Risk Treatment, Risk Register, ISMS (Information Security Management System). Understanding these interconnected concepts provides a more comprehensive view of Risk Management requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Risk Assessment?
Risk Assessment appears in the requirement text of EU Network Code on Cybersecurity for the Electricity Sector, ISO 22301:2019, C5 (Germany), FTC GLBA Safeguards Rule (16 CFR Part 314), Australian Information Security Manual. Across these standards we have identified 43 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Assessment?
Explore our compliance framework pages to see how risk assessment applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Assessment applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.