Risk
Pronunciation: RISK
Definition
Risk is the effect of uncertainty on objectives, including the possibility that events or conditions produce harmful or beneficial outcomes. Decision-makers use Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified. A score for Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions.
Overview
Risk connects uncertainty with something an organization or person values. It is commonly described through scenarios involving assets, objectives, threats, vulnerabilities, likelihood, consequences, time horizon, and the confidence attached to available evidence.
Risk is not identical to a threat, vulnerability, loss, or probability. The same event can create different risk for different parties because exposure, dependencies, controls, objectives, and ability to recover vary.
Effective management states the decision context, identifies plausible scenarios, estimates uncertainty, assigns owners, selects treatment, and monitors change. Numerical scores can support comparison but should not conceal assumptions, data limitations, tail events, or impacts that are difficult to quantify. Risk communication should distinguish known facts, estimates, assumptions, and unresolved uncertainty.
In practice, Risk should be evaluated with security so preventive controls, risk decisions, and response evidence remain connected.
Risk is the effect of uncertainty on objectives, including the possibility that events or conditions produce harmful or beneficial outcomes. Decision-makers use Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified. Risk is decision-focused uncertainty about objectives, requiring explicit scenarios, evidence, ownership, treatment, and awareness of measurement limits.
For Risk, the assessment should evaluate the possibility that events or conditions produce harmful or beneficial outcomes. The assessment record should separate observed evidence supporting the possibility that events or conditions produce harmful or beneficial outcomes from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that events or conditions produce harmful or beneficial outcomes have changed enough to require a new rating, treatment, or approval.
Key Takeaway
Risk is decision-focused uncertainty about objectives, requiring explicit scenarios, evidence, ownership, treatment, and awareness of measurement limits.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)