Risk Assessment is the process of identifying and evaluating risks to an organization’s assets. It inventories what matters, identifies the threats and vulnerabilities against each asset, estimates how likely a loss is and how much it would hurt, and produces risk levels that tell leadership where to spend limited security budget first.
Two approaches exist, and mature programs blend them. Quantitative assessment attaches dollar figures using formulas such as Annual Loss Expectancy, where ALE equals SLE multiplied by ARO. Qualitative assessment uses ratings like high, medium, and low where hard numbers are not available. The common error is forcing precise-looking quantitative math onto guesses, since a confident dollar figure built on invented probabilities misleads more than an honest qualitative rating. It also pays to revisit an assessment after major changes, since a new system, vendor, or regulation can shift the risk picture faster than an annual cycle would catch.
How is risk assessment tested on the CISSP?
Domain 1: Security and Risk Management covers this in depth. Know the quantitative terms SLE, ARO, ALE, and EF, when quantitative or qualitative methods fit, and how assessment results drive risk treatment choices and program priorities.