TechKnowSurge
NIST CSF ID.RA-05 NIST 800-53 RA-3 CompTIA Security+ 5.2 ISC2 CISSP 1.9 NIST 800-53 RA-4 NIST CSF GV.OV-02 CompTIA SecurityX 1.3 NIST 800-53 PM-31
VideoSecurityFree

Risk Assessment

Risk assessment is a core component of risk management that involves identifying, analyzing, and prioritizing the risks facing an organization. The process produces a formal report that guides decision-making and risk mitigation efforts.

Complete this video to capture a CTF flag worth 1 point.

About this video

Risk assessment is a structured process of identifying, analyzing, and prioritizing the risks that affect an organization, and it sits at the heart of any effective risk management program. By examining a wide range of risk sources and evaluating their potential impact, the process produces a clear picture of where the organization is most exposed. The output is a formal risk assessment report that consolidates all identified risks, supporting data, and analytical findings into a prioritized view that decision-makers can act on. Assessments are not necessarily a one-time event. Organizations may conduct them on a scheduled basis, such as annually or quarterly, to maintain an ongoing understanding of their risk posture. They may also be triggered by specific events, such as a customer requesting an updated assessment or the identification of a new threat, or supported by continuous monitoring that allows the risk register to be updated in near real time. The frequency and approach depend on the size, complexity, and security maturity of the organization. Vulnerability management is closely related to risk assessment and feeds directly into it within a security operations context. The findings generated through vulnerability scanning and analysis contribute to a more complete and accurate risk assessment, reinforcing that risk management is not a siloed function but an integrated discipline that draws on multiple data sources to produce actionable intelligence.

What you'll learn

What's covered

Risk Assessment

Aligned to

NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks.
NIST 800-53
RA-3 Risk Assessment
RA-4 Risk Assessment Update
PM-31 Continuous Monitoring Strategy
CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing vulnerabilities in a system.
Risk Prioritization
The process of ranking identified risks by their potential impact and likelihood to determine which require the most urgent attention.
Continuous Monitoring
An ongoing process of collecting and analyzing data about an organization's systems and risks to maintain an up-to-date risk posture.

Topics

Risk Assessment Risk Management Risk Identification Risk Analysis Risk Prioritization Cybersecurity Governance

Transcript

What a risk assessment is

Something that we're going to want to perform as part of our risk management process is a risk assessment. It's one of the key parts to a risk management program.

Not surprisingly, a risk assessment is just assessing all of the risk that's associated with a business. So we're going to take a look at a lot of different sources, all these different things that play into this full-on risk assessment, where in the end we're going to analyze all of these risks and see what the priority risks are — what is causing the most risk to the organization.

Really, the end result of this risk assessment process is going to be a report, a report that's going to have all sorts of data involved and analysis involved. It's going to have all the risks listed out, and what is going to be the top risks. So it's going to be this assessment of all of the risks, and this report is going to be created.

Risk assessment is really about identifying those risks, doing analysis on those risks, and perhaps doing some sort of prioritization on those risks, so then we can take action against that report.

When we do risk assessments

So when do we do risk assessments? There are several different triggers to this.

For instance, maybe you just do an assessment and it's just a one-time assessment to figure out what you need to fix and what you need to tackle first.

For a full-on security operations, we really need to have some sort of reoccurring assessment that happens. Maybe it's going to be on an annual basis, perhaps it's on a quarterly basis. Monthly would be quite often — I don't see that as common, because there's a lot of effort that goes into these assessments.

Perhaps it's just ad hoc, both from the perspective of maybe we do some updates throughout the year when we see or recognize something new, or perhaps we create a new one because something triggered it — like maybe one of our customers is asking for an updated version of this, and so we have to just go through this assessment process and do it.

Or maybe there's some sort of continuous monitoring of our systems, and we're constantly adding to and adjusting this risk assessment and the risk assessment report.

I will call out that other function of vulnerability management when it comes to security operations: some of what vulnerability management is going to do will actually creep into our risk assessment, that it's a part of this whole risk assessment.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →