Risk analysis
Risk analysis is the structured assessment of the risks affecting an organisation’s assets, systems and operations, so that decisions about them can be made on evidence rather than instinct.
Risk analysis is the structured assessment of the risks affecting an organisation’s assets, systems and operations, so that decisions about them can be made on evidence rather than instinct.
Its purpose is to identify, evaluate and rank the threats and weaknesses that could affect the confidentiality, integrity or availability of information, and to produce something a decision can be taken from: what gets mitigated, what gets accepted, what gets transferred.
It is continuous rather than annual. Systems change, threats change, and an analysis describes the organisation as it was on the day it was done.
The stages
Identify assets and threats. What the business actually depends on, and what could plausibly go wrong for each of those things, from inside as well as from outside.
Assess weaknesses. Where the design, the implementation or the configuration would let one of those threats succeed.
Estimate the risk. Likelihood and impact, quantitative or qualitative, arriving at a magnitude that can be compared with another one. Comparability is the point; precision is not available and pretending otherwise is how these exercises lose credibility.
Rank. So that finite money and finite attention go to the top of the list rather than to whatever was raised most recently.
Decide treatment. Controls to implement, policies to change, technology to adopt, and the risks the organisation is knowingly choosing to carry. That last category has to be written down and owned by somebody, or it is not a decision.
A worked example
A financial services firm runs an analysis on its online customer system.
It identifies a threat: phishing aimed at its customers. It identifies the weakness that makes the threat work: authentication that relies on a password alone.
It estimates the risk from how likely such a campaign is and what a successful one would cost, in customer data and in reputation.
Having ranked it near the top, the firm implements multi-factor authentication, runs awareness training for customers, and starts monitoring for the signs of an attempt in progress.
The value of the exercise is not the number it produced. It is that the control was chosen because of what it addressed, and that the choice can be explained afterwards.
Risk analysis, risk model, and the three entries around them
Start with the confusion closest to home. This entry and risk model describe the same territory at different grain, and they are written that way: the model is the structure you measure with (what counts as an asset, which scales of likelihood and impact, which acceptance threshold), and the analysis is the pass of applying it to a defined scope and coming out with an ordered list.
An information security management system (ISMS) sits above both. It sets the scope, records treatment decisions in a statement of applicability, and reviews them. The standard does not certify a list of controls, it certifies that this system works, and risk analysis is its main input.
Threat modelling looks at one system in its design rather than at a portfolio of assets. It is a neighbouring method rather than a substitute: it answers how this could fail, not what it would cost us.
Exposure management is the operational loop at the other end: what is reachable today, which of it is genuinely exploitable, and in what order it gets fixed. Risk analysis orders by estimated likelihood and impact; exposure management orders by what has been demonstrated to work. The two lists do not come out the same, and that difference is information rather than a contradiction.
And the failure that makes the whole exercise worthless: doing it once for the certificate and never returning. An analysis from last year describes an organisation that no longer exists, and the certificate remains valid the whole time.