Risk Probability and Impact
Probability is
the chance that a risk will occur
Impact is
the potential effect of an event. As with an event, an impact may be positive or negative
Assessment of Exposures
A 5x5 matrix is shown below to assess the exposure. A 3x3 (High, Medium, Low) or a 4x4 (low to very high) may also be used:


See next section for IT Controls
Probability can be determined using following table:

DREAD Model originated at Microsoft Corporation and used to asses risk:
Damage β how bad would an attack be?
Reproducibility β how easy is it to reproduce the attack?
Exploitability β how much work is it to launch the attack
Affected users β how many people will be impacted?
Discoverability β how easy is it to discover the threat?
Last updated
Was this helpful?