Risk Assessment
Security
Structured process to identify, evaluate, and prioritize risks and mitigations.
Definition
Risk assessment evaluates threats, vulnerabilities, likelihood, and impact, then defines mitigations and residual risk acceptance. It can be privacy-focused (DPIA) or broader security risk management.
Why this matters
Why it matters: Risk-driven controls reduce harm and ensure resources go to the highest-impact protections.
Example
Example: Map data flows, rank risks (unauthorized access, leakage, inference), assign owners, and track mitigations with review dates.