← Back to glossary

Structured process to identify, evaluate, and prioritize risks and mitigations.

Definition

Risk assessment evaluates threats, vulnerabilities, likelihood, and impact, then defines mitigations and residual risk acceptance. It can be privacy-focused (DPIA) or broader security risk management.

In plain English Structured process to identify, evaluate, and prioritize risks and mitigations.

Why this matters

Why it matters: Risk-driven controls reduce harm and ensure resources go to the highest-impact protections.

Example

Example: Map data flows, rank risks (unauthorized access, leakage, inference), assign owners, and track mitigations with review dates.