overall process (3.1.190) of risk identification (3.1.223), risk analysis (3.1.217) and risk evaluation (3.1.222) Note 1 to entry: Risk assessment involves the process of identifying internal and external threats (3.1.277) and vulnerabilities, identifying the likelihood (3.1.142) and impact (3.1.119) of an event (3.1.96) arising from such threats or vulnerabilities, defining critical functions necessary to continue the organization’s (3.1.165) operations, defining the controls in place necessary to reduce exposure, and evaluating the cost of such controls. Note 2 to entry: Risk assessment is described in detail in ISO 31000:2018.
целокупни процес (3.1.190) идентификације ризика (3.1.223), анализе ризика (3.1.217) и вредновања ризика (3.1.222)