Assessing the Likelihood and Impact Assessment
摘要
There is a tendency to assess risks alone based on potential impacts and existing vulnerabilities. However, as previously accounted for, the likelihood of a cyber security event happening is the product of the threat and the vulnerability. This also means that if either of these two factors is close to non-existent, so will the likelihood be, and this should be considered when quantifying the likelihood.