Risk factor (computing)


In Information security, Risk factor is a collective name for circumstances affecting the likelihood or impact of a security risk.

Definitions

FAIR

is devoted to the analysis of different factors influencing IT risk. It decompose at various levels, starting from the first level Loss Event Frequency and Probable Loss Magnitude, going on examining the asset, the threat agent capability compared to the vulnerability and the security control strength, the probability that the agent get in contact and actually act against the asset, the organization capability to react to the event and the impact on stakeholders.

ISACA

Risk factors are those factors that influence the frequency and/or business impact of risk scenarios; they can be of different natures, and can be classified in two major categories:
An IT risk risk scenario is a description of an IT related event that can lead to a business impact, when and if it should occur.
Risk factors can also be interpreted as causal factors of the scenario that is materialising, or as vulnerabilities or weaknesses. These are terms often used in risk management frameworks.
Risk scenario is characterized by:
The risk scenario structure differentiates between loss events, vulnerabilities or vulnerability events
, and threat events. It is important not to confuse these risks or throw them into one large risk list.