Risk Analysis

Risk analysis is the step in risk management that estimates identified risks by likelihood and impact. Whether a risk is acceptable is decided by the risk evaluation that follows. BSI Standard 200-3, by contrast, uses risk analysis for the whole process up to and including risk treatment.

RisikomanagementLast reviewed:

What is a risk analysis?

A risk analysis estimates, for each identified risk, how likely it is to occur and how much damage it would cause. In risk management it sits between risk identification and risk evaluation, which decides whether the risk is acceptable. Identification, analysis and evaluation together make up the risk assessment.

The separation has a practical reason: setting size and acceptability in one step means rating against a yardstick that is written down nowhere. The techniques available for the analysis are compared in the guide to risk analysis methods.

ISO 31000 and BSI Standard 200-3 use the term differently

BSI Standard 200-3 from the German Federal Office for Information Security (BSI) calls the whole process a risk analysis, from identification through to risk treatment. Under ISO 31000 and ISO/IEC 27005, by contrast, risk analysis is only one step of the risk assessment. The standard says so itself in chapter 1.3, and its comparison in chapter 9.4 maps the steps as follows:

Step under ISO 31000Counterpart in BSI Standard 200-3Chapter
Risk identificationCompiling an overview of threats (Gefährdungsübersicht)4
Risk analysisRisk estimation (Risikoeinschätzung)5.1
Risk evaluationRisk evaluation (Risikobewertung)5.2
Risk treatmentRisk treatment (Risikobehandlung)6

When an auditor, a contract or an authority asks for "a risk analysis", clarify which reading is meant. Under IT-Grundschutz, treatment is part of it; in the vocabulary of ISO 31000, it is not.

When does BSI Standard 200-3 require a risk analysis?

Under IT-Grundschutz, BSI Standard 200-3 requires an explicit risk analysis for target objects that meet one of three conditions:

  • They have a high or very high protection need in at least one of the basic values of confidentiality, integrity or availability.
  • They cannot be adequately modelled with the existing IT-Grundschutz modules.
  • They are operated in scenarios that IT-Grundschutz does not provide for.

The protection need comes beforehand from the protection requirements assessment. The analysis itself has two stages: the first rating assumes the measures already implemented or planned, the second the measures for risk treatment. The before-and-after comparison shows whether the treatment works.

What belongs in a sound risk analysis?

A sound risk analysis describes each risk so that a second person can follow the rating:

ItemExample
Affected assetERP system with the ordering process
Threat and exploited vulnerabilityransomware via an unpatched VPN gateway
Controls already in effectoffline backup, endpoint protection
Likelihood with a time referenceonce in ten years
Impactordering process down for five days
Risk ownerhead of purchasing

The example is invented for illustration. Without a time reference, likelihood cannot be interpreted: "rare" is not a statement, "once in ten years" is. Which level follows from likelihood and impact is set by the risk matrix.

Record the risk without controls and with the controls in effect today separately. Only the gap shows which control carries the result; the terms are explained in the entry on inherent risk.

Qualitative or quantitative: what BSI Standard 200-3 says

BSI Standard 200-3 regards quantitative risk analysis as highly demanding, because it requires extensive statistical data. It therefore works with qualitative categories and recommends no more than five per dimension. Where loss amounts and event frequencies are available for a risk, the quantitative route is still possible. Amounts and likelihoods per year can be added up and compared with the cost of controls; levels cannot.

ISO/IEC 27001 and the law make risk analysis binding

The guidance documents on risk analysis cannot be certified; risk analysis becomes binding only through a requirements standard or a law.

BasisTypeRole for risk analysis
ISO 31000guidance, not certifiablegeneral framework and vocabulary of the risk process
ISO/IEC 27005:2022guidance, not certifiableapplication to information security risks
BSI Standard 200-3BSI standard under IT-Grundschutzprocedure for the supplementary risk analysis
ISO/IEC 27001, clauses 6.1.2 and 6.1.3certifiable requirements standarddefined, repeatable process for assessing and treating risks
Regulation (EU) 2022/2554 (DORA), Chapter IIregulation, for financial entitiesICT risk management, Articles 5 to 16

How Rizzqo keeps a risk assessment traceable

Rizzqo keeps a risk assessment traceable by holding its factors separately instead of condensing them into a score. Likelihood is held in percent, impact as an amount in euros. Configurable scale bands translate both values into your levels, and the risk level comes from a configurable matrix.

Each assessment keeps inherent, current and residual risk separate, similar to the before-and-after comparison in BSI Standard 200-3. This shows which part of the reduction comes from controls already in effect and which from controls still planned.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework