What is a risk analysis?
A risk analysis estimates, for each identified risk, how likely it is to occur and how much damage it would cause. In risk management it sits between risk identification and risk evaluation, which decides whether the risk is acceptable. Identification, analysis and evaluation together make up the risk assessment.
The separation has a practical reason: setting size and acceptability in one step means rating against a yardstick that is written down nowhere. The techniques available for the analysis are compared in the guide to risk analysis methods.
ISO 31000 and BSI Standard 200-3 use the term differently
BSI Standard 200-3 from the German Federal Office for Information Security (BSI) calls the whole process a risk analysis, from identification through to risk treatment. Under ISO 31000 and ISO/IEC 27005, by contrast, risk analysis is only one step of the risk assessment. The standard says so itself in chapter 1.3, and its comparison in chapter 9.4 maps the steps as follows:
| Step under ISO 31000 | Counterpart in BSI Standard 200-3 | Chapter |
|---|---|---|
| Risk identification | Compiling an overview of threats (Gefährdungsübersicht) | 4 |
| Risk analysis | Risk estimation (Risikoeinschätzung) | 5.1 |
| Risk evaluation | Risk evaluation (Risikobewertung) | 5.2 |
| Risk treatment | Risk treatment (Risikobehandlung) | 6 |
When an auditor, a contract or an authority asks for "a risk analysis", clarify which reading is meant. Under IT-Grundschutz, treatment is part of it; in the vocabulary of ISO 31000, it is not.
When does BSI Standard 200-3 require a risk analysis?
Under IT-Grundschutz, BSI Standard 200-3 requires an explicit risk analysis for target objects that meet one of three conditions:
- They have a high or very high protection need in at least one of the basic values of confidentiality, integrity or availability.
- They cannot be adequately modelled with the existing IT-Grundschutz modules.
- They are operated in scenarios that IT-Grundschutz does not provide for.
The protection need comes beforehand from the protection requirements assessment. The analysis itself has two stages: the first rating assumes the measures already implemented or planned, the second the measures for risk treatment. The before-and-after comparison shows whether the treatment works.
What belongs in a sound risk analysis?
A sound risk analysis describes each risk so that a second person can follow the rating:
| Item | Example |
|---|---|
| Affected asset | ERP system with the ordering process |
| Threat and exploited vulnerability | ransomware via an unpatched VPN gateway |
| Controls already in effect | offline backup, endpoint protection |
| Likelihood with a time reference | once in ten years |
| Impact | ordering process down for five days |
| Risk owner | head of purchasing |
The example is invented for illustration. Without a time reference, likelihood cannot be interpreted: "rare" is not a statement, "once in ten years" is. Which level follows from likelihood and impact is set by the risk matrix.
Record the risk without controls and with the controls in effect today separately. Only the gap shows which control carries the result; the terms are explained in the entry on inherent risk.
Qualitative or quantitative: what BSI Standard 200-3 says
BSI Standard 200-3 regards quantitative risk analysis as highly demanding, because it requires extensive statistical data. It therefore works with qualitative categories and recommends no more than five per dimension. Where loss amounts and event frequencies are available for a risk, the quantitative route is still possible. Amounts and likelihoods per year can be added up and compared with the cost of controls; levels cannot.
ISO/IEC 27001 and the law make risk analysis binding
The guidance documents on risk analysis cannot be certified; risk analysis becomes binding only through a requirements standard or a law.
| Basis | Type | Role for risk analysis |
|---|---|---|
| ISO 31000 | guidance, not certifiable | general framework and vocabulary of the risk process |
| ISO/IEC 27005:2022 | guidance, not certifiable | application to information security risks |
| BSI Standard 200-3 | BSI standard under IT-Grundschutz | procedure for the supplementary risk analysis |
| ISO/IEC 27001, clauses 6.1.2 and 6.1.3 | certifiable requirements standard | defined, repeatable process for assessing and treating risks |
| Regulation (EU) 2022/2554 (DORA), Chapter II | regulation, for financial entities | ICT risk management, Articles 5 to 16 |
How Rizzqo keeps a risk assessment traceable
Rizzqo keeps a risk assessment traceable by holding its factors separately instead of condensing them into a score. Likelihood is held in percent, impact as an amount in euros. Configurable scale bands translate both values into your levels, and the risk level comes from a configurable matrix.
Each assessment keeps inherent, current and residual risk separate, similar to the before-and-after comparison in BSI Standard 200-3. This shows which part of the reduction comes from controls already in effect and which from controls still planned.