ABSTRACT

The fourth phase of a security risk assessment is security risk analysis. The security risk analysis depends on all the previous stages to supply the information required to analyze the security risk to the organization. The risk assessment phase consists of techniques and approaches for determining individual and overall risk levels. This process can take many different forms depending upon the security risk assessment method performed. The security risk assessment process will be discussed here by describing the process in the following three steps:

1. Determine risk. 2. Create risk statements. 3. Team review of risk statements.