0% found this document useful (0 votes)
2 views8 pages

Topic5 LearnerGuide

Uploaded by

Naveen Ad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views8 pages

Topic5 LearnerGuide

Uploaded by

Naveen Ad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

LEARNER GUIDE

Topic 5: Risk Analysis & Evaluation


What will you be able to do after this session:
Explain what likelihood and impact are. Use qualitative analysis to rate risks. Calculate a risk
score and rank risks by priority. Use a risk matrix to visualize risk levels.

Introduction
In the last session, you learned how to identify risks in an organization. In this session, you will
learn how to evaluate those risks. Evaluating risks means deciding how serious each risk is.

To do this, we use two key ideas: likelihood (how probable is it?) and impact (how bad would it
be?). Together, these give us a risk score that helps us prioritize what to fix first.

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 1


Part 1: Likelihood and Impact

What is Likelihood?
Likelihood means: How probable is it that this risk will happen?

Likelihood Level What it Means Example

Low (1) It could happen, but it is not A physical break-in at a guarded


common data centre
Medium (2) It happens sometimes An employee accidentally clicks
a phishing link
High (3) It happens often or is very easy Staff using weak passwords
to cause with no training

What is Impact?
Impact means: How serious are the consequences if this risk happens?

Impact Level What it Means Example

Low (1) Minor disruption; easily One employee cannot access


recovered their email for one hour
Medium (2) Moderate harm; requires Company system down for one
significant effort to recover day; some data lost
High (3) Serious harm; major financial, Customer data leaked; GDPR
legal, or reputational damage fine issued by German authority

💡 Key Idea
Likelihood and impact are two separate questions. Always ask them one at a time. A risk
can be VERY likely but have LOW impact, or VERY unlikely but have HIGH impact.

Real Example: Unencrypted Laptop


Question Answer Rating

How likely is theft of an office Thefts happen in shared Medium (2)


laptop? workspaces and while travelling
What is the impact if it contains GDPR breach, potential fine, High (3)
customer data? damaged reputation

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 2


Part 2: Qualitative Risk Analysis

Qualitative risk analysis means we use words (Low, Medium, High) to describe and compare
risks. This is the most common method at entry-level GRC.

Method Uses Example

Qualitative Words: Low / Medium / High Used in most GRC and ISO
27001 work
Quantitative Numbers: exact money values, Used in advanced financial risk
statistics models (not covered here)

The 5 Steps of Qualitative Risk Analysis

Step What to Do Example

1 Name the risk "No antivirus installed on


company laptops"
2 Rate the likelihood High – malware infection is very
common without antivirus
3 Rate the impact High – malware can destroy
data and disrupt all operations
4 Combine into a risk score High × High = Score 9 (Critical)
5 Record in the risk register Add to register with rating and
date

Exercise 1: Rate the Risk


For each scenario below, assign a Likelihood rating (Low, Medium, or High) and an Impact
rating. Then write one sentence explaining your choice. Scenario A: A company with 500
staff has a policy that allows any password, including simple ones like "1234". No training
has been given. Scenario B: A software system used daily has not been updated in 6
months and has a known security weakness. Scenario C: The office has no sign-in book for
visitors. Anyone can enter.

Reflection Question
Why do we use qualitative analysis (words) instead of exact numbers? What are the
advantages for entry-level GRC work?

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 3


Part 3: Risk Rating and Prioritization

Once you have rated likelihood and impact, you can calculate a risk score. This score tells you
how urgent a risk is.

Risk Score = Likelihood × Impact

Likelihood Impact Score Priority Level

1 (Low) 1 (Low) 1 Low


1 (Low) 2 (Medium) 2 Low
2 (Medium) 2 (Medium) 4 Medium
2 (Medium) 3 (High) 6 High
3 (High) 3 (High) 9 Critical

Why Do We Prioritize?
No organization has enough time or money to fix all risks immediately. Prioritization helps you
focus on the most dangerous risks first.

💡 Important Note
A high score means "address this first" in most cases. But sometimes a medium-score risk
is fixed first because it is quick and cheap to fix. Always combine the score with business
judgment.

Exercise 2: Which Risk First?


Below are three risks with their scores. Put them in order from most urgent (1) to least
urgent (3). Risk A: No antivirus on employee laptops (Likelihood: High, Impact: High,
Score: 9) Risk B: Admin accounts use only one password (no second factor) (Likelihood:
Medium, Impact: High, Score: 6) Risk C: No clear desk policy for printed documents
(Likelihood: Low, Impact: Medium, Score: 2) Your order: 1st = ___ | 2nd = ___ | 3rd = ___
Reason for your choice:

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 4


Part 4: The Risk Matrix

A risk matrix (also called a heat map) is a grid that shows all your risks visually. It plots
Likelihood on one axis and Impact on the other. The colour of each cell shows how urgent the
risk is.

Risk Matrix – 3×3 Grid


[DIAGRAM: The grid below shows a 3×3 risk matrix. Rows = Likelihood. Columns = Impact.]

Likelihood →↓ / Low Impact (1) Medium Impact (2) High Impact (3)
Impact →

High Likelihood (3) Medium (3) High (6) ⚠️ Critical (9)

Medium Likelihood (2) Low (2) Medium (4) High (6)


Low Likelihood (1) Low (1) Low (2) Medium (3)

Colour Guide for the Risk Matrix


Zone Colour Score Range What to Do

Critical Red 9 Immediate action


required
High Orange 6 Address as a priority
Medium Yellow 3–4 Plan treatment within
reasonable timeframe
Low Green 1–2 Monitor and review
periodically

How to Use the Risk Matrix


1. Find your risk in the risk register
2. Look at its Likelihood rating (Low, Medium, High)
3. Look at its Impact rating (Low, Medium, High)
4. Find where those two ratings meet on the grid
5. Note the colour zone. This is your risk level.
6. Record the risk level in your risk register

Exercise 3: Plot on the Matrix

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 5


Use the risk matrix above to find the correct zone for each risk: Risk A: Likelihood = High
(3), Impact = High (3) Zone: ________________ Risk B: Likelihood = Low (1), Impact =
High (3) Zone: ________________ Risk C: Likelihood = Medium (2), Impact = Low (1)
Zone: ________________

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 6


Session Summary: Key Points

Topic Key Point to Remember

Likelihood How probable is the risk? Use Low / Medium /


High (1-2-3)
Impact How serious are the consequences? Use Low /
Medium / High (1-2-3)
Qualitative Analysis Use words (Low/Medium/High) to describe and
compare risks – common in GRC and ISO 27001
Risk Score Likelihood × Impact = Risk Score (higher = more
urgent)
Risk Matrix A visual grid to compare and prioritize all risks at
a glance

Reflection Questions
• In your own words: what is the difference between likelihood and impact?
• Why is it important to rate risks before deciding what to do about them?
• If you had to explain the risk matrix to a colleague who has never seen one before, what
would you say?

Real-World Application: What GRC Analysts Actually Do


In a real GRC role in Germany, you might:
• Receive a list of risks identified during an information security audit
• Rate each risk for likelihood and impact based on your knowledge of the organization
• Create a risk matrix slide for a management presentation
• Use the risk scores to recommend which risks to treat first in the quarterly risk review

Action Plan
Action How I Will Do It Target Date

I can explain likelihood and


impact
I can assign qualitative ratings
to a risk
I can calculate a risk score

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 7


I can find a risk on a 3x3 risk
matrix

Next Session
In Topic 6: Risk Treatment & Acceptance, you will learn what to do AFTER you have rated
risks. You will explore options like mitigation, transfer, avoidance, and acceptance.

Learner Guide | Topic 5: Risk Analysis & Evaluation Page 8

You might also like