You are identifying, analyzing, and evaluating information risk focusing on the likelihood and impact of threats. Which of the following is the last tool or technique you may use in the process? (Wentz QOTD)
A. Risk heat map
B. Asset valuation
C. Benefits analysis
D. Risk exposure determination

My suggested answer is A. Risk heat map.

ISO 31000
What does “risk assessment/analysis” mean?

Please be noted that in the CISSP exam outline, OSG, and NIST, risk assessment and risk analysis are treated as synonyms and often expressed as “risk assessment/analysis.”

Identifying, analyzing, and evaluating information risk implies the use of ISO standards for risk management, such as ISO 31000 or ISO 27005, and you are in the process of risk assessment. A risk heat map is a common tool to express the results of risk assessment.

  • Assets valuation may be used in the process of risk analysis when estimating the impact, e.g., the single loss expectancy (SLE) = asset value (AV) x exposure factor (EF).
  • Costs and benefits analysis is more often conducted in the risk treatment (instead of risk assessment) process to justify the risk treatment options (ISO term) or risk response strategies (PMI term).
  • Risk exposure determination is the conclusion of risk analysis. Risk exposure is a function of likelihodd, impact, and other factors.

Risk Heat Map

Source: Babix

A risk heat map (or risk heatmap) is a graphical representation of cyber risk data where the individual values contained in a matrix are represented as colors that connote meaning. Risk heat maps are used to present cyber risk assessment results in an easy to understand, visually attractive and concise format.

Source: Babix


