Risk
A measure of the extent to which an entity is threatened by a potential circumstance or event
Impact
An adverse effect that results from an event occuring
Vulnerability
A weakness in an information system that can be exploited to compromise a pillar of cyber security
Threat
An actor or event with the potential to adversly impact an IS system
Capability
The knowledge and skill set required by a threat to carry out an event
Opportunity
The resources and positioning required by a threat to carry out an action
Intent
The motivation of a threat to carry out an action
Tenets of Risk Management Process
Strategies for addressing Risk