High School AdvancedA15.2Risk Management and Compliance
Lesson A15.2
Assets, Threats, Impact, and Likelihood
Good risk analysis starts before the score. You need to understand what matters, what could happen, what the business consequence would be, how plausible the scenario is, and how strong the evidence behind that judgment really is.
This lesson uses fictional scenarios and safe business-risk evidence only. It does not teach or require scanning, exploitation, credential attacks, or testing of real systems or suppliers.
High School Advanced • A15: Risk Management and Compliance • Lesson 2 of 10
20% complete
Readiness Check
A15.2 Entry Readiness
0/4 ready
Professional Hook
Before You Rate Risk, Understand What the Organization Depends On
A highly protected database can still be critical. A trusted vendor can still create concentration risk. A severe scenario can still be unlikely. Risk analysis becomes useful when it separates these ideas instead of collapsing them into one number.
Identify business services, assets, data, people, suppliers, identities, and operational dependencies that shape cybersecurity risk.
2
Write clear threat-event scenarios that describe what could happen without turning risk analysis into offensive testing.
3
Evaluate business impact across confidentiality, integrity, availability, financial, legal, operational, safety, and reputational dimensions.
4
Estimate likelihood using current evidence, exposure conditions, control strength, history, dependency, and uncertainty rather than treating a score as a prediction.
5
Build a Risk Analysis Worksheet that becomes the second artifact in the A15 Risk Register and Leadership Recommendation.
ANL-02 combines high business consequence with several current exposure conditions: broad legacy trust, incomplete ownership, aging platform dependencies, and incomplete modernization.
Defensive recommendation: Keep the scenario in Treat, preserve uncertainty where evidence is incomplete, and use current control and remediation evidence to refresh likelihood over time.
Impact vs. Likelihood
A Severe Scenario Can Still Be Unlikely
One of the most important risk-analysis habits is resisting the urge to make impact and likelihood move together. A critical service outage can have High impact and Low likelihood. A small recurring control failure can have Low impact and High likelihood. Both dimensions matter for different reasons.
Impact asks
“If this happens, what is the business consequence?”
Likelihood asks
“How plausible is this under current exposure, controls, dependencies, history, and evidence?”
A stable SaaS provider has strong evidence and contracts, but one critical business workflow has no practical alternative provider.
Safe Fictional Lab
Build a Risk Analysis Worksheet
Use fictional business services, assets, suppliers, threat events, impact reasoning, likelihood reasoning, controls, and evidence only. No real system testing is needed.
1
Create at least twenty fictional risk-analysis records.
2
Give every record a stable ANL ID.
3
Record the business service.
4
Record the asset or dependency.
5
Write a high-level threat event.
6
Record the exposure condition.
7
Analyze confidentiality impact where relevant.
8
Analyze integrity impact where relevant.
9
Analyze availability impact where relevant.
10
Analyze financial/operational impact where relevant.
11
Analyze legal/compliance impact where relevant.
12
Analyze reputational impact where relevant.
13
Assign an overall impact label with reasoning.
14
Record current controls.
15
Record control evidence.
16
Record evidence freshness.
17
Analyze exposure frequency.
18
Analyze dependency or concentration.
19
Analyze recent change.
20
Analyze relevant history if available.
21
Assign a likelihood label with reasoning.
22
Record assumptions.
23
Record uncertainty.
24
Choose a decision state.
25
Record what evidence would move likelihood higher.
26
Record what evidence would move likelihood lower.
27
Include at least four High-impact / Low-or-Medium-likelihood scenarios.
28
Include at least three Medium-impact / High-likelihood scenarios.
29
Include at least three third-party dependency scenarios.
30
Include at least two scenarios with stale evidence.
31
Include at least two scenarios with contradictory evidence.
Lab boundary
Do not scan, probe, exploit, test, or investigate real systems, vendors, or people. Do not attempt to prove likelihood through unsafe testing. Use fictional and authorized evidence only.
Analyze the Evidence
Evidence Analysis: Supplier Concentration
The supplier supports a critical business workflow.
The supplier has current security evidence and contract commitments.
A continuity plan exists.
No practical alternate provider is available today.
A major provider outage would still have high business impact.
What is the strongest interpretation of ANL-05?
Advanced Challenge
Design a Risk Rating Method That Does Not Hide Uncertainty
Create a fictional organization-wide method for describing impact and likelihood without turning the result into fake precision.
1
Impact dimensions
2
Likelihood factors
3
Evidence freshness
4
Assumption field
5
Uncertainty field
6
Dependency field
7
Control-strength field
8
Change trigger
9
Third-party concentration
10
Recovery dependency
11
Business criticality
12
Decision state
13
Narrative rationale
14
Score or matrix as optional summary
15
Review cadence
16
Leadership explanation
The strongest method should help reviewers compare risks without pretending that a label or score can perfectly predict the future.
Defender Habits
A15.2 Defender Checklist
Skill Check
Seven Questions
Check Your Understanding
A15.2 Mini Quiz: Assets, Threats, Impact, and Likelihood
Choose your answers first. Explanations appear only after submission.
1. What makes an asset important in risk analysis?
2. What should a strong threat-event scenario include?
3. What does impact measure?
4. What does likelihood measure?
5. Why should evidence freshness matter to likelihood reasoning?
6. What is concentration risk?
7. Which statement about risk matrices is strongest?
Portfolio Prompt
Portfolio Build — Risk Analysis Worksheet
Create the second artifact for your A15 Risk Register and Leadership Recommendation: a fictional Risk Analysis Worksheet with at least twenty records. Include ANL ID, business service, asset/dependency, threat event, exposure condition, impact dimensions, overall impact, controls, evidence, freshness, likelihood factors, overall likelihood, assumptions, uncertainty, decision state, evidence that would raise likelihood, evidence that would lower likelihood, and review trigger.
Keep impact and likelihood separate.
Use business consequences, not technical drama.
Record evidence freshness.
Preserve uncertainty.
Include supplier and concentration risk.
Use fictional provider-neutral records only.
Confidence / Readiness Reflection
Are You Ready for A15.3?
A15.3 focuses on Risk Registers and Ownership. Before continuing, make sure you can explain a risk clearly enough that it can be entered into a professional register.
1
I can identify business assets and dependencies.
2
I can write a safe, high-level threat scenario.
3
I can separate impact and likelihood.
4
I can explain how evidence freshness changes confidence.
5
I can document uncertainty instead of hiding it in a score.
Portfolio Build Guide
How to Make the Risk Analysis Worksheet Look Professional
Start with business context
Show what service, asset, data, user group, or supplier matters before describing the threat event.
Make impact multidimensional
Consider confidentiality, integrity, availability, financial, legal, operational, and reputational consequences where relevant.
Explain likelihood
Show exposure, controls, history, change, dependency, and evidence quality behind the label.
Show uncertainty
Record missing, partial, stale, or contradictory evidence explicitly.
Show dependencies
Include suppliers, identities, recovery, single points of failure, and concentration where relevant.
Use scores carefully
A score or matrix can summarize the result, but the narrative should remain the real analysis.
Show change triggers
New data, owner, supplier, architecture, control, incident, or evidence changes should reopen the estimate.
Connect forward
A15.3 will turn these worksheets into a structured Cybersecurity Risk Register with accountable ownership.
Key Takeaways
What You Should Remember
1.Risk starts with business services, assets, data, identities, people, and dependencies.
2.Threat scenarios should describe what could happen and why it matters without teaching offensive procedures.
4.Strong controls can reduce likelihood without changing how critical the underlying service is.
5.Evidence quality and freshness should directly affect confidence.
6.Dependency and concentration risk matter even when suppliers have strong controls.
7.Uncertainty should remain visible instead of being hidden inside a score.
8.Risk matrices are prioritization aids, not predictions.
9.Change in data, ownership, architecture, supplier, or control state should reopen the analysis.
10.The Risk Analysis Worksheet prepares you for A15.3 Risk Registers and Ownership.
Lesson Safety Boundary
Likelihood reasoning does not require attacking real systems
Do not scan, probe, exploit, test, or investigate real systems, vendors, accounts, or people. Do not collect credentials or private organizational evidence. All scenarios, suppliers, assets, controls, logs, and evidence in this lesson are fictional.
Lesson Complete
A15.2 Assets, Threats, Impact, and Likelihood Complete
You now have a structured way to analyze assets, threat events, business impact, likelihood, dependencies, evidence quality, and uncertainty. Next, A15.3 focuses on Risk Registers and Ownership.