Likelihood of Occurrence
According to the National Institute of Standards and Technology (NIST), the likelihood of occur-
rence is based on the probability that a particular threat is capable of exploiting a particular vul-
nerability, with possible ratings of Low, Medium, or High.
• High: the potential adversary is highly skilled and motivated and the measures that have
been put in place to protect against the vulnerability are insufficient.
• Medium: the potential adversary is motivated and skilled but the measures put in place to
protect against the vulnerability may impede their success.
• Low: the potential adversary is unskilled or lacks motivation and there are measures in
place to protect against the vulnerability that are partially or completely effective.
Impact
The level of impact is determined by evaluating the amount of harm that could occur if the vul-
nerability in question were exploited or otherwise taken advantage of.
• High: taking advantage of the vulnerability could result in very significant financial losses,
serious harm to the mission or reputation of the organization, or even serious injury, in-
cluding loss of life.
• Medium: taking advantage of the vulnerability could lead to financial losses, harm to the
mission or reputation of the organization, or human injury.
• Low: taking advantage of the vulnerability could result in some degree of financial loss or
impact to the mission and reputation of the organization.