This lesson covers IT Risk Assessment which is the process used to identify and evaluate a risk event. Risk assessment is different from identification in that assessment focuses on determining and documenting the types of risks that can affect an organization, whereas assessment is a means of evaluating the risk and its potential affect. This lesson also discusses NIST 800-100 which is a standard for risk assessment. Finally, the lesson also discusses quantitative and qualitative analysis formulas and definitions.

