Qualitative Risk Assessment
Focused on identifying significant risk factors. Based off of opinions of which risk factors are significant rather than calculations, like in Quantitative Risk Assessment. A simple method of qualitative risk assessment is the traffic light impact matrix. For each risk, a red, yellow, or green indicator can be put into each column to represent the severity of the risk, its Likelihood, cost of controls, and so on.
- Low risk represents minor damage or loss to an asset or loss of performance (though essential functions remain operational)
- Moderate risk represents significant damage or loss to assets or performance
- High risk represents major damage or loss or the inability to perform one of more essential functions