Level-of-risk scales help risk owners decide whether to retain or treat risks and in what order, and signal urgency. Depending on the case the inherent level (ignoring controls) or the current level (allowing for controls in place) is considered. A risk ranking is built from: the consequence and likelihood criteria; the effects security events can have at strategic, tactical and operational levels, on a consistent basis such as worst case; legal, regulatory and contractual obligations; and risks whose reach extends past the organisation's own scope, such as unexpected effects on third parties. The criteria can be qualitative (very high to low) or quantitative (expected monetary loss, loss of life or market share over time, such as annual loss expectancy). Either way, scales are anchored to a reference scale all interested parties understand, with analysis and evaluation periodically calibrated against it for validity, consistency and comparability; qualitative levels are unambiguous, clearly stepped, described objectively and non-overlapping, and different scales used in different domains have a stated equivalence.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.