Input: the scenarios with risk sources, business processes and objectives, likelihood criteria and the existing controls' effectiveness and status. Action: assess the likelihood of possible or actual scenarios on the established criteria. Trigger: not done before; scope or context changes; vulnerabilities found in implemented controls; unexpected control test or audit results; or changes in the threat environment such as new actors. Output: scenarios with their likelihoods. Likelihood reflects how often risk sources arise or how easily weaknesses can be exploited, considering experience and statistics; for deliberate sources, attackers' motivation (such as cost-benefit), changing capability and resources, influences such as organised crime, terrorism or foreign intelligence, and how attractive and vulnerable the information looks; for accidental sources, geography (nearby hazardous sites), natural disasters (earthquakes, flooding, tsunami, volcanic activity, extreme weather) and factors affecting human error and equipment malfunction; known weaknesses and compensating controls singly and together; and how well existing controls reduce known weaknesses. Estimates are inherently uncertain, from personal (the assessor's heuristics), methodological (simplified tools) and systemic (limited knowledge of the event) sources; reliability improves with team rather than individual assessment, external sources such as breach reports, scales with fitting range and resolution, and concrete categories (once a year rather than infrequent). Dependent events are conditioned on each other and need not be assessed separately, while independent events all contribute; dependencies within a scenario are identified first and independent events assessed first, and business-level likelihood is better built up from assessed lower-level contributory events than estimated in one step.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.