Glossary · Information security
Impact
The magnitude of harm if a risk scenario occurs, assessed against defined operational, financial, legal, safety, and reputational criteria.
What impact measures
Impact is the magnitude of the consequences if a risk scenario occurs. It answers how serious would the outcome be?, not how likely is it? A useful impact statement names the event, the business objective or asset affected, the resulting harm, and the period over which that harm is considered.
Criteria for a consistent rating
Define the scale before rating risks. Criteria can include service downtime, direct and secondary financial loss, effects on people or personal data, legal and contractual consequences, safety or environmental harm, and damage to reputation. Each level should use thresholds appropriate to the organization. Record the evidence and assumptions used and document how several dimensions are combined, so that two assessors can reach a comparable result.
A practical example
A one-hour outage may have little impact on a development environment but serious impact if it stops a production line, a public service, or a safety-critical process. The duration is identical; the affected objective, dependencies, and consequences are not. Assess the complete scenario rather than the technical fault in isolation.
Impact, likelihood, and the BIA
Likelihood measures the chance of the scenario; impact measures its consequences. A risk method uses both to support prioritization. A Business Impact Analysis has a different focus: it examines how the effects of disruption change over time and uses that information to set recovery priorities and objectives. High impact does not automatically mean high likelihood, and a modest event that happens often can still create material cumulative loss.