This chapter explains the concepts used to reason about cybersecurity risk: threats, vulnerabilities, consequences, likelihood, risk appetite, assessment approaches and response. It also introduces governance, controls, trust and supply-chain considerations.
Use these explanations alongside the cited primary publications and your organisation's agreed methodology. Examples illustrate a concept; they are not universal assessment scales or a guarantee that a particular standard applies to your organisation.
For the steps performed in the app, continue to the product and operational guides. Keep the conceptual basis of an assessment connected to its actual scope, assumptions and supporting evidence.