State the assessment period and the evidence supporting the estimate. A likelihood label is meaningful only in relation to the scenario, assumptions and scale used to assign it.
Likelihood of occurrence
Likelihood estimates how probable the scenario is over the assessment period. Consider both the initiation or occurrence of the threat event and the likelihood that it produces adverse effects, given the relevant vulnerabilities and conditions.
Adversarial threats
For adversarial threats, the assessment of likelihood is typically based on:
Adversary intent
Adversary intent refers to the adversary's motivation or desire to carry out an attack, whether for financial gain, data theft, disruption, or espionage. It indicates the willingness and determination of an adversary to initiate harmful actions against a target.
Adversary targeting
Adversary targeting involves the selection of specific targets, reflecting who or what the adversary aims to attack based on their goals, motivations, or perceived vulnerabilities.
Adversary capability
Adversary capability refers to the skills, resources, and tools available to an adversary that enable them to execute an attack effectively, including their technical skills, infrastructure, and support networks.
Non-adversarial threats
For non-adversarial threats, the likelihood of occurrence is estimated using historical evidence, empirical data, or other relevant factors. The likelihood of a threat event is assessed over a specific time frame (e.g., the next six months, the next year, or until a particular milestone). If an event is almost certain to occur within this period, the risk assessment may also consider its estimated frequency.
Likelihood of impact
The likelihood of impact addresses the probability that a threat event will cause adverse effects, regardless of the expected severity of harm.
(Source: NIST SP 800-30 Rev. 1)