Review dependencies before combining risk results. A shared supplier or control failure can affect several scenarios together, while simple addition can count the same consequence more than once.

Organizations may use risk aggregation to combine several discrete or lower-level risks into a more general or higher-level risk. This approach can help manage the scope and scale of risk assessments across multiple information systems and mission/business processes that have defined relationships and dependencies.

Risk aggregation, typically conducted at Tiers 1 and 2 and occasionally at Tier 3, evaluates the overall risk to organizational operations, assets, and individuals, considering the set of discrete risks. The worst-case impact estimated for an isolated scenario describes that scenario within its assumptions. It should not be treated as a general upper bound for the organisation when several events or dependencies interact.

Concurrent or recurring events can produce losses beyond the organisation's risk capacity, even when each scenario appears manageable in isolation. Consider common causes, dependencies and repeated exposure when reviewing the combined effect.

When aggregating risk, organizations consider the relationships among various risks. For example, if one risk occurs, it may increase or decrease the likelihood of another risk. Such relationships can be described as coupled or correlated, either positively or negatively, which can affect the overall risk level.

CSFaaS lets reviewers associate related risks with a demand and examine them together. These links support contextual analysis; they do not, by themselves, calculate a correlation-aware quantitative aggregate or a probability distribution of total loss.

(Source: NIST SP 800-30 Rev. 1)