As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
Read more: TOGAF Standard
In the Ultra Transcenders books
Each book explains Risk in context, with comparison tables and the common traps.
Terms in this definition
- ISO
The International Organization for Standardization. SQL became an ISO standard in 1987, twelve months after ANSI adopted it.
Related terms
- Adaptive Protection
A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
- AI observability
A page in Data Security Posture Management listing the AI agents and apps used in the past 30 days. For each it shows whether it is high risk, any interactions involving sensitive data, and which policies apply to it.
- AI Red Teaming Agent
PyRIT-based tool in Microsoft Foundry that mounts simulated adversarial attacks on models and agents and reports how often attacks succeed. It identifies risk without blocking anything.
- Alert Triage Agent
A preview Security Copilot agent that sorts DLP alerts for you, weighing the risk each one carries and placing it in groups like Needs attention or Less urgent. Running it uses security compute units.
- Annotate and block
Guardrail action in Microsoft Foundry that marks detected risk and also stops it; at the tool-call intervention point, this means the tool call never runs.
- Benign true positive
Used to classify an alert caused by activity that really happened but was approved, a penetration test for example. Instead of remediating, close the alert or risk and narrow the policy's scope.
- BOM
Bytes placed first in a text file to signal its encoding. Fine-tuning data should be saved as UTF-8 with a BOM, keeping each file below 512 MB; ASCII, UTF-16 or ISO-8859-1 files risk failing validation.
- Business Impact Analysis
Looks at how much harm, or benefit, inadequate security could bring to the business. It ranks which impacts matter without estimating their likelihood, and its result is the set of key risk areas.