Likelihood Determination
Likelihood determination is the step in a risk assessment where an organization estimates how probable it is that a threat could take advantage of a weakness and cause harm to a system or asset. It reflects a judgment about the chance of something going wrong, rather than a precise measurement of certainty. This estimate is typically combined with an evaluation of potential impact to gauge overall risk.
Likelihood determination is the analytic process, within a risk assessment, of assessing the probability that a given threat source is capable of exploiting a given vulnerability (or set of vulnerabilities) to adversely affect an asset or system. It generally produces a weighted factor derived from subjective analysis of threat capability and vulnerability exposure, and is one of the two principal inputs, alongside impact determination, used to characterize risk in most risk-assessment methodologies. Because the resulting value rests on subjective judgment and available threat/vulnerability information, practitioners should treat it as an estimate subject to the assumptions, scope, and scoring approach of the specific methodology in use; this entry does not prescribe a particular scoring scale or agency-tailored implementation, which readers should confirm against current authoritative guidance.
Why it matters
Likelihood determination is one of the two analytic pillars, alongside impact determination, that shape how an organization characterizes and prioritizes risk. Without a defensible estimate of how probable it is that a threat could exploit a given vulnerability, decision-makers lack a rational basis for allocating limited resources, selecting or tailoring controls, and accepting or mitigating risk. In defense and public sector environments where risk-based decisions feed authorization activities, a weak or inconsistent likelihood judgment can distort the entire risk picture and lead to over- or under-investment in safeguards.
Because likelihood determination generally rests on subjective analysis of threat capability and vulnerability exposure, it is inherently an estimate rather than a precise measurement. This is a point experts insist on: a likelihood value reflects a judgment about the chance of something going wrong given available threat and vulnerability information, not a guarantee of what will or will not occur. Practitioners should be cautious about treating the resulting number as objective certainty, and should document the assumptions, scope, and scoring approach that produced it so that reviewers and authorizing officials can understand its basis.
The practical stakes are heightened by the fact that likelihood estimates change as threat information and vulnerability exposure change. A determination made at one point in time can become stale, which is why likelihood is best understood as a component of ongoing risk management rather than a one-time calculation. Readers should confirm the specific scoring scale and any agency-tailored implementation against current authoritative guidance rather than assuming a single universal method applies.
Who it's relevant to
Inside Likelihood Determination
Common questions
Answers to the questions practitioners most commonly ask about Likelihood Determination.