Skip to main content
Category: Risk Assessment & Analysis

Likelihood Determination

Also known as: Risk Likelihood, Likelihood Assessment
Simply put

Likelihood determination is the step in a risk assessment where an organization estimates how probable it is that a threat could take advantage of a weakness and cause harm to a system or asset. It reflects a judgment about the chance of something going wrong, rather than a precise measurement of certainty. This estimate is typically combined with an evaluation of potential impact to gauge overall risk.

Formal definition

Likelihood determination is the analytic process, within a risk assessment, of assessing the probability that a given threat source is capable of exploiting a given vulnerability (or set of vulnerabilities) to adversely affect an asset or system. It generally produces a weighted factor derived from subjective analysis of threat capability and vulnerability exposure, and is one of the two principal inputs, alongside impact determination, used to characterize risk in most risk-assessment methodologies. Because the resulting value rests on subjective judgment and available threat/vulnerability information, practitioners should treat it as an estimate subject to the assumptions, scope, and scoring approach of the specific methodology in use; this entry does not prescribe a particular scoring scale or agency-tailored implementation, which readers should confirm against current authoritative guidance.

Why it matters

Likelihood determination is one of the two analytic pillars, alongside impact determination, that shape how an organization characterizes and prioritizes risk. Without a defensible estimate of how probable it is that a threat could exploit a given vulnerability, decision-makers lack a rational basis for allocating limited resources, selecting or tailoring controls, and accepting or mitigating risk. In defense and public sector environments where risk-based decisions feed authorization activities, a weak or inconsistent likelihood judgment can distort the entire risk picture and lead to over- or under-investment in safeguards.

Because likelihood determination generally rests on subjective analysis of threat capability and vulnerability exposure, it is inherently an estimate rather than a precise measurement. This is a point experts insist on: a likelihood value reflects a judgment about the chance of something going wrong given available threat and vulnerability information, not a guarantee of what will or will not occur. Practitioners should be cautious about treating the resulting number as objective certainty, and should document the assumptions, scope, and scoring approach that produced it so that reviewers and authorizing officials can understand its basis.

The practical stakes are heightened by the fact that likelihood estimates change as threat information and vulnerability exposure change. A determination made at one point in time can become stale, which is why likelihood is best understood as a component of ongoing risk management rather than a one-time calculation. Readers should confirm the specific scoring scale and any agency-tailored implementation against current authoritative guidance rather than assuming a single universal method applies.

Who it's relevant to

Information System Security Managers and Security Officers
These practitioners perform or oversee the risk assessments in which likelihood is estimated. They need to understand that likelihood is a subjective, weighted judgment about the probability of a threat exploiting a vulnerability, and to document the assumptions and scoring approach so the estimate can be defended and revisited as conditions change.
Authorizing Officials and Risk Decision-Makers
Officials who accept, mitigate, or transfer risk rely on likelihood estimates, combined with impact, to prioritize action. They should treat these values as estimates rather than precise measurements, and recognize that a likelihood determination reflects a point-in-time judgment subject to changing threat and vulnerability information.
Risk Managers and Assessors
Those who build and apply likelihood-and-impact matrices use likelihood determination as a core input to characterizing risk. They must be clear about which methodology and scoring scale they are applying, since the resulting factor depends on the scope and approach chosen rather than a single universal standard.
Auditors and Reviewers
Reviewers evaluating a risk assessment should scrutinize how likelihood was derived, including the threat and vulnerability information considered and the subjective analysis behind any weighted factor. They should confirm that the specific scale and agency-tailored implementation align with current authoritative guidance rather than assuming a default method.

Inside Likelihood Determination

Threat Event Likelihood
An assessment of the probability that a given threat source will initiate a threat event, typically considering the threat source's capability, intent, and targeting where the source is adversarial, or the frequency of occurrence where the source is non-adversarial (such as environmental or accidental events).
Likelihood of Impact
An assessment of the probability that a threat event, once initiated or occurring, will result in an adverse impact given the susceptibility of the system and the presence or absence of controls. In many risk assessment methodologies this is combined with threat event likelihood to derive an overall likelihood.
Vulnerability and Predisposing Conditions
Factors such as exploitable weaknesses and pre-existing conditions that affect whether a threat event can successfully occur, which generally inform the likelihood determination as part of a broader risk analysis.
Assessment Scale
A qualitative, semi-quantitative, or quantitative scale (for example, values ranging from very low to very high) used to express the determined likelihood in a consistent and communicable manner across the assessment.
Relationship to Overall Risk
Likelihood is one of the two principal inputs to a risk determination, the other generally being the magnitude of impact; the combination informs the resulting risk level used in decision-making.

Common questions

Answers to the questions practitioners most commonly ask about Likelihood Determination.

Is likelihood determination a precise, quantitative probability that a threat event will occur?
Generally, no. In most risk assessment methodologies, such as those described in NIST SP 800-30, likelihood determination is typically expressed on a qualitative or semi-quantitative scale (for example, low, moderate, high) rather than as a precise statistical probability. It reflects an informed judgment about the chance that a threat event could occur and result in an adverse impact, given threat characteristics and vulnerability conditions. Assessors should avoid presenting these values as exact probabilities unless the methodology and available data genuinely support quantitative analysis, and should verify the scale and definitions used against the applicable methodology and any agency tailoring.
Is likelihood determination the same thing as the overall risk rating?
No. Likelihood is one input to risk, not risk itself. In most implementations, risk is a function of both the likelihood that a threat event occurs (or is initiated and succeeds) and the resulting impact. Determining likelihood alone does not establish risk; it must be combined with an impact determination to produce a risk assessment result. Conflating the two can distort prioritization, so assessors should keep likelihood and impact as distinct factors and confirm how their chosen methodology combines them.
What factors are typically considered when determining likelihood?
In most methodologies, likelihood determination generally considers the characteristics of the threat source (such as capability, intent, and targeting for adversarial threats, or frequency and conditions for non-adversarial ones), the presence and severity of vulnerabilities or predisposing conditions, and the effectiveness of existing security controls. Some approaches, including NIST SP 800-30, distinguish the likelihood of a threat event being initiated from the likelihood that it results in adverse impact. Assessors should confirm which factors and definitions their specific methodology or agency guidance requires.
How does likelihood determination fit into the broader risk assessment process?
Likelihood determination is typically one step within a structured risk assessment. It generally follows identification of threat sources, threat events, vulnerabilities, and predisposing conditions, and it precedes or accompanies impact determination so the two can be combined into a risk determination. Within a framework such as the RMF, risk assessment outputs, including likelihood judgments, inform control selection, authorization decisions, and continuous monitoring. Readers should confirm the exact sequencing against the methodology and any organization-specific procedures in use.
How should assessors document the basis for a likelihood determination?
As a general practice, assessors should document the rationale supporting each likelihood value, including the threat and vulnerability information considered, assumptions made, sources of uncertainty, and the scale definitions applied. Transparent documentation supports repeatability, review by authorizing officials, and reassessment during continuous monitoring. The specific documentation format and level of detail may be driven by organizational policy or agency-specific guidance, which readers should verify against current authoritative sources.
Does a likelihood determination remain valid over time?
Not necessarily. Likelihood values reflect conditions at the time of assessment, and threat environments, vulnerabilities, and control effectiveness can change. Because of this, likelihood determinations generally should be revisited as part of ongoing risk management and continuous monitoring rather than treated as fixed. Organizations should confirm their required reassessment triggers and cadence against applicable policy and methodology.

Common misconceptions

Likelihood determination produces a precise, objective probability figure.
In most risk assessment methodologies applicable to federal and defense systems, likelihood is generally expressed using qualitative or semi-quantitative scales rather than exact probabilities, and the result reflects informed judgment about factors such as threat capability, intent, and vulnerability rather than a statistically derived value. Readers should confirm the specific approach and scale defined in the applicable methodology.
Likelihood alone determines the risk level.
Likelihood is only one input to a risk determination. Risk is generally derived by combining likelihood with the magnitude of potential impact, so a high likelihood with negligible impact and a low likelihood with severe impact can yield very different risk conclusions.
A single likelihood value covers both whether a threat event occurs and whether it causes harm.
Many methodologies distinguish the likelihood that a threat event is initiated or occurs from the likelihood that it results in an adverse impact. These are often assessed separately and then combined, and conflating them can distort the resulting risk analysis.

Best practices

Assess threat event likelihood and likelihood of resulting impact as distinct factors where the applicable methodology calls for it, then combine them consistently rather than collapsing them into a single undifferentiated estimate.
Use a defined and documented assessment scale so that likelihood values are applied consistently across systems and are understandable to authorizing officials and other stakeholders.
Differentiate adversarial from non-adversarial threat sources when determining likelihood, considering capability, intent, and targeting for adversarial sources and frequency or probability of occurrence for non-adversarial ones.
Incorporate vulnerabilities, predisposing conditions, and the effect of existing controls into the likelihood determination so the assessment reflects the system's actual susceptibility.
Document the rationale and supporting evidence behind each likelihood determination so the judgment can be reviewed, challenged, and updated during continuous monitoring.
Treat likelihood determinations as time-bound and revisit them as threat information, system configurations, and controls change, and verify the specific scales and procedures against the current authoritative methodology in use.