> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/online-courses/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/online-courses/is-auditing-controls-and-assurance/introduction-to-information-systems-is-auditing/risk-in-information-systems-is.md).

# Risk in Information Systems (IS)

## What is risk?

The possibility of having **negative** impact.

## Why do we take risk?

Thinking of having **positive** impact.

## Elements of risk

### Threats

Types of threats are:

* Natural disaster
* Man-made threats
  * Internal
  * External

{% hint style="info" %}
Internal threats have the possibility of being of higher impact to the organization.
{% endhint %}

* Technical

### Impact

Measure of damage.

Quality measures can be:

1. Negligible
2. Minor
3. Moderate
4. Serious
5. Major

### Probabilities

Likelihood of having risk:

1. Very unlikely
2. Unlikely
3. Possible
4. Likely
5. Probable
