Does your organization have a documented process for prioritizing cybersecurity investments based on risk assessment (likelihood and impact)?
Explanation
Risk-based investment prioritization is the focus: whether your cybersecurity spending decisions follow documented assessments of likelihood and impact rather than guesswork. Effective resource allocation requires understanding which threats are most likely to occur and would cause the greatest damage, allowing limited security budgets to address the most critical vulnerabilities first.
Evidence could include a risk assessment framework document, meeting minutes from security investment planning sessions, or a prioritized security roadmap with justifications based on risk calculations. An ideal deliverable would be a risk register or matrix that shows how different security initiatives were ranked based on threat likelihood and potential business impact scores.
Implementation Example
Prioritize cybersecurity resource allocations and investments based on estimated likelihoods and impacts
ID: ID.RA-05.163
Context
- Function
- ID: IDENTIFY
- Category
- ID.RA: Risk Assessment
- Sub-Category
- Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Related questions
- Does your organization implement vulnerability management tools to detect unpatched software and misconfigurations?
- Does your organization regularly conduct security architecture reviews to identify and remediate design and implementation weaknesses?
- Does your organization conduct security reviews, analysis, or testing of internally developed software to identify vulnerabilities in design, code, and default configurations?
- Has your organization conducted a comprehensive physical security assessment of all facilities housing critical computing assets within the past 12 months?
- Does your organization actively monitor cyber threat intelligence sources for information about new vulnerabilities in your products and services?
- Does your organization regularly conduct vulnerability assessments of business processes and procedures to identify potential cybersecurity weaknesses?

