Quantitatively or qualitatively assess (e.i., identify, analyze, and evaluate) relevant risks, taking into account the information assets, threats, existing controls, and vulnerabilities to determine the likelihood of incidents or incident scenarios, and the predicted business consequences if they were to occur to determine a level of risk.