Extent to which an organization and/or stakeholder is subject to a risk.
Sources:
NIST SP 800-161r1-upd1
[11/1/2024 errata update]
from
ISO Guide 73 - adapted
The combination of likelihood and impact levels for a risk.
Sources:
NISTIR 8286