Likelihood
Likelihood is a measure of the chance that something will happen. In a security compliance context, it describes how probable it is that a particular threat or risk event will occur.
In risk assessment, likelihood expresses the estimated chance that a given threat event or scenario will occur, typically evaluated alongside impact to determine an overall risk rating. It is generally captured either qualitatively (for example, low, medium, or high) or quantitatively (for example, an assigned probability or frequency), with the specific scale and criteria depending on the organization's risk methodology and scope. In statistics more broadly, the term carries a distinct technical meaning as a function measuring how plausible a set of parameter values is given observed data; practitioners should note that risk-assessment usage refers to the everyday sense of chance or probability rather than the formal statistical likelihood function.
Why it matters
In a security compliance program, likelihood is one of the two dimensions, alongside impact, that drive nearly every risk-based decision. Whether an organization is prioritizing remediation work, allocating budget, or deciding which threats warrant a formal control, an estimate of how probable a threat event is provides the basis for that judgment. Without a defensible sense of likelihood, teams risk treating remote and imminent threats identically, which wastes resources on unlikely scenarios or leaves probable ones underprotected.
Both SOC 2 and ISO 27001 depend on likelihood as an input to their risk processes, though they approach it differently. Under ISO/IEC 27001, the ISMS requirements in clauses 4 through 10 call for a risk assessment that informs the selection of Annex A reference controls via the Statement of Applicability, and likelihood is typically a core factor in that assessment. In a SOC 2 examination, the service organization's risk assessment supporting the Common Criteria similarly considers the probability that identified risks will materialize. In both cases, the specific scales and criteria depend on the organization's chosen methodology rather than a single mandated formula.
A subtle but important pitfall involves terminology. In risk assessment, likelihood means the everyday sense of chance or probability that an event will occur. In statistics more broadly, the term carries a distinct technical meaning, a function measuring how plausible a set of parameter values is given observed data. Conflating the two can lead to misunderstandings when technical and risk teams collaborate, so practitioners should be explicit about which sense they intend.
Who it's relevant to
Inside Likelihood
Common questions
Answers to the questions practitioners most commonly ask about Likelihood.