The document discusses risk analysis and assessment. It defines risk as the likelihood and impact of threats exploiting vulnerabilities. It describes qualitative and quantitative risk analysis approaches. Qualitative approaches use relative scales like high/medium/low likelihood and impact to assess risk, while quantitative assigns monetary values. Information gathering techniques for risk assessment include questionnaires, interviews, and document reviews.