Security Risk
A security risk is the possibility that a threat will exploit a vulnerability and negatively affect the confidentiality, integrity, or availability of information or systems.
“A quality risk related to security.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Security Risk?
Security risks help organizations prioritize security controls and testing based on the likelihood and potential impact of attacks.
Threat driven: Risks arise from threats exploiting vulnerabilities.
Business impact: May affect operations, reputation, or compliance.
Risk management: Security risks require assessment and mitigation.
Real World Example
An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.
The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Security risk points testing toward that hostile or risky behavior.
The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.
The team strengthens the controls because Security risk helps them test the product from the perspective of misuse, not only normal customer journeys.
Practice Questions
Question 1
Which statement BEST describes Security risk in the context of ISTQB terminology?
Question 2
A tester needs to explain Security risk to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Security Risk. Test your understanding with topic-specific questions in our Mock Exams.