This chapter discusses concepts related to quantitative risk assessment and risk management. Management of risk is important to the design, implementation, and operation of information technology (IT) systems because IT systems are increasingly an essential part of the operation of most organizations. As a result, both the size of the potential harm or loss and the possibility of a risk event occurring are increasing. In extreme cases, a risk loss may be large enough to destroy an organization. If an organization's risk-management program is deficient in some area, the organization may suffer excessive harm or loss, but at the same time the organization may be wasting resources on ineffective, excessive, or misdirected mitigation measures in other areas. This chapter discusses risk management with special emphasis on two aspects of risk management: risk assessment and risk mitigation. Objectives of a risk assessment are explained and different risk-assessment techniques are also discussed.