Students evaluate various risk management frameworks (NIST RMF, ISO 27005) to understand how to quantify cyber risk. The lesson involves conducting a mock risk assessment for a fictional organization, identifying assets, threats, and vulnerabilities.