The article proposes a methodology for assessing the risk of information security of a computer network based on the results of the analysis of vulnerability attributes and protection attributes of information system elements, as well as security attributes of information system elements. According to the results of the research the space of information protection signs is formed. The results of the analysis of possible variants of threats of unauthorized access to electronic resources of the computer network, as well as solutions to reduce the risks of information security are given. Quantitative indicators of the results of the application of the proposed methodology to assess the risk of threats of unauthorized access to electronic resources of the computer network confirm the effectiveness of the proposed methodology, which can be used to improve the level of protection of electronic resources in organizations.