"Systematic application of procedures and practices to the tasks of identifying, analyzing, prioritizing, and controlling risk". (SEI, 1993)Moreover, according to SEI, each risk management paradigm activity [...]
"function of the probability of occurrence of a given threat and the potential adverse consequences of that threat's occurrence." (ISO/IEC 15926:2008) (ISO/IEC 25010:2011)
It refers to the distance observed between optimal requirements (e.g., that need to be implemented) and the current software product implementation (e.g., under domain assumptions and [...]