NASA’s Defect Detection Prevention approach (DDP) is a notable effort to systematize the
Identify – Assess – Control cycle and integrate risk management in the RE process (Feather and Cornford, 2003, Feather et al., 2005). The approach is supported by a quantitative reasoning
risk consequences as loss of attainment of the corresponding objective.
In DDP , object, risk and countermeasures are called requirement, failure modes and
PACTs, respectively. There is a coarser counterpart of the notion of risk-reduction leverage,
Called effectiveness, defined as the proportion by which a countermeasure reduces a risk.
The likelihood of risk, the severity of consequences and the effectiveness of countermeasures must be estimated quantitatively by elicitation from expert or from accumulated measurements.