How it works
*Identify subject areas
*Experts’ judgment
*Probability of risk
*Impact of risk
*Reviewers’ expertise and justification
- apply measurement units to a measurement path

Specific Specs, dependencies, software & hardware requirements, orgs, etc.

Ask experts to estimate the risk exposure. For example:
Specification or source code can be independently inspected (open source & shared source models)
Complex, or poorly documented
Widely accepted and used
Unique in its class (competing or similar formats exist)
DRM, encryption, signatures, watermarks allowed, mandated, used
Supported by a very small organization or community, or by irreplaceable expertise

What experts can be included

Attempting to create objective group assessment from subjective individual opinions

Transition - results