Tool Mentor: Maintaining the Risk Management Plan in DOORS
This tool mentor describes how to manage the Risk Management Plan in IBM® Rational® DOORS®.
Tool: IBM Rational DOORS
Main Description

Introduction

The risk management plan allows the project team to track risks identified.  The associated DOORS® module will compute the Magnitude of the risk by multiplying the Probability and Severity attribute values assigned to each risk item.  Risk items can also be linked to other project artifacts, such as a requirement or test case to simplify tracking if desired.  Finally, various views can be created to filter the risks to show only those of interest for a particular analysis situation.  For example, one could create a view that shows only those risks assigned for mitigation in a particular microcycle/prototype or to show only those risks assigned to a particular individual. See the DOORS help to learn how to create filters and views.

Open the Risk Management Plan

Open the Risk Management Plan in DOORS.

Capture or Update Risk Information

Each Risk is entered into a separate DOORS Object. Select the view “02 – Risks”.

For each Risk:

  1. The Risk ID is automatically generated (it is the DOORS Object Identifier)
  2. Enter or update the following information:
    • Risk Name: This is the name of the risk - a short descriptive phrase can be used as well
    • Risk Description: This is a short description of the risk, how it might manifest, and the consequences
    • Computed Risk: this is a protected (non-modifiable) field that is computed from the Probability and Severity columns
    • Probability: this is the likelihood the risk will manifest itself. The valid range is 0.0 to 1.0, inclusive.
    • Severity: this is a measure of the consequence of the risk should it manifest itself. The valid range is 0.0 (no impact) to 10.0 (highly severe impact).
    • Owner: this is the person or team responsible to investigate or mitigate the risk
    • Planned Start: this is optional, but identifies the date planned to start the risk mitigation activity
    • Prototype Affected: this identifies the prototype (by name or number) in which the risk mitigation activity will be performed
    • Planned effort: Expected effort of the risk mitigation activity, with both a numeric value and units (e.g. 2 weeks)
    • Mitigation activity: this is a description of the activity that will be performed to investigate or mitigate the risk

Note: The Computed Risk attribute is automatically calculated by multiplying the Severity by the Probability. In order to update this attribute for all risks in the Risk Management Plan select Tools->Refresh DXL Attributes.  The Computed Risk is also updated automatically when the module is opened.

Tips

Tip: Each row in this document has associated attributes. If you copy an existing row you will preserve the attribute values.

Tip: Experienced users can modify the structure, attributes, and views of this document as necessary.