Risk Management

1) Deliberate process of understanding risk and deciding upon and implementing actions to reduce risk to a defined level. Characterized by identifying, measuring, and controlling risks to a level commensurate with an assigned value. 2) The identification, assessment, and mitigation of probabilistic security events (risks) in information systems to a level commensurate with the value of the assets protected --

An organized means of controlling the risk on a project. --

Some good links:
  • Know Your Enemy: Software Risk Management by Karl E. Wiegers:
  • Risk Management in the context of system's engineering:
