Catching Elephant is a theme by Andy Taylor (slightly modified)

 

…people tend to do software risk analysis by thinking of the severe risks first, and then the more manageable risks. So the more risk analysis that’s done, the less severe the last risk imagined, and thus the greater the underestimation of the total risk.

Bruce Schneier, in Imagining Threats, referencing Magne Jørgense’s paper More Risk Analysis Can Lead to Increased Over-Optimism and Over-Confidence

Blog comments powered by Disqus