Risk Identification
This is a systematic attempt to specify threats to the project plan. With the identifying known and predictable risks the project manager will takes a first step toward avoiding them when possible and controlling them when needed.
There are 2 distinct categories of risks for each of the type that are generic risks and product-specific risks. The Generic risks are a potential threat to every software project and the Product-specific risks can only be identified by those with a clear understanding of the technology, the people, and the environment which is specific to the project at hand. To identify product-specific risks the project plan and the software statement of scope are examined and an answer to the following question which is developed that are what special characteristics of this product may threaten our project plan?
Both product-specific and generic risks should be identified systematically. The Tom glib drives this point home when he states that if you do not actively attack the risks they will actively attack you.