Hacker News new | ask | show | jobs
by datadrivenangel 1040 days ago
Severity should include detectability. If you never detect an issue, it's not an issue because nobody sees it.
1 comments

Usually it is a seperate factor, at least as far as P/D-MEAs are concerned. Quick and dirty, sure, it can be included in severity. Personally, I prefer the increased transparency and granularity of having detectability as a different factor.