Deciding what gets fixed.
WHAT SEVERITY MEASURES
Technical impact of the defect.
WHAT PRIORITY MEASURES
Urgency of fixing it.
WHY THEY DIFFER
A crash in a feature nobody uses is severe but not urgent; a spelling error on the home page is trivial but may be urgent.
WHAT SEVERITY LEVELS TYPICALLY MEAN
- Critical: data loss, security breach, or nothing works
- High: major function unavailable, no workaround
- Medium: function impaired, workaround exists
- Low: cosmetic or minor
WHAT TO ALWAYS TREAT AS CRITICAL
Data loss or corruption Security exposure Money handled incorrectly
WHY
They cannot be undone by fixing the code.
WHAT PRIORITY SHOULD CONSIDER
Users affected Business impact Whether a workaround exists Cost of fixing Risk of the fix
WHO SETS PRIORITY
The business, informed by the technical assessment.
WHAT TESTERS SHOULD NOT DO
Set priority unilaterally.
WHAT THEY SHOULD DO
Provide the information priority requires.
WHAT TO AVOID
Severity inflation, where everything becomes critical.
WHY
It removes the meaning of the scale.
WHAT TO REVIEW
Whether classification is applied consistently.