Software Process
Software Process
Hanna Oktaba
Nacional Autonomous University of Mexico, Mexico
Mario Piattini
University of Castilla-La Mancha, Spain
Copyright © 2008 by IGI Global. All rights reserved. No part of this publication may be reproduced, stored or distributed in any form or by
any means, electronic or mechanical, including photocopying, without written permission from the publisher.
Product or company names used in this set are for identification purposes only. Inclusion of the names of the products or companies does
not indicate a claim of ownership by IGI Global of the trademark or registered trademark.
Software process improvement for small and medium enterprises : techniques and case studies / Hanna Oktaba and Mario Piattini, editors.
p. cm.
Summary: "This book offers practical and useful guidelines, models, and techniques for improving software processes and products for
small and medium enterprises, utilizing the authoritative, demonstrative tools of case studies and lessons learned to provide academics,
scholars, and practitioners with an invaluable research source,"--Provided by publisher.
ISBN 978-1-59904-906-9 (hbk.) -- ISBN 978-1-59904-908-3 (e-book)
1. Computer software--Development--Management. 2. Computer software industry--Management--Case studies. 3. Small business--Data
processing--Case studies. I. Oktaba, Hanna. II. Piattini, Mario, 1966-
QA76.76.D47S66354 2008
005.1--dc22
2008001869
All work contributed to this book set is original material. The views expressed in this book are those of the authors, but not necessarily of
the publisher.
Chapter II
The Application of International
Software Engineering Standards
in Very Small Enterprises
Claude Y. Laporte
École de Technologie Supérieure, Canada
Alain Renault
Centre de Recherche Public Henri Tudor, Luxembourg
Simon Alexandre
Centre d’Excellence en Technologies de l’Information et de la Communication, Belgium
AbstrAct
The software industry recognizes the value of very small enterprises in contributing valuable products
and services to the economy. As the quality of software increasingly becomes a subject of concern and
process approaches are maturing and gaining the confidence of companies, the use of ISO/IEC JTC 1
SC71 standards is spreading in organizations of all sizes. However, these standards were not written for
development organizations with fewer than 25 employees and are consequently difficult to apply in such
small settings. A new ISO/IEC JTC1 SC7 Working Group, WG24, has been established to address some
of these difficulties by developing profiles and providing guidance for compliance with ISO software
engineering standards. A survey was conducted to question these very small organizations about their
utilization of ISO/IEC JTC1 SC7 standards and to collect data to identify problems and potential solu-
tions to help them apply these standards. Over 400 responses were received from 32 countries. Results
from the survey are discussed.
Copyright © 2008, IGI Global, distributing in print or electronic forms without written permission of IGI Global is prohibited.
The Application of International Software Engineering Standards in Very Small Enterprises
Table 1. Size of software development companies in the Montreal area (Laporte et al., 2006)
The Application of International Software Engineering Standards in Very Small Enterprises
joined forces and put in place a joint technical • ISO/IEC 12207 Software Life Cycle Processes
committee called Joint Technical Committee 1 (ISO/IEC 12207, 1995)
(ISO/IEC JTC1) with the following mandate: • ISO/IEC 15288 Systems Life Cycle Processes
“Standardization in the Field of Information (ISO/IEC 15288, 2002)
Technology: Information technology includes the • ISO/IEC 15504 Software Process Assessment
specification, design, and development of systems series (ISO/IEC 15504, 2003-2005)
and tools dealing with the capture, representa- ° As an example, the Capability Matu-
tion, processing, security, transfer, interchange, rity Model®2 IntegrationSM3 (CMMI®)
presentation, management, organization, storage, conforms to ISO/IEC 15504
and retrieval of information” (Coallier, 2003). The • ISO/IEC 90003 (ISO/IEC 90003, 2004)
mandate of subcommittee SC7, within JTC1, is Guidelines for the Application of ISO 9001
to standardize processes, supporting tools, and (ISO 9000, 2000) to computer software
supporting technologies for the engineering of
software products and systems. The relationships between these standards are
Figure 1 illustrates the evolution of the ISO/IEC illustrated in Figure 2.
JTC1 standards that are maintained and published Although these standards are well known in
under the responsibility of SC7. large software and systems engineering organiza-
Within the portfolio of SC7 standards, a num- tions, the current SC7 Life Cycle standards are a
ber of international standards are grouped together challenge to use in VSEs, and compliance with
in a category called “Software and Systems En- them is difficult, if not impossible, to achieve.
gineering Processes.” These standards describe Consequently, VSEs have few, or a very limited
good software and systems engineering practices, number of, ways to be recognized as organizations
as well as standards assessing them. Within this producing quality software systems.
group, there are four key ISO/IEC standards:
Figure 1. Evolution of published ISO/IEC JTC1 SC7 software and systems engineering standards (SC7,
2006)
The Application of International Software Engineering Standards in Very Small Enterprises
At the Brisbane meeting of the SC7 in 2004, It was also decided that a special interest group
Canada’s representatives raised the issue of small (SIG) be created to explore these objectives and
enterprises requiring standards adapted to their to better articulate the priorities and the project
size and maturity level. The current software plan. The participants felt that it would be pos-
engineering standards target (or are perceived sible, during 2004, to draw up:
as targeting) large organizations. Australian’s
delegates supported Canada’s representatives’ • A set of requirements
position in this regard, and the two national bodies • An outline of key deliverables and the as-
took action to investigate possible ways forward. sociated processes to create them (e.g., how
A meeting of interested parties was held with to create profiles)
delegates from five national bodies (Australia, • A terms of reference document for the work-
Canada, the Czech Republic, South Africa, and ing group
Thailand) at which a consensus was reached on • An example of a simple profile
the general objectives:
The Application of International Software Engineering Standards in Very Small Enterprises
first special working group risk is of great concern while larger organizations
Meeting – thailand rank managing risk as priority number 8 only.
Conversely, for small organizations, consistency
In March 2005, the Thailand Industrial Standards across teams is less of a concern, while for larger
Institute (TISI) invited a Special Working Group organizations it is a top-priority issue.
(SWG) to advance the work items defined at the A consensus was achieved by the members
Brisbane meeting. The meeting was attended of the SWG on this study and a consensus was
by delegates from the following countries: Aus- reached on defining our target VSE as IT services
tralia, Belgium, Canada, the Czech Republic, and organizations and projects with between 1
Finland, South Africa, South Korea, the USA, and 25 employees.
and Thailand. A list of actions that could be undertaken by a
A key topic of discussion was to clearly define future ISO/IEC SC7 working group was developed
the size of a VSE that would be targeted by the at this meeting. The proposed action items are:
working group. The working group used a paper
published by the Centre for Software Process 1. Validate the work products produced by the
Technologies (McFall et al., 2003) to help define working group
the size of small organizations. McFall et al. pre- 2. Prepare, conduct, analyze, and communicate
sented the various perceived priorities and areas survey results
of concern for different organization sizes. 3. Search for other centers/organizations focus-
As illustrated in Figure 3, the priorities and ing on SMEs and VSEs
concerns of organizations with fewer than 20 4. Assemble a complete list of characteristics
employees are quite different from those of larger of VSEs and projects
organizations. As an example, medium and large 5. Generate multiple profiles from the standards
organizations rank process adherence higher than mentioned above
do small organizations. For the latter, managing 6. Prepare communication material to inform
VSEs about the work performed by the WG
Figure 3. Priority and concern differences based on organization size (McFall et al., 2003)
The Application of International Software Engineering Standards in Very Small Enterprises
7. Develop business cases for the adoption and The major output of this one-week meeting
deployment of work products developed by was a document that has since been presented
the WG and discussed at the Helsinki SC7 meeting held
8. Develop one or more ISO 12207 roadmaps in May 2005. The document was essentially a
9. Pilot roadmaps, using an approach similar to draft list of the new work item that was approved
the trials conducted by the ISO/IEC 15504 by ISO/IEC in September 2005. This document
(SPICE) project is presented later.
The major output of this one-week meeting Plenary Meeting of Iso/Iec Jtc
was a draft list of new work items, as described 1/sc7 Meeting – finland
later. A work schedule has also been developed for
the new working group. As illustrated in Figure The document developed in Thailand was re-
4, the top row shows the standard steps for the viewed during a meeting of one of the WGs at
development and approval of an ISO standard. the 2005 SC7 plenary meeting in Helsinki. A
The lower part of the figure illustrates the actions resolution was approved as follows: “JTC1/SC7
that would need to be performed, as well as their instructs its Secretariat to distribute for letter
expected date of completion, in order to obtain a ballot an updated version of New Work Item Pro-
CD 1 (Committee Draft) by the end of 2007. posal for the development of Software Life Cycle
The Application of International Software Engineering Standards in Very Small Enterprises
Profiles and Guidelines for use in Very Small including small software systems develop-
Enterprises (VSE) by 20 June 2005 (ISO/IEC ment departments and projects within larger
JTC1/SC7 N3288, 2005). organizations.
Balloting on this document was open until ° Guides to be based on ISPs identifying
September 21, 2005. Over 12 countries voted in which parts of the existing standards
favor of the NWI Proposal, and the following are applicable to VSEs at a specific
countries indicated a commitment to participate level and for a specific domain.
in the new working group: Belgium, Canada, ° Guides which can be applied throughout
the Czech Republic, Ireland, Italy, Japan, Korea, the life cycle for managing and perform-
Luxemburg, South Africa, Thailand, the UK, and ing software development activities; the
the USA. As a result of this vote, the project was ultimate goal is to improve the com-
approved and the new working group, WG24, was petitiveness and capacity of VSEs.
established as follows:
Purpose and Justification
• Mr. Tanin Uthayanaka (Thailand) was ap-
pointed convener. The software systems industry as a whole
• Mr. Claude Y. Laporte (IEEE Computer So- recognizes the value of VSEs in terms of their
ciety) was appointed project editor. contribution of valuable products and services.
• Mr. Jean Bérubé (Canada) was appointed The majority of software organizations fall
secretary. within the VSE size category. From the various
surveys conducted by some of the national bod-
Proposed Project tabled at Iso/Iec ies that initially contributed to the development
Jtc 1/sc7 of this NWI list, it is clear that the current SC7
Life Cycle Standards (ISO/IEC 12207 and the
The document tabled at the SC7 Helsinki plenary related guide) are a challenge to use in these or-
meeting describes the scope and purpose of the ganizations; compliance with them is difficult (if
proposed working group, the justification for it, not impossible) to achieve. Consequently, VSEs
and a vision statement. In the following para- have few, or a very limited number of, ways to
graphs, each element of that project is presented. be recognized as organizations producing quality
The text below has been extracted from the docu- software systems, and therefore they do not have
ment balloted by the ISO (ISO/IEC JTC1/SC7 access to some markets. Currently, conformity
N3288, 2005). with software engineering standards requires a
critical mass in terms of number of employees,
Project scope cost, and effort, which VSEs cannot provide.
This project will attempt to ease the difficul-
• Organizations and projects with fewer than ties associated with the use of ISO/IEC 12207
25 employees. processes and ISO 9001:2000 and reduce the con-
• The current scope of ISO/IEC 12207 and its formance obligations by providing VSE profiles.
amendments, the associated guidance docu- The project will develop guidance for each process
ment and other relevant SC7 standards (e.g., profile and provide a roadmap for compliance with
ISO/IEC 15504, ISO/IEC 90003). ISO/IEC 12207 and ISO 9001:2000.
• Production of technical reports (guides) estab- It has been reported that VSEs find it difficult
lishing a common framework for describing to relate ISO/IEC 12207 to their business needs
assessable life cycle profiles used in VSEs, and to justify the application of the international
The Application of International Software Engineering Standards in Very Small Enterprises
standards in their operations. Most VSEs cannot • Address the market needs of VSEs by allowing
afford the resources for, or see a net benefit in, domain-specific profiles and levels.
establishing software processes as defined by • Provide examples to encourage VSEs to adopt
current standards (e.g., ISO/IEC 12207). A liaison and follow processes that lead to quality soft-
will be established between the proposed work ware, matching the needs, issues, and risks
and other SC7 work; specifically, the progress of of their domain.
ISO/IEC 12207 will be tracked. • Provide a baseline for how multiple VSEs can
work together or be assessed as a project team
vision statement on projects that may be more complex than
can be performed by any one VSE.
This project will: • Develop scalable profiles and guides so that
compliance with ISO/IEC 12207 and/or ISO
• Provide VSEs with a way to be recognized 9001:2000 and assessment become possible
as producing quality software systems with- with a minimum of redesign of the VSE’s
out the initial expense of implementing and processes.
maintaining an entire suite of systems and
software engineering standards or performing referenced documents
comprehensive assessments.
• Produce guides which are easy to understand, As illustrated in Figure 5, a number of documents
affordable, and usable by VSEs. have been identified as pertinent inputs to this
• Produce a set of profiles, which build on or im- project: ISO 90003, ISO/IEC 12207, ISO/IEC
prove a VSE’s existing processes, or provide 15504, Capability Maturity Model Integration
guidance in establishing those processes.
The Application of International Software Engineering Standards in Very Small Enterprises
(CMMI) and the Software Capability Maturity 3. Gain consensus and commitment of WG
Model (SW-CMM). members regarding the project
4. Process the NWI comment disposition
second special working group 5. Liaise with other related working groups (i.e.,
Meeting – thailand WG7 and WG10)
6. Define the profile creation strategy
In July 2005, the Thailand Industrial Standards 7. Define situational factors, that is, the attributes
Institute (TISI) sent out a second invitation to of a business model, such as the critical-
participate in the Special Working Group held in ity of the software under development, that
September 2005 in Bangkok. The main objective influence the selection of software practices
of the meeting was to prepare material that would (Iberle, 2002) and business models
be presented to WG24 in order to facilitate the 8. Build survey material in order to validate
start-up of the working group. The main outputs project requirements and collect missing
of the meeting were: information for the industry
• Proposed requirements for ISPs based on Discussion on the material presented in order
Technical Report ISO/IEC TR10000-1 to start building consensus led to the updating of
• A proposed survey on VSE exposure and some input documents and the validation of the
needs for software development life cycles project baseline. The new work item list was updat-
• Proposed approaches to profile development ed in order to take into account relevant comments
and architecture received during balloting, and the requirements
• Proposed business models, that is, how were validated by WG members. Furthermore,
organizations profit from software (Iberle, some VSE business models were identified (i.e.,
2002), such as custom systems written on custom on contract, custom in-house, commercial
contract, custom systems written in-house, products, mass-market software, firmware), as
commercial products (mass-market), and well as a strategy for creating profiles. Finally,
consumer software WG24 designed a survey in 2006 to collect rel-
• Proposed agenda for the first WG24 meet- evant information from VSEs around the world.
ing Twelve countries committed to participation in
• Proposed draft strategic plan for WG24 WG24: Belgium, Canada, the Czech Republic,
Ireland, Italy, Japan, Korea, Luxemburg, South
first Iso/Iec Jtc 1/sc7 wg24 Africa, Thailand, the UK, and the USA.
Meeting – Italy
second Iso/Iec Jtc 1/sc7 wg24
In October 2005, Italy hosted the ISO/IEC JTC1 Meeting – thailand
SC7 Interim Meeting 2005. WG24, officially es-
tablished at the SC7 plenary meeting in Helsinki, In the previous meetings, national delegates
held its first working sessions there in order to: presented documents for discussion, which the
members of WG24 reviewed and discussed. In
1. Present the project to the official members May 2006, WG24 members met at the ISO/IEC
of WG24 JTC 1/SC7 plenary meeting in Thailand. Two
2. Finalize project requirements to constitute new countries, India and Mexico, sent delegates
the project baseline to WG24. The three main outputs of the meet-
ing were:
0
The Application of International Software Engineering Standards in Very Small Enterprises
1. Analysis of the survey responses: competitive, since WG24 will try to benefit from
• 345 responses were collected from 26 coun- the experience gained by these centers.
tries.
° 219 responses were received from en- Centre for Software Process
terprises with 25 or fewer employees. Technologies
° Over 67% indicated that it was impor-
tant to be either recognized or certified The Centre for Software Process Technologies
(e.g., ISO, market). (CSPT)4 is a research and knowledge transfer
° WG24 decided to prioritize the develop- organization hosted by the Faculty of Engineering
ment of profiles and guides for orga- at the University of Ulster. Its activities cover a
nizations with 25 or fewer employees wide range of areas affecting the quality and effec-
(total staff). These profiles and guides tiveness of both software development processes
should also be usable for projects and and products, from process measurement, through
departments with 25 fewer employ- business process co-evolution, to object oriented
ees. software complexity metrics. The CSPT recently
• WG24 decided to propose separate profiles published the results of its first six assessments
for: in small- and medium-sized enterprises (SMEs)
° Enterprises with fewer than 10 employ- using its express process appraisal (EPA) method
ees and (Wilkie, McFall, & McCaffery, 2005). EPA is a
° Enterprises with 10 to 25 employees. class C method that complies with the appraisal
• WG24 decided to focus first on enterprises requirements for CMMI (2002). The EPA model
with fewer than 10 employees. assesses six of the seven process areas at maturity
2. Evaluation of documents tabled by national level 2: requirements management, configuration
delegations. management, project planning, project moni-
3. Selection of the Mexican Standard (NMX- toring and control, measurement and analysis,
059-NYCE, 2005) as an input document for and process and product quality assurance. The
the development of profiles and guides. (The authors reported that the EPA method requires
Mexican standard is presented later.) approximately 45 person-hours of the appraised
organization’s time and 42 person-hours of the
centers and Initiatives focusing on CSPT appraisal team’s time over a two-week
small and very small software period.
enterprises The CSPT also published a paper (McFall et
al., 2003) in which the authors present the various
In this section, we describe the work performed perceived priorities and concern areas for different
by a few centers and initiatives that focus their sizes of organizations. As illustrated in Figure 3,
activities on small and very small enterprises. the priorities and concerns of organizations with
Most software engineering research centers, such fewer than 20 employees are quite different from
as the Software Engineering Institute, dedicate those of larger organizations. As an example, for
their resources mainly to large organizations. Even small organizations, managing risk is of great
though there seems to be a certain awareness of concern, while for larger organizations, this only
those needs for VSE solutions, these are still quite ranks as priority number 8. Conversely, for small
unusable by companies with 25 or fewer employ- organizations, consistency across teams is less of
ees. We discuss their objectives and accomplish- a concern, while for larger organizations, this is
ments in helping these enterprises become more the top-priority issue.
The Application of International Software Engineering Standards in Very Small Enterprises
The Application of International Software Engineering Standards in Very Small Enterprises
• Training and expert services for software operation. Currently, NORMAPME is party to
process improvement an EC contract offering standardization services
• Process assessments, improvement planning, to SMEs.
and results evaluation The principal and most important activity of
• Training and expertise in software manage- NORMAPME is participation in the standardiza-
ment, methods, and technologies tion process: experts recommended by member
SME organizations participate in the work of
Two SataSPIN projects have involved 20 soft- technical committees at the European standard-
ware SMEs and over 400 IT professionals. ization organizations (CEN, CENELEC, ETSI)
and at the ISO.
NORMAPME Second, NORMAPME collects information
on new directives, directives under review, and
NORMAPME8 (2006) is the European Office of standardization works. Essential parts of this
Crafts, Trades, and SMEs for Standardisation. It information are published in simple language by
is an international nonprofit association created in means of newsletters, specific circulars, a Web
1996 with the support of the European Commis- site, seminars, and the like. All publications are
sion and the only European organization focusing translated into six languages (English, French,
on small enterprise interests in the European German, Spanish, Italian, and Polish) in order
standardization system. Its members represent for them to be accessible by the largest number
over 11 million enterprises in all European coun- of Europeans.
tries, including all EU and EFTA member states, NORMAPME members, and all SMEs and
and its mission is to defend the interests of all of their organizations, have the opportunity to for-
them. This mission is of crucial interest, as SMEs mulate proposals for the improvement of standards
represent over 90% of European companies, and and directives. These opinions are debated in the
they employ nearly 81 million people, which is expert groups in order to draft SME representative
66% of Europe’s total employment. positions. Once these positions are finalized, they
Standards are essential for SMEs today, as they are promoted in the standards organizations, in
are for any company operating in an internal mar- European institutions, and through the media by
ket. The application of standards adoption guar- publishing articles and through the press.
antees them several advantages, such as enlarging
the potential market for products, facilitating Software Quality Institute
product acceptance, lowering transaction costs,
achieving economies of scale, reducing external The Software Quality Institute, Griffith University
effects (like environmental impact), interoperabil- (Australia), developed the rapid assessment for
ity, improving management systems, and so on. process improvement for software development
Thus, standards definition cannot be a privilege (RAPID) method in conformity with ISO/IEC
enjoyed by big companies alone. SMEs must be 15504 (Rout, Tuffley, Cahill, & Hodgen, 2000).
represented. However, SMEs lack knowledge RAPID was developed for SMEs with limited
with respect to standards and standardization, and investment of time and resources. The model
they need some support to help them implement includes eight ISO/IEC 15504 processes: require-
existing standards, as well as have a voice in the ments gathering, software development, project
standardization process. management, configuration management, quality
The European Commission (EC) has sup- assurance, problem resolution, risk management,
ported NORMAPME during its first years of and process establishment. The scope of the
The Application of International Software Engineering Standards in Very Small Enterprises
model is limited to Levels 1, 2, and 3, although and the answers are neither cross-checked nor
capability ratings at Levels 4 and 5 are possible. validated.
The organizations assessed in Queensland ranged The rapid assessment procedure offered
in size from 3 to 120 employees, with an average through awareness and training events shows
size of 10 to 12 employees. that, in very many cases, identifiable benefits can
be achieved via focused SPI projects. The offer
ESPRIT – ESPINODE Initiative of a free (rapid) assessment is a way to both dif-
fuse process quality concepts and propose actual
An assessment methodology has been developed improvement paths to enterprises.
by ESPINODE for Central Italy, with the aim
of using rapid software process assessment as a Mexican Approach
way to promote innovation for SMEs (Cignoni,
1999). The methodology is based on a two-part In Mexico, it was felt that standards such as ISO/
questionnaire compiled by experts who inter- IEC 12207, or models such as CMMI, were either
view representatives of the enterprise. Part 1 is too general or too costly for Mexican enterprises.
conducted by phone, and Part 2 is completed in A Mexican standard was therefore developed at
a direct audit meeting. the request of the Ministry of the Economy. It
Rapid-assessment meetings to allow enter- provides the software industry there with a model
prises to “taste” SPI and awareness and training based on international practices and on the fol-
events are used as a way to establish the very first lowing characteristics:
contact with the enterprises and to present the
opportunity of a rapid software process assess- • It is easy to understand.
ment as a free service. The specific goals of the • It is easy to apply.
subsequent assessment program are: • Adopting it is economical.
• It provides the basis on which to achieve suc-
• To stimulate interest in software process as- cessful evaluations with other standards or
sessment and improvement models, such as ISO 9000:2000 or CMMI®.
• To contribute to the definition of specific
improvement plans The Mexican standard (NMX-059-NYCE,
• To collect data and statistics about software 2005) is divided into four parts: Part 1, Defini-
process maturity tion of Concepts and Products; Part 2, Process
Requirements (MoProSoft); Part 3, Guidelines for
Being “rapid,” the methodology developed is Process Implementation; and Part 4, Guidelines
also approximate. Due to time constraints, the for Process Assessment (EvalProSoft).
scope and accuracy of the assessment are sacri-
ficed, since the assessment meeting is limited to the Process Model
half a day, including time for discussion. In par-
ticular, a very general assessment is made of the The process model MoProSoft uses ISO/IEC
35 processes, and some more accurate questions 12207 as a general framework. It was devel-
are formulated on just three processes belong- oped considering integration between software
ing to two of the five SPICE process categories. processes and business processes and borrows
Moreover, the accuracy of the assessment is practices from ISO 9000:2000 and CMMI®. It also
limited to the answers given by the enterprises, incorporates practices from the Project Manage-
The Application of International Software Engineering Standards in Very Small Enterprises
ment Body of Knowledge (PMBOK, 2006) and In addition, MoProSoft highlights informative
the Software Engineering Body of Knowledge data, added to the normative part, and proposes
(SWEBOK) (ISO TR 19759, 2005). In addition, tailoring guides for each process. This is a very
MoProSoft addresses the process model require- helpful feature and one requested by VSEs in
ments of ISO/IEC 15504-2 (ISO/IEC 15504-2, the survey.
2003). The percentage of coverage by MoProSoft
with respect to these practices is as follows: the Assessment Method
The Application of International Software Engineering Standards in Very Small Enterprises
The Application of International Software Engineering Standards in Very Small Enterprises
12207
12207 Processes & Level I Level II Level III Level IV Level V
Activities
Primary
5. life cycle
processes
Development Process Process Process Process Process
5.3
process implementation implementation implementation implementation implementation
Software Systems Systems Systems Systems
requirements requirements requirements requirements requirements
analysis analysis analysis analysis analysis
Software System System System System
architectural architectural architectural architectural architectural
design design design design design
Software Software Software Software
Software coding
requirements requirements requirements requirements
and testing
analysis analysis analysis analysis
Software Software Software Software Software
acceptance and architectural architectural architectural architectural
support design design design design
Software
Software detailed Software Software
coding and
design detailed design detailed design
testing
Software
Software Software coding Software coding
coding and
installation and testing and testing
testing
Software
Software Software Software
acceptance and
integration integration integration
support
System System System
qualification qualification qualification
testing testing testing
Software Software Software
installation installation installation
Software Software Software
acceptance and acceptance and acceptance and
support support support
(Paulk, Curtis, Chrissis, & Weber, 1993) and on development and project management, product
the ISO/IEC 15504 (SPICE) reference model and management, and training and human resources
uses an interview method. It covers six key axes management.
selected on the basis of former experience with The Micro-Evaluation was first tested on a
SME and VSE evaluation as the most pertinent sample of 20 organizations in Wallonia (Laporte,
and the most important to the targeted organiza- Renault, Desharnais, Habra, Abou El Fattah, &
tions. These axes are quality management, cus- Bamba, 2005). Figure 7 shows the global maturity
tomer management, subcontractor management, profile of the small enterprises involved in the first
The Application of International Software Engineering Standards in Very Small Enterprises
The Application of International Software Engineering Standards in Very Small Enterprises
10 processes (requirements management, project 100 employees, organizations with fewer than 50
planning, project tracking and oversight, devel- people, and projects with fewer than 20 people
opment, documentation, testing, configuration (Garcia, 2005). The IPSS project will assemble
management, subcontractors management, qual- small businesses, governments, large businesses,
ity management, and experience capitalization), advocacy organizations, universities, and indus-
each of which is decomposed into a number of try associations from around the world to jointly
practices (from 3 to 12). It is also supported by explore the unique challenges and opportunities
success factors. Each of the above processes is of applying process improvement strategies in
assigned a general goal in accordance with the small businesses. The SEI seeks to achieve the
organization’s defined objectives. It involves a following objectives:
number of practices and is supported by a number
of success factors. Each practice is defined by its • Increase awareness of process excellence as
goal, its inputs and outputs, the resources assigned an enabler of global competitiveness
to support it and its weight. This last attribute is • Demonstrate effective approaches to process
an indicator of the importance of the practice to improvement for the small business
improving the process as a whole. • Provide tools for process improvement that
are easily applied by small businesses
Software Engineering Institute
The ParqueSoft Organization of
The Software Engineering Institute (SEI) has Columbia
launched a project titled “Improving Processes in
Small Settings (IPSS).”12 For this project, small The Software Technology Park Foundation13
settings are defined as companies with fewer than (Fundación Parque Tecnológico del Software),
The Application of International Software Engineering Standards in Very Small Enterprises
0
The Application of International Software Engineering Standards in Very Small Enterprises
• VSEs require low-cost solutions. The IEEE survey gathered several new require-
• VSEs require additional effort in communica- ments about IEEE standards being requested by
tions, in standardizing vocabulary. the respondents. These were principally examples
• VSEs require a staged approach. and templates of deliverables (about 32 responses),
• VSEs require ways to identify potential quick support for metrics and measurement (about 30
wins. responses), help on life cycle process definition
(about 23 responses), and a training course and
support for small, rapid application development
fIndIngs of the Ieee efforts.
stAndArds survey
The Application of International Software Engineering Standards in Very Small Enterprises
encountered when using them, and how we can free tutorials for their members the week before
facilitate their adoption and utilization. the SC7 meeting. One condition for a SIPA mem-
An introductory text (see Appendix A) and ber to participate in the tutorials was to respond
a questionnaire were developed by a graduate to the survey. This resulted in over 58 responses
student and members of WG24 and translated from Thai VSEs (see Table 4). In Colombia, Par-
into nine languages: English, French, German, queSoft designated an individual to solicit VSEs
Korean, Portuguese, Thai, Turkish, Russian, and and help them complete the survey. Since there
Spanish. The survey (see Appendix B) is made up are over 100 VSEs in the Parquesoft group, this
of 20 questions structured in five parts: general explains the high number of responses received
information, information about standards utiliza- from that country.
tion in VSEs, information about implementation Respondents were informed that it would take
and assessment problems in VSEs, information a maximum of 15 minutes to complete the survey.
about VSE needs, and information about justifica- They were also informed that all data would be
tion for compliance to standard(s). kept confidential and that only summary results
A Web site, hosted by the École de Technologie and project data that could not be matched to a
Supérieure,14 was developed to maximize the num- specific VSE would be included in the published
ber of responses and facilitate data collection and results.
analysis. A mailing list was created using WG24 In order to increase participation in the survey,
members’ contact networks. We also contacted WG24 promised to send all respondents a report
centers and software engineering professors focus- presenting, on an anonymous basis, the survey re-
ing on the concerns of small software enterprises, sults. The survey was launched in February 2006,
such as the CETIC15 Center in Belgium, the Centre and, as of as of June 2006, over 392 responses
de Recherche Public Henri Tudor in Luxem- had been collected from 29 countries.24
bourg,16 the Thai Software Industry Promotion
Agency (SIPA17), The European Software Institute categorization of the sample
(ESI18), the Colombian Parquesoft19 organization, According to the size criterion
the Japan Information Technology Promotion
Agency (JITEC20), the Irish Enterprise Ireland,21 In order to avoid developing profiles that would
and the Software Process Improvement Networks not meet the needs of VSEs, WG24 defined what
(SPIN22) worldwide. Access to the Web-based VSEs are in terms of size. At the time, there was
survey was protected, as suggested by Kasunic no official definition of the VSE, while the concept
(2005), to prevent unauthorized individuals from of the small- and medium-sized enterprise (SME)
participating and to prevent duplicate submissions had already been clearly defined in Europe (fewer
by a single respondent. The survey software, pro- than 250 employees or with a turnover ≤ €50
duced by Quask,23 was satisfactory. Its weakness million) and in the United States (fewer than 500
was that it was not capable of supporting double employees). The Organization for Economic Co-
characters. These characters are used in languages operation and Development (OECD) subdivides
such as Thai, Korean, and Russian. To remedy the SME category into several subcategories:
this problem, we provided the survey question- micro (025-9 employees); small (10-49 employees);
naire to the respondents from these countries as and medium (50-250 or 500 in the United States).
a Word document. In Europe, micro enterprises represent 93% of the
One of these organizations, Thailand’s SIPA, total number of companies (56% in the United
also acted as a host for the 2006 ISO/IEC JTC1/SC7 States) and 66% of total employment [9].
plenary meeting. The SIPA organized a series of Of the 392 responders, 228 were enterprises
The Application of International Software Engineering Standards in Very Small Enterprises
%
%
0-
0-
% -
0-
0-++
%
%
The Application of International Software Engineering Standards in Very Small Enterprises
to the extent that this sample represents them. for life/mission-critical systems and 34% on
Moreover, we have no evidence that participat- regulated developments.
ing companies are representative of the situation With regard to the types of software develop-
in their own countries. Conclusions drawn from ment, the majority control customized or tailor-
these survey results should be confirmed with made software and specialized products, as shown
additional responses. To achieve this objective, in Figure 11.
WG24 plans to keep the survey Web site online
and launch another survey blitz. features of the vse results
The strong representation of Latin American
countries in the sample has no impact on the final More than 70% of VSEs are either working on
results of the study. These VSEs differ from the life- or mission-critical systems, or in a regulated
rest of the respondents in the types of develop- market. This underscores our hypothesis concern-
ment, that is, more specialized products and the ing the awareness of the participating companies,
application domain, as they are more involved as it is assumed that companies working on these
in critical applications with almost 50% of VSEs particular contexts are prone to using standards
working on these fields. for contractual reasons. An interesting finding
Among the respondents, the majority (79%) of the survey is the difference in the percentage
are private companies and 78% operate at the of certified companies with regard to company
national level only. Regarding the application size: fewer than 18% of VSEs are certified, while
domain, as shown in Figure 10, almost half the 53% of larger companies (those with more than
respondents are working either on life/mission- 25 employees) claim to be certified. Furthermore,
critical systems or on regulated projects. Over among the 18% not certified, 75% do not use
40% of the respondents are developing software standards. In larger companies using standards,
The Application of International Software Engineering Standards in Very Small Enterprises
0
0
0
0
number of answers
00
0
0
0
0
0
Life or mission-critical Regulated Non-critical Other
systems
0
0
00
number of answers
0
0
0
0
0
Customized In-house Commercial of- Specialize Embedded Integrated Other
the-shelf Product
(COTS)
The Application of International Software Engineering Standards in Very Small Enterprises
10%
24%
15%
9% Not required
Lack of support
14%
Lack of resources
Too time-consuming
Standard(s)
28%
Other
The Application of International Software Engineering Standards in Very Small Enterprises
future work And conclusIon will enable WG24 to propose profiles, guides,
and templates for the 0-9 employee category and
The software industry recognizes the value of the 10-25 employee category that really take the
VSEs in contributing valuable products and concerns of VSEs into account and fit them into
services to the economy. As software quality their particular context. The working group’s key
increasingly becomes a subject of concern, and challenge will be the selection and tailoring of
process approaches are maturing and gaining the processes from existing standards (mainly ISO
confidence of companies, the use of standards is 12207) for VSEs.
spreading in organizations of all sizes. However, The next stage will be to undertake pilot pro-
existing standards were not written for small or jects. These will be conducted within real projects
very small organizations (development organi- to assess the artifacts developed by WG24, pro-
zations with fewer than 25 employees), and are viding the working group with key information
consequently difficult to apply in such settings, to update them and move towards international
though small and very small companies can balloting and publication by the ISO. We will
represent from 50 to 85% of a local economy in conduct pilot projects in different environments
some regions of the world. in order to gain confidence that their results will
A large number of universities, research cen- be applicable to a wide spectrum of VSEs. These
ters, and associations have tried to find their own projects will be coordinated and monitored by the
answers to this issue being faced by most VSEs, members of WG24. The fact that the members of
and are proposing software process models dedi- this working group are located on many contin-
cated to small companies. However, at this point, ents should enable us to conduct pilot projects in
no one has been able to propose a one-size-fits-all different cultural contexts.
solution for any context and taking all previous
experience and knowledge into account. Most
potential solutions are still too complicated and AcknowledgMent
cannot be applied to VSEs as defined in the scope
of this project. The authors would like to thank Mrs. Karine
A new ISO/IEC JTC1 SC7 Working Group, Bluteau, a graduate software engineering student
WG24, has been established to address those dif- at the ÉTS, who was instrumental in developing
ficulties by developing profiles and by providing and conducting the survey and the establishment
guidance for compliance by very small organiza- of the survey Web site. The authors would also
tions with ISO software engineering standards. like to thank all those who helped translate the
A survey was conducted to ask these very small survey and invited VSEs to respond to it.
organizations about their use of ISO/IEC JTC1
SC7 standards and to collect data to identify prob-
lems and potential solutions to help them apply references
standards. Over 400 responses were received from
30 countries. The survey was intended to validate Ad Hoc Report. (2004, May). Software engineer-
working hypotheses regarding VSEs drawn up by ing standards for small and medium enterprises.
the working group. ISO/IEC JTC1/SC7 /N3060. Retrieved December
Based on this feedback, the working group will 12, 2007, from [Link]
start tailoring existing solutions (i.e., the Mexican
Anacleto, A., von Wangenheim, C.G., Salviano,
standard) to adapt them to the requirements ex-
C.F., & Savi, R. (2004). Experiences gained
pressed by VSEs taking part in the survey. This
The Application of International Software Engineering Standards in Very Small Enterprises
from applying ISO/IEC 15504 to small software ISO/IEC 15504. (2003-2005). Information tech-
companies in Brazil. In Proceedings of the 4th nology: Process assessment (Part 1-5). Geneva,
International SPICE Conference on Process Switzerland: International Organization for
Assessment and Improvement, Lisbon, Portugal Standardization/International Electrotechnical
(pp. 33-37). Commission.
Cellule Interfacultaire de Technology Assessment ISO/IEC 15504-2. (2003). Information technol-
CITA. (1997). Utilisation des Systèmes d’Infor- ogy: Process assessment (Part 2: Performing an
mation Inter-Organisationnels [SIO] par les PME assessment). Geneva, Switzerland: International
Belges (SIO Research Report). Cita-Computer Organization for Standardization/International
Sciences Department, University of Namur. Electrotechnical Commission.
Cignoni, G.A. (1999). Rapid software process ISO/IEC 17799. (2005). Information technology:
assessment to promote innovation in SME’s. In Security techniques (Code of practice for informa-
Proceedings of Euromicro 99, Italy. tion security management). Geneva, Switzerland:
International Organization for Standardization/
CMMI. (2002). CMMI for systems engineering
International Electrotechnical Commission.
and software engineering (CMMI-SE/SW, V1.1):
Continuous representation (CMU/SEI-2002-TR- ISO/IEC 90003. (2004). Software engineering:
001). Software Engineering Institute. Guidelines for the application of ISO 9001:2000
to computer software. Geneva, Switzerland:
CMMI. (2002). CMMI for systems engineering
International Organization for Standardization/
and software engineering (CMMI-SE/SW, V1.1):
International Electrotechnical Commission.
Staged representation (CMU/SEI-2002-TR-002).
Software Engineering Institute. ISO/IEC 9001. (2000). Quality management
systems: Requirements. Geneva, Switzerland:
Coallier, F. (2003). International standardization
International Organization for Standardization/
in software and systems engineering. Crosstalk,
International Electrotechnical Commission.
Journal of Defense Software Engineering, 18-
22. ISO/IEC JTC1/SC7 N3288. (2005, May). New
work item proposal: Software life cycles for very
Garcia, S. (2005). Thoughts on applying CMMI in
small enterprises. Retrieved December 12, 2007,
small settings. Presentation to Montréal SPIN.
from [Link]
Iberle, K. (2002). But will it work for me? In
ISO/IEC TR 10000-1. (1998). Information technol-
Proceedings of the Pacific Northwest Software
ogy: Framework and taxonomy of international
Quality Conference, Portland, WA.
standardized profiles (Part 1: General principles
ISO/IEC 12207. (1995). Information technol- and documentation framework, 4th ed.). Gen-
ogy: Software life cycle processes. Geneva, eva, Switzerland: International Organization for
Switzerland: International Organization for Standardization/International Electrotechnical
Standardization/International Electrotechnical Commission.
Commission.
ISOTR19759-05. (2005). Software engineering
ISO/IEC 15288. (2002). Systems engineering: body of knowledge: Technical report ISO/IEC
Systems life cycle process. Geneva, Switzerland: PRF TR [Link], Switzerland: International
International Organization for Standardization/ Organization for Standardization/International
International Electrotechnical Commission. Electrotechnical Commission.
The Application of International Software Engineering Standards in Very Small Enterprises
ITMark. (2006). Retrieved December 12, 2007, NMX-059-NYCE. (2005). Information technol-
from [Link] ogy-software-models of processes and assess-
ment for software development and maintenance
Kasunic, M. (2005). Designing an effective survey
(Part 1: Definition of concepts and products, Part
(Handbook CMU/SEI-2005-HB-004). Software
2: Process requirements (MoProSoft), Part 3:
Engineering Institute.
Guidelines for process implementation, Part 4:
Land, S.K. (1997, June 1-6). Results of the IEEE Guidelines for process assessment (EvalProSoft)).
survey of software engineering standards users. Mexico Ministry of Economy.
In Proceedings of the Software Engineering
NORMAPME. (2006). Retrieved December 12,
Standards Symposium and Forum: Emerging
2007, from [Link]
International Standards (ISESS 97), Walnut
Creek, CA (pp. 242-270). Parquesoft Brief. (2006). Cali, Colombia: Par-
quesoft.
Laporte, C.Y., & April, A. (2006a, January). Ap-
plying software engineering standards in small Paulk, M., Curtis, B., Chrissis, M.B., & Weber,
settings: Recent historical perspectives and initial C. (1993, February). Capability maturity model
achievements (CMU/SEI-2006-Special Report- for software (Version 1.1, CMU/SEI-93-TR-24,
001). In Proceedings of the 1st International DTIC No. ADA263403). Software Engineering
Research Workshop for Process Improvement in Institute.
Small Settings (pp. 39-51). Software Engineering
PMBOK. (2006). Project management body of
Institute, Carnegie Mellon University.
knowledge. Retrieved December 12, 2007, from
Laporte, C.Y., April, A., & Renault, A. (2006, May [Link]
4-5). Applying ISO/IEC software engineering
Resolutions. (2005, May). Presented at the
standards in small settings: Historical perspectives
JTC1/SC7 Plenary Meeting (ISO/IEC JTC1/SC7
and initial achievements. In Proceedings of the
N3274), Helsinki, Finland.
SPICE Conference, Luxembourg (pp. 57-62).
Rout, T., Tuffley, A., Cahill, B., & Hodgen, B.
Laporte, C.Y., Renault, A., Desharnais, J.M.,
(2000). The rapid assessment of software process
Habra, N., Abou El Fattah, M., & Bamba, J.C.
capability. In Proceedings of SPICE 2000, Lim-
(2005, May 27-June 1). Initiating software process
erick, Ireland (pp. 47-55).
improvement in small enterprises: Experiment
with micro-evaluation framework (SWDC-REK). SC7 Secretariat Presentation. (2005, May 25).
In Proceedings of the International Conference ISO/IEC Advisory Group Planning Meeting,
on Software Development, University of Iceland, Helsinki, Finland.
Reykjavik, Iceland (pp. 153-163).
SC7 Secretariat Presentation. (2006, May). Bang-
McFall, D., Wilkie, F.G., McCaffery, F., Lester, kok, Thailand.
N.G., & Sterritt, R. (2003, December 1-10).
Software Technology Park Foundation. (2006).
Software processes and process improvement
Retrieved December 12, 2007, from [Link]
in Northern Ireland. In Proceedings of the 16th
[Link]
International Conference on Software & Systems
Engineering and their Applications, Paris, France. Thai Quality Standard. (2005, March). Associa-
ISSN: 1637-5033. tion of Thai Software Industry presentation to
The Application of International Software Engineering Standards in Very Small Enterprises
0