0% found this document useful (0 votes)
7 views59 pages

Software Process Improvement Models

Uploaded by

psmohammedali5
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views59 pages

Software Process Improvement Models

Uploaded by

psmohammedali5
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Software Process Improvement

Models and SCM


What is Process Improvement?
“The analysis and redesign of processes to
eliminate organizational problems and
inefficiencies in small increments, over time,
by improving one or two processes at a
time”
• Done at operational level
• Scope : limited to one or two process at a
time to control the damage
Benefits of Software Process
Improvement (SPI)
• Defines the various processes and activities
• Helps an organization to move from a stage of
total confusion to well-defined and mature state
• Helps the organization to continuously improve
the quality of the products, services and efficiency
of the organization and to deliver high quality
products
• Assess the current state, determine the process
maturity scale
- provide guidelines to increase the maturity levels
SPI Models and Standards
1. CMM - Capability Maturity Model
2. CMMI - Capability Maturity Model Integration
3. Information Technology Infrastructure Library
(ITIL)
4. Control Objectives for Information and Related
Technology (COBIT).
5. Software Engineering Body of Knowledge
(SWEBOK)
Capability Maturity Model - CMM
• Describes the principles and Maturity levels
practices underlying software
process maturity 1. Initial
• Improves the maturity of their 2. Managed
software processes 3. Defined
• The CMM is organized into five 4. Quantitative
maturity levels Managed
- Each maturity level provides a
5. Optimizing
layer in the foundation for
continuous process improvement
Key Process Areas
• “Each maturity level is broken down into
several key process to improve its software
process”
- Except Level 1
• KPA: Identify the issues that must be
addressed to achieve a maturity level
• Each key process area identifies a cluster of
related activities that performed collectively
• KPA for level 2: Configuration management
Goals
• The configuration management practice should
achieve the following four goals:
1. SCM activities are planned
2. Selected software work products are
controlled, and available
3. Changes to identified software work
products are controlled
4. Affected groups and individuals are
informed of the status and content of software
baselines
Commitments from Organization to
Achieve the goals
• Commitment to Perform
- certain commitments from the organization
• Ability to Perform
- The organizations should have the necessary resources
• Activities Performed
- Specifies several activities to be performed
• Measurement and Analysis
- Mechanisms for measuring and reviewing data
• Verifying Implementation
- Mechanisms for analyzing determining status, and
auditing
Capability Maturity Model
Integration- CMMI
• Addresses the need that computer system
development environments were concerned with more
than just software
• The CMMI 's mission was to combine three source
models
- The Capability Maturity Model for Software (SW-CMM)
- The Systems Engineering Capability Model (SEM)
- The Integrated Product Development Capability Maturity
Model (IPD-CMM)
• For the pursuit of enterprise-wide process
improvement
CMMI Model Representations
• There are two types CMMI model
representations
- Staged Representation
- Continuous Representation
Staged Representation
• It is the approach used in the SW-CMM.
• Uses predefined sets of process areas to
define an Improvement path for an
organization.
• Improvement path is described by a model
component called a maturity level
• A maturity level is a well-defined evolutionary
plateau toward achieving improved
organizational processes for a project
Continuous representation
• Allows an organization to select a specific
process area and improve relative to it
• Uses capability levels to characterize
improvement relative to an individual
process area
• A capability level : is a well-defined
evolutionary plateau toward achieving
improved organizational processes for a
particular organization
Configuration Management in CMMI
• CM comes under Support Process Area
• CMMI defines CM as a discipline whose
purpose is to
- Establish and maintain the integrity of work
products using configuration Identification
- Configuration control
- Configuration status accounting
- Configuration audits
Work Products
The work products placed under configuration
management include
• Products that are delivered to the customer
• Designated internal work products
• Acquired products
• Tools and other items that are used in creating and
describing these work products.
Examples of Work Products
• Plans
• process descriptions
• Requirements
• design data
• Drawings
• product specifications
• Code
• Compilers
• Product data files
• Product technical publications
Specific goal of configuration
management
• Establish baselines
- Baselines of identified Work Product
• Track and control changes
- Changes to work product under CC
• Establish integrity
- Integrity of Baselines
Practices for each specific goal of
configuration management
• Establish baselines (SG 1.)
- 1. Identify configuration Items (SP 1.1-1)
– 2. Establish a configuration management system (SP 1.2-
1)
- 3.. Create or release baselines (SP 1.3-1)

• Track and control changes (SG 2)


- [Link] change requests (SP 2.1-1)
– [Link] configuration items (SP 2.2-1)

• Establish integrity (SG 3)


- [Link] configuration management records (SP 3.1-1)
– [Link] configuration audits (SP 3.2-1
Information Technology Infrastructure Library
(ITIL)
ITIL
• ITIL is a framework of best practices for
delivering IT services.
• ITIL’s systematic approach to IT service
management can help businesses manage risk,
strengthen customer relations, establish cost-
effective practices, and build a stable IT
environment that allows for growth, scale and
change.
Objective
Key Objectives of IT Service Management:

1. Align IT Services with the Current and Future


Needs of the Business and its Customers
2. Improve Quality of IT Services
3. Reduce Long-Term Costs of IT Service Provision
The Deming Cycle
The Deming
Cycle
• Service strategy involves understanding customers and
how to develop and successfully execute IT services to
meet their needs
• Service design ensures that the service is designed
efficiently and cost-effectively.
• Service transition sees the design built and tested.
• Service operation delivers and manages the service.
Continual service improvement provides a mechanism for
improving the service and the technology and processes
used in its management.
ITIL Service Strategy
• Helps businesses develop organizational goals and objectives to prioritize customer
needs.
• ITIL Service Strategy involves examining the current market needs and existing
offerings and creating a plan for services to meet needs.
– Service portfolio management -managing the portfolio of all offered IT services
– Financial management for IT services - the budgeting, accounting, and charging activities of
the business. Financial Management also looks at the costs to provide services while
maximizing service value
– Strategy Management for IT Services - analyzing the market, reviewing current customer
needs, and planning for potential market expansion
– Demand management - customer’s demands, and balancing that with the capacity,
availability, and types of services provided are all part of Demand Management.
– Business relationship management -creating and maintaining customer relationships,
understanding customer needs, and providing services to meet those needs.
ITIL Service Design
• Offers a strategy to build a plan to deliver on established business objectives using RACI
matrix, which stands for Responsible, Accountable, Consulted and Informed.

• Service Level Management involves planning for and defining organizational service
delivery targets, and then measuring performance against those targets. Service level
agreements (SLAs) are often used to spell out service level goals for easy measurement and
comparisons against actual service performance.

• Service Catalog Management involves making sure that there is an updated service catalog
available with accessibility to services customers require to remain productive.

• Capacity Management ensures that systems are always operating at enough capacity to
meet business needs.

• Availability Management entails making sure that services are always available to the
customer.
ITIL Service Design (Cont)
• IT Service Continuity Management involves risk management and ensuring business
continuity.

• Information Security Management includes system and data protection, as well as


protection for the people who use the systems and data. Detecting, limiting and
preventing intrusions, as well as limiting damage and correcting problems are all aspects
of information security management.

• Supplier Management monitors all supplier relationships, including whether parties are
adhering to contracts and agreements.

• Design Coordination involves taking a all-inclusive view into managing the service design
phase - looking at resource availability and service needs to determine if the design is
optimum and efficient
ITIL Service Transition
• Focuses on the project development and operational use of
services, setting it apart from day-to-day IT maintenance.
• Change Management ensures that services remain scalable and
reliable as business needs change.
• Change Evaluation includes anticipating and managing changes,
as well as evaluating which changes merit moving forward.
• Release and Deployment Management involves software
deployment while making sure that changes minimally impact
the active/live production environment.
ITIL Service Transition (cont)
• Service Validation and Testing details testing and measuring results as

well as making service changes and/or service continuation decisions.

• Service Asset and Configuration Management manages the configuration

items (CIs) attributes, status, owner, relationships, and change/activity

history.

• Knowledge Management involves assembling and accumulating useful

knowledge for use by technicians and customers in resolving issues.

• Transition Planning and Support is a less common process and works to

plan for the transition of a new or updated service into production.


ITIL Service Operation
• ITIL Service Operation involves managing the smooth delivery of IT services with the ultimate
goal of delivering value to the business. Service Operation must be aware of the changing needs
within business based on advancing technology, such as cloud computing and cloud security
needs
• Incident Management is the process of taking action to rapidly restore interruptions in service
due to incidents. Incidents may include, password resets, printer failure, or an error message
• Problem Management works to pinpoint and prevent the recurrence problems and incidents.
• Event Management examines and analyzes all service events that may arise from applications,
monitoring solutions, and other systems so that action, if needed, can be taken to ensure
service continuity.
• Access Management controls who has access to the systems by preventing unauthorized
attempts to access the system while allowing access for legitimate users.
• Request Fulfillment process includes receiving, logging, prioritizing, and resolving service
requests received by the service desk.
ITIL Continual Service Improvement
achieves services incremental and large-scale improvements using a seven-step
process.
The seven steps include:
1. Identify the strategy for improvement
2. Define what you will measure
3. Gather the data
4. Process the data
5. Analyze the information and data
6. Present and use the information
7. Implement improvement
Benefits
ITIL provides a systematic and professional approach to the management of IT
service provision, and offers the following benefits:
• Reduced IT costs
• Improved IT services through the use of proven best practice processes
• Improved customer satisfaction through a more professional approach to
service delivery
• Standards and guidance
• Improved productivity
• Improved use of skills and experience
• Improved delivery of third-party services through the specification of ITIL
Control Objectives for Information
and Related Technology (COBIT)
The Need for IT Governance

Security Keeping
IT Running
Aligning Managing
IT with Complexity
Business

Regulatory
Value/Cost
Compliance

Organizations require a structured approach for managing these and other


challenges.

This will ensure that there are agreed objectives for IT, good management controls
in place and effective monitoring of performance to keep on track and avoid
unexpected outcomes.
COBIT

• COBIT is used in many companies to provide a framework for


governance and implementation of internal controls
• COBIT includes the essential business and IT process controls
and objectives needed to achieve corporate objectives
• COBIT is written at the management level and driven by
business requirements
• COBIT is aligned with other IT practices and standards but is more
complete than others
• COBIT is generally accepted as the internal IT control
framework
COBIT

• COBIT supports IT governance by providing a


framework to ensure that
• IT is aligned with the business
• IT enables the business and maximises benefits
• IT resources are used responsibly
• IT risks are managed appropriately

• Designed to support
• Executive and management boards
• Business and IT management
• Governance, assurance, control, security professionals
The COBIT framework was created with the main
characteristics:
• Business-focused
• Business goals and IT goals, COBIT’s information criteria,
COBIT’s IT resources
• Process-oriented
• Domains: Plan and Organise (PO), Acquire and
Implement (AI), Deliver and Support (DS), Monitor
and Evaluate (ME)
• Controls-based
• Process controls, Business and IT controls, IT general
controls and application controls
• Measurement-driven
• Maturity models

3
9
History of COBIT

• A framework and a knowledge base for managing IT


created by ISACA and the IT Governance Institute in
1994
• Former name of IT Governance Institute was the
Information Systems Audit and Control
Foundation (ISACF) – renamed in 2003

4
0
COBIT 4.1 – the core content

• Frameworks
• Organize IT Governance objectives and good practices by IT
domains and processes, and links them to business
requirements

• Control Objectives
• Provide a complete set of high-level requirements to be
considered by management for effective control of each
process
• Management Guidelines / Maturity Models
• Help assign responsibility, measure performance, and
benchmark and address gaps in capability

4
1
Interrelationships of
COBIT components
requirements information

derived
from

based
on

IT Governance Institute – COBIT 4.1 Executive Overview,


2007

4
2
The COBIT Cube
COBIT Framework

As a control and governance framework for IT, COBIT focuses on two key areas:
► Providing the information required to support business objectives and requirements
► Treating information as the result of the combined application of IT-related resources
that need to be managed by IT processes
Information Criteria
Effectiveness
IT Process Efficiency
Confidentiality
Integrity
Availability
Business Requirement Compliance
Reliability

Control Approach
IT Resources
IT Processes Applications
Domains
Consideration Information
Processes
• ……………………………
• …………………………… Activities Infrastructure
• ……………………..…….. People
COBIT Cube

The COBIT framework describes how IT processes deliver the information that the business
needs to achieve its objectives.
For controlling this delivery, COBIT provides three key components, each forming a
dimension of the COBIT cube.

Business Requirements for Information Criteria

IT Resources

IT Processes
COBIT Cube: IT Processes

► COBIT describes the IT life cycle with the help of four domains:
 Plan and Organise
 Acquire and Implement
 Deliver and Support
 Monitor and Evaluate
► Processes are series of activities with natural control breaks. There are 34 processes
across the four domains. These processes specify what the business needs to achieve its
objectives. The delivery of information is controlled through 34 IT processes.
► Activities areactions that are required to achieve measurable results. Moreover, activities
have life cycles and include many discrete tasks.
Information Criteria

Domains IT Resources
Processes
Activities
IT Processes
COBIT Cube: IT Domains

Plan and Organise (PO)


► Objectives:
 Formulating strategy and tactics
 Identifying how IT can best contribute to achieving business objectives
 Planning, communicating and managing the realisation of the strategic vision
 Implementing organisational and technological infrastructure
► Scope:
 Are IT and the business strategically aligned?
 Is the enterprise achieving optimum use of its resources?
 Does everyone in the organisation understand the IT objectives?
 Are IT risks understood and being managed?
 Is the quality of IT systems appropriate for business needs?

IT and Business
COBIT Cube: IT Domains (Cont.)

Let’s look at the COBIT process model, which consists of 34 IT processes defined within
the four IT domains.

Plan and Organise

PO1 Define a strategic IT plan.


PO2 Define the information architecture.
Plan and Acquire and PO3 Determine technological direction.
Organise Implement
PO4 Define the IT processes, organisation
IT Processes
and relationships.
PO5 Manage the IT investment.
PO6 Communicate management aims and
Deliver and Monitor and
Support Evaluate direction.
PO7 Manage IT human resources.
PO8 Manage quality.
PO9 Assess and manage IT risks.
PO10 Manage projects.
COBIT Cube: IT Domains (Cont.)

Acquire and Implement (AI)


► Objectives:

 Identifying, developing or acquiring, implementing, and integrating IT solutions


 Changes in and maintenance of existing systems
► Scope:

 Are new projects likely to deliver solutions that meet business needs?
 Are new projects likely to be delivered on time and within budget?
 Will the new systems work properly when implemented?
 Will changes be made without upsetting current business operations?

?
New Projects Organisation
COBIT Cube: IT Domains (Cont.)

Acquire and Implement

AI1 Identify automated solutions.


AI2 Acquire and maintain application
Plan and Acquire and software.
Organise Implement
AI3 Acquire and maintain technology
IT Processes
infrastructure.
AI4 Enable operation and use.
AI5 Procure IT resources.
Deliver and Monitor and
Support Evaluate AI6 Manage changes.
AI7 Install and accredit solutions and
changes.
COBIT Cube: IT Domains (Cont.)

Deliver and Support (DS)


► Objectives:

 The actual delivery of required services, including service delivery


 The management of security, continuity, data and operational facilities
 Service support for users
► Scope:

 Are IT services being delivered in line with business priorities?


 Are IT costs optimised?
 Is the workforce able to use IT systems productively and safely?
 Are adequate confidentiality, integrity and availability in place?

IT Services Business Priorities


COBIT Cube: IT Domains (Cont.)

Deliver and Support


DS1 Define and manage service levels.
DS2 Manage third-party services.
DS3 Manage performance and capacity.
DS4 Ensure continuous service. Plan and Acquire and
Organise Implement
DS5 Ensure systems security.
IT Processes
DS6 Identify and allocate costs.
DS7 Educate and train users.
DS8 Manage service desk and incidents.
Deliver and Monitor and
DS9 Manage the configuration. Support Evaluate
DS10 Manage problems.
DS11 Manage data.
DS12 Manage the physical environment.
DS13 Manage operations.
COBIT Cube: IT Domains (Cont.)

Monitor and Evaluate (ME)


► Objectives:

 Performance management
 Monitoring of internal control
 Regulatory compliance
 Governance
► Scope:

 Is IT’s performance measured to detect problems before it is too late?


 Does management ensure that internal controls are effective and efficient?
 Can IT performance be linked to business goals?
 Are risk, control, compliance and performance measured and reported?

IT Performance
COBIT Cube: IT Domains (Cont.)

Monitor and Evaluate Plan and Acquire and


Organise Implement
ME1 Monitor and evaluate IT performance.
IT Processes
ME2 Monitor and evaluate internal control.
ME3 Ensure compliance with external
requirements.
Deliver and Monitor and
ME4 Provide IT governance. Evaluate
Support
COBIT Cube: Information Criteria

► Tosatisfy business objectives, information needs to conform to specific control criteria,


which COBIT refers to as business requirements for information.
► Broadly, information criteria are based on the following requirements:
 Quality
 Fiduciary
 Security
Quality Requirements

Fiduciary Requirements

Security Requirements

Information Criteria

IT Resources
IT Processes
COBIT Cube: Information Criteria (Cont.)

Deals with information being relevant and pertinent to the business


Effectiveness process as well as being delivered in a timely, correct, consistent Quality Requirements
and usable manner Fiduciary Requirements
Security Requirements
Concerns the provision of information through the optimal
Efficiency
(most productive and economical) use of resources Information Criteria

Concerns the protection of sensitive information IT Resources


Confidentiality
from unauthorised disclosure IT Processes

Relates to the accuracy and completeness of information as


Integrity well as to its validity in accordance with business values
and expectations
Relates to information being available when required by the business process
Availability now and in the future. It also concerns the safeguarding of necessary resources
and associated capabilities.

Deals with complying with those laws, regulations and contractual arrangements to which the
Compliance business process is subject, i.e., externally imposed business criteria as well as internal policies

Relates to the provision of appropriate information for management to operate the entity and to
Reliability
exercise its fiduciary and governance responsibilities
COBIT Cube: IT Resources

► IT processes manage IT resources to generate, deliver and store the information that the
organisation needs to achieve its objectives.
► The IT resources identified in COBIT are defined as:
 Applications are automated user systems and manual procedures that process
information.
 Information is data that are input, processed and output by information systems, in
whatever form used by the business.
 Infrastructure includes the technology and facilities, such as hardware, operating
systems and networking, that enable the processing of applications.
 People are the personnel required to plan, organise, acquire, implement, deliver,
support, monitor and evaluate information systems and services. They may be
internal, outsourced or contracted, as required.
Information Criteria
Applications
Information
Infrastructure
People
IT Processes
IT Resources
COBIT Framework
COBIT Maturity Model

• Generic Maturity Model


• 0 - (Non-existent) management processes are not applied at
all
• 1 – (Initial/Ad Hoc) processes are ad hoc and disorganised
• 2 – (Repeatable but intuitive) processes follow a regular
pattern
• 3 – (Defined Process) processes are documented and
communicated
• 4 – (Managed and Measurable) processes are monitored and
measured
• 5 – (Optimised) good practices are followed and automated

59

You might also like