LOT # 4
Software Quality Audit and Certification
Training Plan
PLANET SA - INTRAKOM - FINMECCANICA - CCS
1. Structure of the Course
The purpose of this training plan outline is to sketch out the basic elements and structure of training to be provided to personnel from organisations selected to become Information Technology Nodes (ITNs) in the area of Software Quality Assurance, Audit and Certification.
It is recognised that prospective receivers of this training in Third Mediterranean Countries exhibit a wide variety of experiences, technical competence and potential for their own markets. While on average, Third Mediterranean Countries are at an intermediate development level in industrial and information technology areas, there are countries closer to the advanced industrialised world and others closer to underdeveloped countries. Therefore, the training material will be flexibly structured to enable adaptation to each individual ITN level of maturity and market potential. Trainers will adjust the pace and focus of the presentation and handling of delivered material, so to make the course best suitable for their audience and the needs of the local market.
Since the ITNs are going to operate as experts and innovation carriers in the local market, they must:
The role of the ITNs in the case of S/W Qual. Audit, Certification and SPI is significant because these techniques:
The training course will focus in the development of Business Intelligence/Capability at the ITNs, by assisting in:
Preparation: Before the course begins, the trainees will have the chance to take some preparatory actions, the essential part being the answering of the specially prepared questionnaire, which indicates their background and interest in the ITN area of specialisation and prospects. Another questionnaire should be filled by 1 person from each participant organisation, to identify the organisation’s awareness, involvement and interest in SW Quality issues. They are also encouraged to reflect upon the special area of SW quality in relation to their country’s circumstances and, if possible have available examples, experiences, any relevant surveys and statistics and any other information that might be useful during the course, especially the action planning. When at the beginning of the course they will present themselves, they should also identify any concrete information they may have availabe, so that the trainer and other trainees will know and take it into account in time.
The approach taken seeks to address the general characteristics and needs that are common to a great extent in Third Mediterranean Countries, concerning the software quality area. Thus, it provides wide coverage on several relevant subjects and experiences from the EU and other advanced markets. The course is structured in 5 Modules in a manner that allows for a flexible introduction to Software Quality Issues to match the trainees’ interests and needs. While details about each module is given in section 2, Presentation of the Module, an explanation about the rationale underlying each modules, follows here. The division in modules does not adhere to a formally strict categorisation, since this may not be very fruitful with relatively inexperienced audiences and may confuse them. Instead a pragmatic approach is followed, where essential issues are explained and discussed and an open strategy is adopted to introduce elements of best practices, sometimes originating from different sources, in a way best fitting the needs of a developing country, economy and market. A more formal approach could be part of a more specialised training, maybe as part of actions to be planned and undertaken by an ITN.
In the First Module, we compiled some introductory information on the subject of quality in general and in particular software quality, to allow a common understanding of problems related to software development and use as well as the significance of some common approaches to manage and solve these problems. This should link to experiences of trainees both in the software field as well as other areas where similar problems and approaches are also found
In the Second Module, the focus shifts to the issue of building a Quality System for Software, based on ISO 9001 (and associated standards), and going through the process of third-party certification. The standards that apply are introduced and explained, the certification as well as accreditation schemes presented and their significance emphasized. This area is considered of special importance as a foundation to building a stable infastructure ensuring good quality, but also capable of being used as a springboard for further improvements. It is expected that for many audiences in the Third Mediterranean countries it will address their immediate needs and they should be encouraged to take this relatively well-paved route to start in their long journey towards quality for software.
In the Third Module, there is an overview of other, alternative/complementary approaches to SW quality, mainly based on process assessment and improvement models (CMM, SPICE etc.). These offer the potential for a more ambitious advance in areas particularly important and relevant to Software (but not necessarily limited by it.). Such models should be interesting to know and use when planning long-term improvements as well as building maturity for software development in a staged/evolutionary manner. It could provide valuable complementary material for trainees and countries where ISO and certification will be the priority strategy. It should also allow more mature and demanding users to path their way ahead in a manner that is increasingly recognised as important for international markets and high-end applications.
The Fourth Module, includes presentation of several other techniques and Best Practices that have already proven or promise improvements in particular aspects of software development. Issues cover a wide range including process related and product related standards and techniques, experiences and organisations in Europe active in Sofware Quality, the role of the EU and the Commission (ESPRIT, ESSI) etc. Case studies could be presented and discussed here (when not directly related to one of the issues covered in previous modules, in which case they should be handled there).
Throughout the presentation of the first 4 modules, preparation related to the 5th module will begin, by briefly introducing the issue of Action Plan and identifying/disc/summarising relevant issues from each module’s material and from trainee experiences and needs.
In the Fifth Module, the issue of ACTION PLAN Preparation which is critical to the operation of the prospective ITNs will be presented to some extent and discussed extensively in relation to the material presented in previous modules. A practical exercise for preparing such a plan, should allow trainees with the help of the trainer to better grasp the important issues and start exploring/planning possible activities that an ITN embark in within their respective countries. The approach is quite generic and similar to the one taken in other ITN areas (e.g. WWW and Multimedia), but special attention to peculiarities of SW quality as well as local concerns should be used as guiding criteria when selecting and planning appropriate actions
After a general training session introducing the issues of software quality assurance, audit and certification, emphasis is put on ISO 9001 application in software development. Additionally, more dynamic and specialised models like the CMM and SPICE are presented, followed by several other best practices and approaches that complement the potential for improving software quality in a practical manner.
The training course on “Software Quality Audit and Certification” will be structured along the Modules presented in the following table:
|
Module |
Days |
Hours |
|
1. Software Quality Overview |
0.5 |
3 |
|
2. ISO 9001 applied to Software Quality |
1.0 |
6 |
|
3. Evolutionary Models for Software Quality |
0.5 |
3 |
|
4. Other Best Practices for Software Quality |
0.5 |
3 |
|
5. Action Plans |
1.5 |
9 |
|
TOTAL |
4 |
24 |
This programme can be changed according to the specific national needs of ITNs personnel. For example, less time can be dedicated to “Module 2” and more to “Module 3” if there is such a willingness among the participants.
In total, four days (or 24 hours) of training are planned for each training intervention. There will be two 3-hour sessions daily. The morning session (ms) from 9 am to 12 am and the afternoon session (as) from 2 pm to 5 pm.
The following table presents the time scheduling of training activities:
|
1st day |
2nd day |
3rd day |
4th day |
|||||
|
Module |
ms |
as |
ms |
as |
ms |
as |
ms |
as |
|
1. Software Quality Overview |
||||||||
|
2. ISO 9001 applied to Software Quality |
||||||||
|
3. Evolutionary Models for Software Quality |
||||||||
|
4. Other Best Practices for Software Quality |
||||||||
|
5. Action Plans |
||||||||
The schedule indicated includes 30 min. of discussion/preparation on the Action Plan issue (i.e. Module 5), at the end of each session (3-hr either morning or afternoon) after covering relevant material of Modules 1-4. The slack (30 min.) in each session for covering Modules 1-4, in total 5x30=150min., is expected to be covered when reviewing and discussing the SW quality issues and techniques presented throughout the last 1.5 days, where training will concentrate on Action Plan preparation. The focus areas for training are thus displayed with darker shading than the secondary ones (which are in lighter gray).
With respect to the case studies provided in the material, their number is much higher than what could be possible to present and discuss during the course. The intent is for the trainer to select among them a few, taking into account the particular background (by using the Mapping.xls table provided titled Case Study versus Types of Target Audiences) and expressed needs of the trainees and the respective country. These should serve 3 purposes:
Of particular importance is the case study material provided from the ESPITI programme. For the prospective ITNs in the area of SW quality, the experience gained by the ESPITI programme which had essentially similar objectives for the Lot 4 ones is of critical significance and should be particularly addressed and evaluated during the Action Plan preparation.. For this purpose, relevant ESPITI material (both User Survey Analysis and Final Report) will be distributed beforehand and discussed in the event to draw useful hints for Lot 4.
The ESPITI information and experience will be approached in a careful manner. It is understood that it addresses the issues important for prospective Med ITNs regarding Software Quality and Certification, but one should take into account that in most cases the level of development of 3rd Med countries is less than in EU countries in general and in SW industry in particular. Examples of less developed european countries are of particular importance and relevance, but in certain cases, the experience in more developed countries is also of high importance to trainees. They should be part in evaluation ESPITI’s relevance to their circumstances, as well as take it into account in the preparation of an Action Plan for the ITN.
Other experiences besides the ESPITI can be also useful, like the emerging SPIRE case studies- reports, as well as the SPI for SMEs Guide that is being published by this consortium (ordered but not received yet at the time of the writing). For this purpose a reference to such material has been included in the Case Studies material so that trainees will have the chance to search and familiarise themselves with it. Another source of useful material is the dissemination CD-ROM from the SMILE programme, addressing exactly issues relevant to the training and prospective ITN actions, i.e. SW Process Improvement.
Material to be distributed before
Trainee's Material
Trainer’s material
Deliverables
In the following pages there is a presentation of each of the above Modules together with a short description of the objectives and technical approach to be followed.
2. Presentation of the Modules
Module 1: Software Quality Overview
Objectives
The first module’s objectives are to:
Content
Duratio
3 hours
Presentation material
Trainer’s material
Trainees’ material
Instructions to the trainer/Work to be done during the session
The presentation should be rather informal, without going into deep technical detail. Through this module, the instructor will actively seek feedback (complementing the questionnaire that the trainees must have returned, via short exercises, questions etc.) to get to know the audience better and establish good relationship and confidence. The actual module duration will depend on the maturity / needs of the individual ITNs.
The trainer should keep notes about the exact status and background of various trainees, any special interests and expectations etc., in order to tailor the remainder of the presentation to best suit their particular needs.
The general idea about an Action Plan should be discussed to set up the context for detailed coverage at the last module. To this effect, an exploratory discussion about the local market conditions should be performed, in a relaxed manner, trying to bring forward interesting points and to build up confidence in trainees as well as better understanding for the trainer.
Indicative Schedule
Introduction: 30min.
Lecture: 1hr 45min
Discussion: 45min.
Deliverables expected
Discussion chapter within the country report
Module 2: ISO 9001 applied to Software Quality
Objectives
This module’s objectives are to:
Content
· The main features of ISO 9001 and ISO 9000-3 standards
· Quality audit and software (also introduce ISO 10011)
· Trends and driving forces for adopting ISO 9001 in software development
· The programme to introduce ISO 9001 and obtain certification: steps and milestones
· Case studies from the European industry on ISO 9001 introduction and certification (ESPITI, CSE, INTRACOM, etc.)
· Benefits and drawbacks from ISO9001 introduction: industrial experiences
· The accreditation scheme, national and international normalisation efforts: TickIT, ITQS etc.
· Discussion on status of ISO 9001 introduction in Third Mediterranean Countries
Duration
6 hours
Presentation material
Trainer’s material
Trainees’ material
Instructions to the trainer/Work to be done during the session
Depending on trainees background, a varying degree of explanation on the standard(s) will be given. Some exercises will be presented to deepen understanding and receive feedback (e.g. handle a hypothetical certification scenario; an audit scenario etc.). Experiences from the trainee organisations or their national markets will be discussed.
The module duration will depend on the maturity / needs of the individual ITNs. In case where there is some experience in place, a focus on consolidating such experiences together with european and international ones should be followed. Possibly, the duration can be shortened, in order to ensure more time for next modules (3-4).
If no significant experience is available in trainees, then a more rudimentary and detailed presentation and discussion should be followed. In such a case, the 6hours time should be a minimum, if necessary expanded by cutting next modules (3-4). The ISO 9000-3 (which includes ISO 9001 text) should be thoroughly analysed.
Investigate the possibility to distribute and then retreive copies of ISO 9000-3 to trainees (to ensure property rights), in case the ITN does not posses a licenced copy.
In the end, a discussion about possible scheme for ISO registration in the local market should be performed and suggestions and opinions noted (to be used in the Action Plan also).
Indicative Schedule
Introduction to ISO 9000 series and ISO 9001: 1hr
Analysis of ISO 9000-3 (1997): 2 hrs
Presentation of Audit and Certification issues: 2hrs
Discussion: 1hr.
Deliverables expected
Discussion chapter within the country report
Module 3: Evolutionary Models for Software Quality Improvement
Objectives
This module aims to:
Content
· Historical evolution of software capability assessment and models
· Overview of the basic models: CMM, SPICE and BOOTSTRAP
· Comparison between ISO 9001 - CMM - SPICE
· Orientation on how to select the appropriate model for an organisation
· The capability assessment approach and rational (as opposed to quality audit)
· Other derivative models (People CMM, System Engineering CMM etc.)
· Case studies from assessments and software process improvement programmes based on CMM
Duration
3 hours
Presentation material
Trainer’s material
Trainees’ material
Instructions to the trainer/Work to be done during the session
The module duration will depend on the maturity / needs of the individual ITNs.
For less mature organisations and markets, it is generally recognised that the ISO 9001 is the primary approach. In such cases the emphasis is on module 2, even allowing for some shrinking of module 3 (say, 2,5 hrs).
Otherwise, the evolutionary models merit greater coverage. When there is evident interest, the allocated time could rise to, say 4 hrs or evem more (by reducing module 2 allocated time).
In any case, emphasis will be put on comparisons and discussion of practical scenarios, including 1-2 familiarisation exercises.
It is important to ensure that access to WWW pages be effected in the classroom andf the trainees can work also their own way on line. If this is impossible, some additional material (e.g. some CMM printout) could be helpful.
In the end, a discussion about the relevance and importance of the material for the local market should be effected, as well as explore some possible scenaria for applying these techniques. Notes should be taken to help in the Action Plan module.
Indicative Schedule
Introduction to CMM and other evolutinary models: 30min
Analysis of SW-CMM: 1 hr
Overview of other models: 45min
Discussion: 45min.
Deliverables expected
Discussion chapter within the country report
Module 4: Other Best Practices for Software Quality Improvements
Objectives
This module aims to:
Content
· Other relevant standards: ISO 12207, ISO 9126, ISO 14598
· Application of Metrics in Industry (ami method)
· Best practices in Software Inspections (Fagan’s approach, Gilb’s approach)
· The Personal Software Process (PSP) and related experiences in Europe
· ESSI : The European Systems and Software Initiative
· PIEs, ESPINODEs and ESBNETS
· Case studies from Europe and the rest of the world
· International co-operation, consulting services and dissemination related to software quality
· Conclusion and discussion on software quality issues
Duration
3 hours
Presentation material
Trainer’s material
Trainees’ material
Instructions to the trainer/Work to be done during the session
The training approach in this module will heavily depend on the particular background of trainees and their needs. Case studies and best practices will be available, allowing a selection each time, best suited to the needs of an ITN organisation. The module duration will also depend on the maturity / needs of the individual ITNs.
The duration, if there is interest and maturity can be extended to, say, 4 hrs (by trimming the mod 2).
The techniques that are presented here could become part of a set of services (training, consulting, linking to international IT experts), to be provided to the local community.
During presentation of ESSI and other CEC activities, WWW access is preferable.
It is important to give a judgment about the general value of such techniques, especially to compare them with approaches in mod. 2 and 3 and to explore how they can become part of an integrated SPI effort.
A discussion at the end should explore such possibilities for the local market.
Indicative Schedule
Presentation of various techniques: 1hr 45min
ESSI and other CEC activities presentation: 30 min.
Discussion: 45min.
Deliverables expected
Discussion chapter within the country report
Module 5: Action Plan Preparation
Objective
The objective of this Module is to provide training to the representatives of organisations in the IT Node on:
The presentation of examples, cases and best practices during the previous Modules will provide the basis for selecting the most appropriate actions to be developed in Module 5.
Content
Firstly the representatives of the organizations will be requested to establish a Memorandum of Association which is deemed significant prior to commencing work as IT Node. .
Related guidelines and a model will be presented.
Thereafter the following issues will be addressed:
At the end the trainees will be briefly introduced to the follow up and supporting actions provided by the trainer for a 12 month period.
Selection of Actions
By describing an Action plan for an IT Node as “A programme of strategic actions, which complement one another, have well defined goals, and which are realised via the co-operative effort of the members of the IT Node consortium”, the next step will be to indicate and organise a series of activities - projects that should be included into the outline of the IT Node Action Plan:
Sub-activities could include:
The selection of these themes has been based on the case studies and best practices presented in previous Modules. In this context, trainees are going to have beforehand an illustration in real terms of the value and importance of their potential activities in these fields.
Consideration of Action plans implementation in fine detail
Preparation of Action Plans (analytical design and organisation of activities) for the services proposed to be selected and provided by the IT Nodes. The action plans to be prepared will contain an analytical list of activities together with the necessary “tools” required (e.g. structured and semi-structured questionnaires etc.).
There will also be an analytical presentation of the significance of the selected Action Plans for the SW Quality Audit and Certification sector together with the identification of the specific role that the agents of the sector have in each of them.
Monitoring Mechanisms - Evaluation and Redesign
Presentation of the major evaluation techniques and indicators to be used for monitoring and evaluations of actions.
The importance of each technique and indicator will be explained and the methodology of feeding this information into the design cycle for future events will be presented.
An indicative list of such indicators is given below:
Technical Approach
The Module will be delivered in three major parts: