{"title":"Software development process standards: challenges for process assurance","authors":"R. Smith","doi":"10.1109/SESS.1997.595967","DOIUrl":"https://doi.org/10.1109/SESS.1997.595967","url":null,"abstract":"During 1992-94 the Cellular Infrastructure Group (CIG) organization of Motorola implemented a set of common software development process specifications using the IEEE Std 1074 as a process architecture guideline and the SEI Capability Maturity Model (CMM) for process requirements. In late 1993 the Software Quality Assurance group implemented a process assurance program of auditing against these process specifications for process compliance and process improvement. The IEEE Std 1028 was chosen as the basic standard for development of the audit program. In June 1996, the Cellular Infrastructure Group became ISO 9001 certified. This paper discusses challenges and lessons learned from working with these three major quality system and software development process standards from a process assurance perspective.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"12 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132340230","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"A process standard for system security engineering: development experiences and pilot results","authors":"R. Hefner","doi":"10.1109/SESS.1997.595974","DOIUrl":"https://doi.org/10.1109/SESS.1997.595974","url":null,"abstract":"The Systems Security Engineering Capability Maturity Model/sup SM/ (SSE-CMM/sup SM/) describes the essential characteristics of an organization's security engineering process. The standard was developed by a unique government-industry consortium of leading security providers and acquirers. This paper summarizes the model and presents lessons learned in the model's development and from pilot appraisals.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"11 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115737981","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Functional safety of safety-related systems: the influence of IEC 1508 and developments in conformity assessment schemes on business drivers","authors":"S. Nunns","doi":"10.1109/SESS.1997.595922","DOIUrl":"https://doi.org/10.1109/SESS.1997.595922","url":null,"abstract":"Industry faces many challenges and unremitting pressures within increasingly competitive markets. There are increasing regulatory demands to address risks to safety and the environment in a world where public concern for safety is rising. A consistent approach to the use of new technology and standards is essential to avoid the potential confusion of different approaches to safety being followed by different application sectors. Programmable electronics is a technology that, if properly used in the implementation of safety-related systems supported by internationally acceptable standards with supporting conformity assessment schemes, offers significant benefits to industry in meeting its challenges, whilst maintaining and improving safety. This paper presents a range of current technical issues and business drivers within manufacturing industry, and discusses the relevance and importance of the emerging international standard IEC 1508 in assisting industry in satisfying their evolving business drivers and continuous organisational restructuring. A UK Government-sponsored research project called FRESCO (FRamework for the Evaluation of Safety-Critical Objects) has developed a conformity assessment scheme from process industry requirements based on IEC 1508. This paper outlines the organisational framework and assessment methodology developed by the FRESCO project.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"22 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"114712166","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Computer Related Standards And Safety Workshop Proceedings","authors":"V. Stavridou","doi":"10.1109/SESS.1997.595978","DOIUrl":"https://doi.org/10.1109/SESS.1997.595978","url":null,"abstract":"This is an outline proceedings of the ISESS 97 workshop on computer related standards and safety. It outlines the motivation for organising the workshop and includes a selection of workshop presentation abstracts.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"604 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116368455","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Viewpoints on improving the standards making process: document factory or consensus management?","authors":"Luke Emmet, Robin Bloomfield Adelard","doi":"10.1109/SESS.1997.595972","DOIUrl":"https://doi.org/10.1109/SESS.1997.595972","url":null,"abstract":"Emerging standards and guidelines need to be timely and reflect the requirements of the industrial sector they are designed to support. However, often, the delay between the identification of a need for a standard and its eventual release is too long. There is a need for increased understanding of the sources of delay and deadlock within the standards process. In this paper we describe an application of PERE (Process Evaluation in Requirements Engineering) to the standards process. PERE provides an integrated process analysis that identifies improvement opportunities by considering process weaknesses and protections from both mechanistic and human factors viewpoints. The resulting analysis identified both classical resource allocation problems and also specific problems concerning the construction and management of consensus within a typical standards making body. A number of process improvement opportunities are identified that could be implemented to improve the standards process. We conclude that consensus problems are the real barrier to timely standards production. Ironically the present trend for more distributed working and electronic support (via e-mail etc.) may make the document factory aspect of standards production more efficient at the expense of consensus building.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"50 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126314752","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Framework for computer based safety-related systems: overview of draft international standard IEC 1508","authors":"R. Bell","doi":"10.1109/SESS.1997.596030","DOIUrl":"https://doi.org/10.1109/SESS.1997.596030","url":null,"abstract":"This article provides an overview of the proposed International Electrotechnical Commission (IEC) standard (IEC 1508) entitled \"Functional safety of electrical/electronic/programmable electronic safety-related systems\" which sets out a generic approach for all Safety Lifecycle activities for electrical/electronic/programmable electronic systems (E/E/PESs) that are used to perform safety functions. The emergence of this international standard should be a major step towards the adoption of a more rational and consistent technical policy for all electrically based safety-related systems. A major objective is to facilitate the development of application sector standards. The article also considers priorities for the future if both the safety and economic benefits are to be fully realised from the adoption of this proposed international standard.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130727337","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Results of the IEEE survey of software engineering standards users","authors":"S. Land","doi":"10.1109/SESS.1997.595987","DOIUrl":"https://doi.org/10.1109/SESS.1997.595987","url":null,"abstract":"This survey was initiated by the Software Engineering Standards Subcommittee (SESC) at a steering committee meeting held in conjunction with the Forum on Software Engineering Standards Issues. Individuals responsible for project process definition and documentation, for corporate process definition and documentation, and for compliance assessments bring different interpretations to the same software engineering standard. These users of software standards employ the standards in different ways. The Software Engineering Standards Users Survey is an attempt by SESC to take a market snapshot of software standards implementation and report the results to those responsible for IEEE standards creation and maintenance. This paper is a report of the survey results.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"45 02","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132123845","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Computer Related Standards And Safety","authors":"V. Stavridou","doi":"10.1109/SESS.1997.595976","DOIUrl":"https://doi.org/10.1109/SESS.1997.595976","url":null,"abstract":"","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"53 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"133781876","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Y. Wang, I. Court, M. Ross, G. Staples, G. King, A. Dorling
{"title":"Quantitative analysis of compatibility and correlation of the current SPA/SPI models","authors":"Y. Wang, I. Court, M. Ross, G. Staples, G. King, A. Dorling","doi":"10.1109/SESS.1997.595564","DOIUrl":"https://doi.org/10.1109/SESS.1997.595564","url":null,"abstract":"It is a fundamental requirement to quantitatively analyze the compatibility and correlation between the current models for software process assessment (SPA) and improvement (SPI). The compatibility and correlation of SPA/SPI models (e.g., SPICE, CMM, ISO 9000, BOOTSTRAP and SPRM) are formally and quantitatively analyzed and contrasted in this paper. First, formal definitions of the compatibility and correlation between the models are introduced. Then the relational properties are mutually analyzed from every view point of each of the five models to the others. The objective analysis results provided are useful not only for theoretical research in software engineering, but also for practitioners in the software industry.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"34 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"133813690","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"A survey to determine federal agency needs for a role-based access control security product","authors":"C. Smith","doi":"10.1109/SESS.1997.595975","DOIUrl":"https://doi.org/10.1109/SESS.1997.595975","url":null,"abstract":"This paper is an overview of a study done for the National Institute of Standards and Technology (NIST) to determine what potential market there is for a role-based access control (RBAC) product. Thirty security managers from 27 large civil federal organizations were interviewed using a six-page questionnaire. Their security needs were identified and it was concluded that these organizations desired an RBAC product to complement their mandatory and discretionary access control products. The results of the main reference study (Smith et al., 1996) will be used by NIST personnel as an input to the formulation of standards for future RBAC products.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"129043273","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}