An integrated risk measurement and optimization model for trustworthy software process management

被引:31
|
作者
Li, Jianping [1 ]
Li, Minglu [1 ,2 ]
Wu, Dengsheng [1 ,3 ]
Song, Hao [1 ,3 ]
机构
[1] Chinese Acad Sci, Inst Policy & Management, Beijing 100190, Peoples R China
[2] Natl Nat Sci Fdn China, Bur Planning, Beijing 100085, Peoples R China
[3] Chinese Acad Sci, Grad Univ, Beijing 100039, Peoples R China
关键词
Risk integration; Trustworthy software; Process risk measurement; Risk control optimization; Bayesian network learning; FUZZY-SET THEORY; BAYESIAN NETWORKS; AGGREGATIVE RISK; EVALUATE;
D O I
10.1016/j.ins.2011.09.040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The growing demand for higher trustworthiness of software poses an unprecedented challenge to the software industry. Risk management is the important part for high quality software development processes. However, under the constraints of project cost and duration, it is very difficult to establish the budget for risk management. To integrate efficient risk management and pure software process is the goal of this paper. We propose a software process model with risk management and cost control modules to help improve software process risk management. Furthermore, based on this process model, a measurement model that includes process risk and software trustworthiness metrics is presented. Through risk management effectiveness calculation methods and risk transfer assumptions, a software process risk optimization model is proposed. This model can be used to derive an optimized risk management scheme for the process of trustworthy software development, with constraints of process cost and duration. Simulation cases are then analyzed by this model framework. The results show that risk management is critical to enhance trustworthiness but risk management is an effective complement, rather than the most fundamental process, to enhance the trustworthiness of software. Software developers should adopt appropriate and optimal strategies about risk management inputs, especially in lower CMMI level companies. (C) 2011 Elsevier Inc. All rights reserved.
引用
收藏
页码:47 / 60
页数:14
相关论文
共 50 条
  • [1] A Multi-criteria Risk Optimization Model for Trustworthy Software Process Management
    Li, Jianping
    Li, Minglu
    Song, Hao
    Wu, Dengsheng
    CUTTING-EDGE RESEARCH TOPICS ON MULTIPLE CRITERIA DECISION MAKING, PROCEEDINGS, 2009, 35 : 535 - 539
  • [2] The Study of Trustworthy Software Process Improvement Model
    Yu, Benhai
    Wang, Qing
    Yang, Ye
    NSWCTC 2009: INTERNATIONAL CONFERENCE ON NETWORKS SECURITY, WIRELESS COMMUNICATIONS AND TRUSTED COMPUTING, VOL 2, PROCEEDINGS, 2009, : 315 - 318
  • [3] Software risk management:: a process model and a tool
    Kirner, Teren G.
    Goncalves, Lourdes E.
    SOFTWARE ENGINEERING TECHNIQUES: DESIGN FOR QUALITY, 2006, 227 : 149 - 154
  • [4] A Measurement Model for Trustworthy Software Based on Trusted Evidences
    Li, Yan
    Chen, Yixiang
    2016 INTERNATIONAL SYMPOSIUM ON SYSTEM AND SOFTWARE RELIABILITY (ISSSR), 2016, : 20 - 24
  • [5] A Software Development Process Model Integrated to a Performance Measurement System
    Baptista, G. L.
    Vanalle, R. M.
    Salles, J. A. A.
    IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (03) : 739 - 745
  • [6] A Petri Net based Model for Trustworthy Software Process Composition
    Zhang, Xuan
    Li, Tong
    Xie, Zhong-Wen
    Dai, Fei
    Liu, Jin-Zhuo
    2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW), 2013, : 108 - 114
  • [7] Software Process Risk Measurement Model based on Bayesian Network
    Zhang, Zijian
    Rao, Guozheng
    Cao, Jing
    Zhang, Li
    2014 5TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS), 2014, : 41 - 44
  • [8] A process model for integrated IT governance, risk, and compliance management
    Racz, Nicolas
    Weippl, Edgar
    Seufert, Andreas
    DATABASES AND INFORMATION SYSTEMS, 2010, : 155 - 169
  • [9] A Bayesian Networks-Based Risk Identification Approach for Software Process Risk: The Context of Chinese Trustworthy Software
    Li, Jianping
    Li, Minglu
    Wu, Dengsheng
    Dai, Qianzhi
    Song, Hao
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY & DECISION MAKING, 2016, 15 (06) : 1391 - 1412
  • [10] The Design and Application of Software Measurement and Evaluation Model Based on Process Management
    Li, WenXing
    Gu, ZiYi
    Yang, XiangLin
    Tian, Fang
    2021 2ND INTERNATIONAL CONFERENCE ON BIG DATA & ARTIFICIAL INTELLIGENCE & SOFTWARE ENGINEERING (ICBASE 2021), 2021, : 649 - 653