Can you describe what a "software factory" is?
The “Software Factory” is something that is common with larger, multi-departmental organizations where IT is serving a broad array of constituents. It may exist in any type of environment, but this is the most common scenario I’ve seen.
Factories are often focused around the development of foundational technologies – objects, web services, or modules that serve multiple applications and can be reused by the various constituent groups. One very interesting model segments the IT development organization into two segments; a “factory” that develops and certifies these foundational modules, and “customer facing” developers that use the components, as well as additional html/java/php etc. to assemble end-user applications.
In this type of model, the factory has little or no customer contact, but serves the other segments of the IT organization. There are also examples of the Software Factory within the big consulting firms – the earliest of which was Ernst & Young’s “Advanced Development Centers” that used a variety of acceleration techniques to serve clients directly. Accenture has followed up with a similar concept. I’m not sure these a true “factories” as they develop custom software that are almost all one-offs, but they use that expression nevertheless.
In my view, the value of a factory is their ability to focus on churning out a set of proven, well developed components that benefit the rest of the organization. You’re experience may be different, but that’s what I’ve seen.
www.broadswordsolutions.com
Got questions? Get answers! Thoughts from an Agile CMMI Lead Appraiser by Jeff Dalton.
Tuesday, August 7, 2007
Some REQM Practices seem complex if done properly. Can you provide some practicle examples?
Can you explain following two REQM practices with some practical examples?
- Identify inconsistencies between the project plans and work products and the requirements
- Establish and maintain an organizational policy for planning and performing the requirements management process
Sure! Practical examples is what this 'blog is all about.
I'll start with the last first. Your question appears to be about REQM.GP2.1 "Establish an Organizational Policy." Let's start with a question: "what's an organizational policy?" According to the CMMI, an OP is: "A guiding principle typically established by senior management that is adopted by an organization to influence and determine decisions." To put it more simply, it's management's expectations for performing a process.
My advice to you here is to keep it simple and not use your policy to describe the process. You will probably be going through an exercise to define a Requirements Management process, so there is no need to be redundant within the policy. A simple documented policy that sets management's expectations is sufficient.
"All employees are required to read, understand, and follow the REQM process as defined in the process guide."
Of course, there needs to be a process guide for this to be valid, and a valid REQM process as well to point to.
The second part of the practice refers to "maintaining" the policy. This implies a cyclical review of all policies, and updating or changing it as appropriate (keeping it all under CM of course!)
You first question refers to REQM SP1.5 Identify Inconsistencies Between Project Work and Requirements. What could this possibly mean, and whose job is it?
To begin with, we can think about this practice as part of PMC because it is clearly a project management activity. It involves keeping up to date on all of the latest requirements changes, and ensuring that the tasks being performed by the project team reflects the latest approved requirements set.
Imagine a large scale project with dozens of developers who are each assigned a set of requirements or features to implement. They may not be involved in all of the meetings and approvals for new or changed requirements. How does the PM ensure that, as requirements change, the developers are working on the latest and greatest requirements set? How do we avoid having them work on the old requirements, or when the requirements have changed to something different?
The place to manage this, IMHO, is in the traceability matrix. This tool can quickly identify who is working on what code and gives the PM a way to rapidly determine what work needs to be halted, modified, or added.
www.broadswordsolutions.com
- Identify inconsistencies between the project plans and work products and the requirements
- Establish and maintain an organizational policy for planning and performing the requirements management process
Sure! Practical examples is what this 'blog is all about.
I'll start with the last first. Your question appears to be about REQM.GP2.1 "Establish an Organizational Policy." Let's start with a question: "what's an organizational policy?" According to the CMMI, an OP is: "A guiding principle typically established by senior management that is adopted by an organization to influence and determine decisions." To put it more simply, it's management's expectations for performing a process.
My advice to you here is to keep it simple and not use your policy to describe the process. You will probably be going through an exercise to define a Requirements Management process, so there is no need to be redundant within the policy. A simple documented policy that sets management's expectations is sufficient.
"All employees are required to read, understand, and follow the REQM process as defined in the process guide."
Of course, there needs to be a process guide for this to be valid, and a valid REQM process as well to point to.
The second part of the practice refers to "maintaining" the policy. This implies a cyclical review of all policies, and updating or changing it as appropriate (keeping it all under CM of course!)
You first question refers to REQM SP1.5 Identify Inconsistencies Between Project Work and Requirements. What could this possibly mean, and whose job is it?
To begin with, we can think about this practice as part of PMC because it is clearly a project management activity. It involves keeping up to date on all of the latest requirements changes, and ensuring that the tasks being performed by the project team reflects the latest approved requirements set.
Imagine a large scale project with dozens of developers who are each assigned a set of requirements or features to implement. They may not be involved in all of the meetings and approvals for new or changed requirements. How does the PM ensure that, as requirements change, the developers are working on the latest and greatest requirements set? How do we avoid having them work on the old requirements, or when the requirements have changed to something different?
The place to manage this, IMHO, is in the traceability matrix. This tool can quickly identify who is working on what code and gives the PM a way to rapidly determine what work needs to be halted, modified, or added.
www.broadswordsolutions.com
Thursday, July 19, 2007
Could you imagine a CMMI-compatible ERP?
Can you imagine a CMMI-compatible ERPs? It would be, indeed, a kind of “Big Brother” system.
I think you answered the question already. I could imagine it, but I sure wouldn't recommend it!
If I understand your question, your asking if a system that globally controls practitioner's work so that they were "CMMI-Compatible" would be a good idea.
There are several products on the market the purport to deliver CMMI compliance if only the developers would just fill out the forms and use the system. These products try to tightly control the environment so that developers CAN'T go any other route. Believe it or not, Microsoft claims to have such a system (don't get me started . . .). Compuware has one also.
I guess I would have to say that anyone who advocates this type of approach may understand workflow and military efficiency, but probably doesn't appreciate the creative process used to develop software. As I've said many times, software development is not linear and cannot follow a linear process succesfully. The "big brother" approach defeats the purpose of improving process performance and probably won't result in accelerated development, reduced defects, and better retention of employees- the three biggest reasons I believe the CMMI is valuable.
The CMMI is not about filling out forms - it's about increasing productivity through the elimination of non-value added work, improving project visibility, and using fact-based data to make sound business decisions. This is something that I appreciate more and more the older and more experienced I get.
http://www.broadswordsolutions.com/
I think you answered the question already. I could imagine it, but I sure wouldn't recommend it!
If I understand your question, your asking if a system that globally controls practitioner's work so that they were "CMMI-Compatible" would be a good idea.
There are several products on the market the purport to deliver CMMI compliance if only the developers would just fill out the forms and use the system. These products try to tightly control the environment so that developers CAN'T go any other route. Believe it or not, Microsoft claims to have such a system (don't get me started . . .). Compuware has one also.
I guess I would have to say that anyone who advocates this type of approach may understand workflow and military efficiency, but probably doesn't appreciate the creative process used to develop software. As I've said many times, software development is not linear and cannot follow a linear process succesfully. The "big brother" approach defeats the purpose of improving process performance and probably won't result in accelerated development, reduced defects, and better retention of employees- the three biggest reasons I believe the CMMI is valuable.
The CMMI is not about filling out forms - it's about increasing productivity through the elimination of non-value added work, improving project visibility, and using fact-based data to make sound business decisions. This is something that I appreciate more and more the older and more experienced I get.
http://www.broadswordsolutions.com/
What is the difference between RD and REQM?
What is the difference between REQM and Requirements Development? What are some of the the leading tools for capturing requirements?
Requirements Management, or "REQM," is all about maintaining the set of requirements that you have, and the process of accepting new ones. In the CMMI world, that includes understanding them, committing to them, managing changes to them, maintaining the appropriate degree of traceability, and understanding how they relate to the actual work being performed by the team.
Requirement Development, or "RD," is about the transformation of customer needs into requirements that can then evolve into a design and/or code. This includes eliciting the customer needs (JAD sessions, interviews, et al), transforming those needs into requirements, evolving them into product requirements, allocating the requirements across releases, teams, developers, or modules, validating them, and ensuring that they fit within the customer constraints and assumptions.
I am not aware of one single tool that does all of this, but parts can be supported by Borland's CaliberRM, IBM's ReqPro, or Doors. My preference is CaliberRM, but they all pretty much do the same thing. They are also all parts of a larger "development framework" that these companies market.
http://www.broadswordsolutions.com/
Requirements Management, or "REQM," is all about maintaining the set of requirements that you have, and the process of accepting new ones. In the CMMI world, that includes understanding them, committing to them, managing changes to them, maintaining the appropriate degree of traceability, and understanding how they relate to the actual work being performed by the team.
Requirement Development, or "RD," is about the transformation of customer needs into requirements that can then evolve into a design and/or code. This includes eliciting the customer needs (JAD sessions, interviews, et al), transforming those needs into requirements, evolving them into product requirements, allocating the requirements across releases, teams, developers, or modules, validating them, and ensuring that they fit within the customer constraints and assumptions.
I am not aware of one single tool that does all of this, but parts can be supported by Borland's CaliberRM, IBM's ReqPro, or Doors. My preference is CaliberRM, but they all pretty much do the same thing. They are also all parts of a larger "development framework" that these companies market.
http://www.broadswordsolutions.com/
Tuesday, July 17, 2007
Does a company that is certified in SigSigma need to get certified in CMMI?
Why do top IT companies with six sigma certification need CMMI certification???? how will it help them? In case they refuse this certification will it affect its market reputation?
No company "needs' either one - but they are both helpful for benchmarking and measuring performance.
Six Sigma and the CMMI are completely different (although often confused) animals. Companies seeking Sig Sigma focus on defects and corrective action, with the hope of being able to correct the cause of the defect and eliminate it in future releases. The focus is largely on metrics.
CMMI is a process model intended to guide organizations through a cycle that improves productivity and performance, eliminates waste, reduces defects, and gives management much better visibility into project performance. The CMMI's focus is both process and metrics.
There is no real conflict between the two except when you realize that in order to predict defects and take true corrective action you must be performing and CMMI Levels 4/5. Many companies attempt Six Sigma programs long before they are mature enough, often leading to failure and wasted effort. Without the standard processes implied by the CMMI, it would be pretty tough to identify the process cause of a defect.
That said, neither has a “certification” per say. A company “achieves” CMMI Level 2/3/4/5 and “achieves” 3/4/5/6 Sigma.
In general, I think the CMMI Appraisal is a much stronger vehicle for evaluating the capabilities of a company, as it is a “best practices” model that used external appraisers to conduct the assessment.
CMMI is verifiable (by the SEI), whereas Six Sigma really isn’t. Any company could claim to have achieved SixSigma, with CMMI you are "awarded" a "rating" by a Lead Appraiser, and you can verify it on the SEI's web site.
As far as market position, I think it depends on the industry. In defense and manufacturing both SixSigma and CMMI are common, but no one is requiring companies to adopt SixSigma that I know of. The same is not true for CMMI. Many OEM's and defense agencies (as well as electonics, health care, and insurance) are requiring that their suppliers achieve CMMI Level Two as a minimum.
If you're in one of those categories, or you want to sell to one of them, the CMMI might be your best route.
www.broadswordsolutions.com
No company "needs' either one - but they are both helpful for benchmarking and measuring performance.
Six Sigma and the CMMI are completely different (although often confused) animals. Companies seeking Sig Sigma focus on defects and corrective action, with the hope of being able to correct the cause of the defect and eliminate it in future releases. The focus is largely on metrics.
CMMI is a process model intended to guide organizations through a cycle that improves productivity and performance, eliminates waste, reduces defects, and gives management much better visibility into project performance. The CMMI's focus is both process and metrics.
There is no real conflict between the two except when you realize that in order to predict defects and take true corrective action you must be performing and CMMI Levels 4/5. Many companies attempt Six Sigma programs long before they are mature enough, often leading to failure and wasted effort. Without the standard processes implied by the CMMI, it would be pretty tough to identify the process cause of a defect.
That said, neither has a “certification” per say. A company “achieves” CMMI Level 2/3/4/5 and “achieves” 3/4/5/6 Sigma.
In general, I think the CMMI Appraisal is a much stronger vehicle for evaluating the capabilities of a company, as it is a “best practices” model that used external appraisers to conduct the assessment.
CMMI is verifiable (by the SEI), whereas Six Sigma really isn’t. Any company could claim to have achieved SixSigma, with CMMI you are "awarded" a "rating" by a Lead Appraiser, and you can verify it on the SEI's web site.
As far as market position, I think it depends on the industry. In defense and manufacturing both SixSigma and CMMI are common, but no one is requiring companies to adopt SixSigma that I know of. The same is not true for CMMI. Many OEM's and defense agencies (as well as electonics, health care, and insurance) are requiring that their suppliers achieve CMMI Level Two as a minimum.
If you're in one of those categories, or you want to sell to one of them, the CMMI might be your best route.
www.broadswordsolutions.com
Wednesday, July 11, 2007
Should SAM be in our appraisal scope?
Do organizations that develop software applications over SAP or Oracle Applications and that deliver no products or products components to their customers require the SAM Process Area to be in appraisal scope?
As you may know, SAM is the only PA allowed to be “out of scope” for a CMMI Appraisal. However, it's not automatic. The exclusion of SAM is something that will need to be understood, negotiated, and agreed to between the appraisal sponsor and the Lead Appraiser.
In general, I am comfortable excluding SAM if the appraised organization does not purchase key products or services from a supplier that ends up being integrated into your product. In other words, if you hire a company to write a device driver for your handheld inventory device that you use or market, then SAM would be applicable. On the other hand, if you purchase an off-the-shelf “c” library that offers a spell check routine, and you got it from CDW for 29.95, I would not apply SAM. SAM could also apply to internal suppliers, like an operations department, if a service-level agreement exists and they do indeed need to integrated into your product.
Another test I would apply is, is it possible to apply the SAM practices to a particular vendor? For instance, SAP probably wouldn’t comply with your request to “monitor selected supplier processes.”
www.broadswordsolutions.com
As you may know, SAM is the only PA allowed to be “out of scope” for a CMMI Appraisal. However, it's not automatic. The exclusion of SAM is something that will need to be understood, negotiated, and agreed to between the appraisal sponsor and the Lead Appraiser.
In general, I am comfortable excluding SAM if the appraised organization does not purchase key products or services from a supplier that ends up being integrated into your product. In other words, if you hire a company to write a device driver for your handheld inventory device that you use or market, then SAM would be applicable. On the other hand, if you purchase an off-the-shelf “c” library that offers a spell check routine, and you got it from CDW for 29.95, I would not apply SAM. SAM could also apply to internal suppliers, like an operations department, if a service-level agreement exists and they do indeed need to integrated into your product.
Another test I would apply is, is it possible to apply the SAM practices to a particular vendor? For instance, SAP probably wouldn’t comply with your request to “monitor selected supplier processes.”
www.broadswordsolutions.com
Should we receive a "Partially Implemented" if we don't use historical data for estimates?
The majority of my appraisal team wanted to rate PP SP 1.4 “Partially Implemented” because they felt we were missing one critical element: how we took actuals from the prior year and translated those into plans for the current year (e.g., with a multiplier, due to complexity differences and/or team experience differences). I felt that the absence of that piece of written data was not sufficient to prevent us from attaining the larger Goal. What do you think?”
In general, I’m reluctant to require any prescriptive method as the only way to satisfy a practice. In other words, a project can very easily estimate properly without specifically taking actual estimates from the prior year and using them with a multiplier as you have described. I agree with your assessment, the absence of a specific piece of written data should not stop you from achieving a goal as long as you are achieving it in some other way.
The suggested work products in the book are just that, suggestions. There's no need to take them literally.
www.broadswordsolutions.com
In general, I’m reluctant to require any prescriptive method as the only way to satisfy a practice. In other words, a project can very easily estimate properly without specifically taking actual estimates from the prior year and using them with a multiplier as you have described. I agree with your assessment, the absence of a specific piece of written data should not stop you from achieving a goal as long as you are achieving it in some other way.
The suggested work products in the book are just that, suggestions. There's no need to take them literally.
www.broadswordsolutions.com
Sunday, June 10, 2007
What can be evidence for "Estimating Rationale" in Project Planning?
What can be documented evidence for "estimation rationale?"
Hey, I asked a Sr. Engineer for an estimate and he told me. Isn't that rational?
It may be rational, but it isn't evidence of estimating "rationale." That darn "e!" changes everything. I hate that!!
Estimation rationale is a way to explain how you and your team came up with an estimate. Did you use any specific estimating process? If so, what were its outputs? Did you count reports, screens, features, functions points, or lines of code? If so, what was the output of that exercise? If you’re in an “agile” world, did you estimate a number of releases and iterations and allocate the high-priority features you planned on delivering during each one?
I always ask myself “why does the model want to know this?” when I’m stuck trying to figure out why a practice was put into the CMMI. In this case, they seem to have been looking for evidence that an engineer didn’t just “guess” at what the estimate would be – but went through some process to validate it. This is process is the“rational.”
So, how did you validate your last estimate? The output of that work is your evidence. Or . . . did you just guess?
www.broadswordsolutions.com
Hey, I asked a Sr. Engineer for an estimate and he told me. Isn't that rational?
It may be rational, but it isn't evidence of estimating "rationale." That darn "e!" changes everything. I hate that!!
Estimation rationale is a way to explain how you and your team came up with an estimate. Did you use any specific estimating process? If so, what were its outputs? Did you count reports, screens, features, functions points, or lines of code? If so, what was the output of that exercise? If you’re in an “agile” world, did you estimate a number of releases and iterations and allocate the high-priority features you planned on delivering during each one?
I always ask myself “why does the model want to know this?” when I’m stuck trying to figure out why a practice was put into the CMMI. In this case, they seem to have been looking for evidence that an engineer didn’t just “guess” at what the estimate would be – but went through some process to validate it. This is process is the“rational.”
So, how did you validate your last estimate? The output of that work is your evidence. Or . . . did you just guess?
www.broadswordsolutions.com
Tuesday, May 22, 2007
Can CMMI apply to a Document Production company?
Hi Jeff,
My name is Renuka from Bangalore India, working as a Quality Executive. I have been in the domain for more than 2+ years and have actively participated in CMMI L3 implementation mainly for the Process area SAM.
Current I'm with a company whose main business is Technical communication for Major development companies in bangalore. We have a tailored QMS in place for the document development lifecyle model. Is it possible that a Document development company could be appraised for CMMI? The QA team here also is an internal development team, which supports for software development eg: online applications internally (who would like be be a revenue generating team instead of only support function).
We have tailored the SDLC to DDLC & use the QMS for the process compliance.
Interesting application of the model! Does your company produce a product? Does it take requirements in, manage them, have a plan, measure performance, design and build, and verify? If so, then I see no reason why you couldn't successfully use the CMMI to benchmark your performance.
Two hints I would give you though. First, spend some time with your selected Lead Appraiser to make sure he/she REALLY understands your business. If you select one with only a systems background he/she MAY not be able to logically make the transition to apply the model to your business. Secondly, take a look at the Continuous Representation of the model. You may discover that it is more appropriate for your situation. Just a thought!
www.broadswordsolutions.com
How do we measure CMMI Compliance?
Greetings.
Congratulations on performing your self appraisal. Let me ask you this, what are you using to "self-appraise?" This may be the only tool you need. There is no "standard compliance matrix" unless you consider the practices in the model to be one. The way to measure CMMI Compliance is to engage with an authorized SEI SCAMPI Lead Appraiser (either in your area or one that will travel to you) to conduct an objective SCAMPI Appraisal. SCAMPI is the method we use to evaluate CMMI performance and it does not include an standard forms or matrices - although it is a robust methodology.
As a SCAMPI Lead Appraiser, it's my job to evaluate process performance across your organization against the required components of the model (the Goals) and the expected components (the Practices). For a self assessment you could do the same by opening the book and going through it practice by practice Have fun!
Is there a difference between Risks and Risk Sources?
Hello Jeff,
- Lack of Human resources may be a risk, but also a source for the risk “Product not delivered on time”;
- The element “Uncertain requirements” is present in both RSKM risks sources and risk taxonomy categories.
First of all, let me congratulate you on your obvious level of knowledge about Risks, as well as your knowledge of the CMMI model. Excellent for a trainee! I'll be looking forward to YOUR Blog in the future!
Second, let's step back for a second and try to view the CMMI as a set of guidelines, and the examples in the model as a set of suggestions. In doing that, we see that identifying risk sources is a neat way to ensure that we capture most of the important risks, by providing us with "memory joggers" to help us identify the important ones. You have done so with great clarity.
As to a distinction between risks and sources, you're right! Some risks and sources are related, and some risks can become sources themselves. Should you treat these things differently? I would say "no" and here's why. It's very difficult to get people to adopt a process of any kind, primarily due to the culture change. Add to that the complexity of tailoring guidelines (which force the Project Manager to interpret the process and make decisions about what is appropriate) and it becomes, in some cases, nearly impossible.
As I always am conscious to keep my "Agile" hat on (I believe "Agile" is a philosophy as well as a family of methods) I am always looking for simplicity and an opportunity to streamline as much as possible. In the spirit of this philosophy, I would argue that it would be better for the organization as a whole to deploy a simple set of "risk sources" and not muddy the waters with the maddening and circular discussion that would inevitably take place once you introduce the "source or risk?" conversation. Believe me, I've been tortured through many a similar discussion.
That's what I think anyway. Others may (and probably will!) disagree.
Monday, May 14, 2007
Dear Jeff
For instance, it would be pretty tough to “Manage Requirements” (REQM.SG1) without understanding them, obtaining commitment, managing traceability, etc… You get the picture.
One way to handle this is to identify all of the “must have” work products and processes, and then the “should have” work products and processes. Like the practices, the “should” really are “must” unless the project has a good reason for tailoring it out – and has some alternative for it.
www.broadswordsolutions.com
I’ve read your message on waivers athttp://tech.groups.yahoo.com/group/cmmi_process_improvement/message/7929
I’d like to ask what CANNOT be tailored out from a CMMI perspective. For example, if a tailoring request will result in not meeting an SG or GG in one of the projects, should the request be approved?
I understand that we should determine which parts of our processes must be done, but, from an appraisal viewpoint, what would be considered improper tailoring?
Great question. I think you’ve answered part of it already.
If the tailoring results in not meeting and SG or a GG then it shouldn’t be approved (assuming CMMI compliance is one of your goals of course). But the story doesn’t end there. Remember that the Goals are required, but the practices (SPs and GPs) OR AN ALTERNATIVE are expected. By expected the CMMI means that they need to be satisfied in order to satisfy the goals. I’d be hard pressed to come up with an example of a goal that didn’t require the SPs to actually be satisfied (although there are alternatives – especially in the Agile world).
One way to handle this is to identify all of the “must have” work products and processes, and then the “should have” work products and processes. Like the practices, the “should” really are “must” unless the project has a good reason for tailoring it out – and has some alternative for it.
Tuesday, May 8, 2007
Can we just have our software department appraised?
Dear Jeff,
We're an ISO9001-2000 certified company working towards CMMI ML 3. Can we be certified in our software department only?
There is a concept in the SCAMPI Appraisal process called the "organizational unit," or "OU." The OU is the targeted organization to be appraised and must be a logical entity or grouping of some kind. This could include: All Web Development Teams, The Project Management Office, and yes, the Software Department. You will need to discuss this with your Lead Appraiser to ensure his/her understanding of your request, but I see no reason that you could not appraise just this part of your company.
www.broadswordsolutions.com
We're an ISO9001-2000 certified company working towards CMMI ML 3. Can we be certified in our software department only?
There is a concept in the SCAMPI Appraisal process called the "organizational unit," or "OU." The OU is the targeted organization to be appraised and must be a logical entity or grouping of some kind. This could include: All Web Development Teams, The Project Management Office, and yes, the Software Department. You will need to discuss this with your Lead Appraiser to ensure his/her understanding of your request, but I see no reason that you could not appraise just this part of your company.
www.broadswordsolutions.com
Tuesday, May 1, 2007
Can we get to Level Three in 12 months?
Dear Jeff,
I represent a privately held software firm. We were assessed as a CMMI Level 2 organization the first week of April, 2007, and the executive team has challenged the Development organization to achieve CMMI Level 3 within a year. We have had an SEPG in place for over a year, and presently the only full-time person committed to this effort is myself. I have extensive CMM experience from Motorola, as well as leading our CMMI effort here the last 18 months. I know 12 months from CMMI Level 2 to CMMI Level 3 is a challenge, but I truly believe we are capable of obtaining this goal, but to be truthful, the amount of time the Development staff has to dedicate to quality initiatives is minimal. How realistic is it for a software company who has essentially one product that has developed over the course of 10-15 years to achieve CMMI Level 3 within a year after achieving CMMI Level 2?
What are the unforeseen challenges in your opinion?
Level Two to Three in one year is possible . . . but extremely challenging. It comes down to a question of resources and commitment. The SEI expects it to take 18-24 months to make this transition but I believe that is primarily a guideline that assumes that no mature ML 3 process are in place and that you just went from zero to ML 2. That doesn't sound like your situation. Your experience with Motorola, a premier player in the CMMI, will help you here.
Having your SEPG in place will help, but you're going to have to figure out how to get work done. There will more than likely be a large amount of work to do over the first few months and, since you're a lone ranger, that will be difficult, if not impossible.
I advocate a "virtual team" approach that allocates 5% of all participants time (2 hours per week) in which they focus, under your direction on three components: process design, communication, and education. Once you scope this out, plan it, and make task assignments you become a project leader for the development of a large process "product."
To learn more about this you can download my white paper "Agile CMMI" at www.broadswordsolutions.com/resources.php. The second half of the document explains this technique in detail.
The first test is management's commitment. Tell them about your plan to harness the power and brains of all of your software engineering colleagues to make this real (and to aid in adoption) and gauge their reaction. If you sense enthusiasm and PUBLIC support, then jump in. If not, run away as fast as you can.
www.broadswordsolutions.com
I represent a privately held software firm. We were assessed as a CMMI Level 2 organization the first week of April, 2007, and the executive team has challenged the Development organization to achieve CMMI Level 3 within a year. We have had an SEPG in place for over a year, and presently the only full-time person committed to this effort is myself. I have extensive CMM experience from Motorola, as well as leading our CMMI effort here the last 18 months. I know 12 months from CMMI Level 2 to CMMI Level 3 is a challenge, but I truly believe we are capable of obtaining this goal, but to be truthful, the amount of time the Development staff has to dedicate to quality initiatives is minimal. How realistic is it for a software company who has essentially one product that has developed over the course of 10-15 years to achieve CMMI Level 3 within a year after achieving CMMI Level 2?
What are the unforeseen challenges in your opinion?
Level Two to Three in one year is possible . . . but extremely challenging. It comes down to a question of resources and commitment. The SEI expects it to take 18-24 months to make this transition but I believe that is primarily a guideline that assumes that no mature ML 3 process are in place and that you just went from zero to ML 2. That doesn't sound like your situation. Your experience with Motorola, a premier player in the CMMI, will help you here.
Having your SEPG in place will help, but you're going to have to figure out how to get work done. There will more than likely be a large amount of work to do over the first few months and, since you're a lone ranger, that will be difficult, if not impossible.
I advocate a "virtual team" approach that allocates 5% of all participants time (2 hours per week) in which they focus, under your direction on three components: process design, communication, and education. Once you scope this out, plan it, and make task assignments you become a project leader for the development of a large process "product."
To learn more about this you can download my white paper "Agile CMMI" at www.broadswordsolutions.com/resources.php. The second half of the document explains this technique in detail.
The first test is management's commitment. Tell them about your plan to harness the power and brains of all of your software engineering colleagues to make this real (and to aid in adoption) and gauge their reaction. If you sense enthusiasm and PUBLIC support, then jump in. If not, run away as fast as you can.
www.broadswordsolutions.com
Is our Appraisal Team over-reaching?
Dear Jeff,
We are a small organization; only about 20 people support the software projects. We recently completed a SCAMPI B in our quest to reach CMMI-SWML3.
I have a question about the numbers of direct artifacts required for each practice. When we look at Generic practices such as “Identify and Involve RelevantStakeholders,” I understand where it might require 2 direct artifacts to show that we do indeed first identify them, then involve them. But in other cases, how many examples do we need to show? For instance, SAM SP.1.1 wants a list of the acquisition types for each product orproduct component to be acquired. So, say we have 3 products we are acquiring, one CFE, one COTS, and one via subcontract. Now my question is, for all the rest of the SAM SP’s, do we need to show 3 differentdirect artifacts, one for each of the 3 products??
Our SCAMPI B observations revealed that some of the mini-teams repeatedly wanted to see “more such examples to show that the process is an ongoing activity.” I was surprised; I thought the SCAMPI way was to show one good direct and one indirect.
Finally, another thing surprised me from this appraisal team. I know the definition of an Indirect artifact: They are artifacts that are either a consequence of performing the practice, or that substantiate the practice. When we provided them a Direct artifact that they thought was strong, they wanted the Indirect artifact to be linked to that particular Direct artifact. So, if we showed, say, meeting minutes for the Direct artifact, they wanted the Indirect to be something associated with those particular meeting minutes, e.g., an action item that was generated from the meeting, relating to the practice. Is this normal? It presents a challenge for us, because, sometimes it was the case that the meeting minutes were discussing the issue related to the SP, but no action items were generated.
I would appreciate your opinions on any/all of my questions!!
Jeff Says: Whew! I'm tired just thinking about answering this question!
The minimum requirement for evidence in a SCAMPI A Appraisal is OneDirect + (one indirect OR one affirmation). More than the minimum could be required, if the artifacts were incomplete, but if that’s not the case it could easily create an appraisal that has an unreasonable scope. You may drive yourself nuts trying to map one artifact to one practice. In your example, ID and Involve Stakeholders, you might use a RASIC chart to ID the stakeholders, but your evidence of involving them could be partially in your workplan, partially in meeting minutes, meeting logs, emails, or calendar entries. Sometimes the evidence “lives”within another artifact that was meant to satisfy a totally different practice. This type of “synthesis” will greatly reduce the amount of artifacts you need to produce.
Ultimately it’s the Appraisal Team’s responsibility to ferret out that evidence, not your job to create a document for each and every practice. The evidence is out there . . .they just need to be creative in finding it. Of course, you can help them by creating a mapping to the model.
An appraisal is not a “QA Audit.” The team should not be auditing that“the correct stakeholders were identified for the project and that everyone of them was involved appropriately.” The CMMI isn’t magic – it doesn’t automatically create high performing clients that don’t show upf or meetings. They should be looking for the “infrastructure” you’ve put in place and some evidence that the process was indeed performed. But a functional audit may be too much.
You are correct in your definitions of Direct and Indirect, and your description of the Appraisal Team’s demands for more data seem to be overreaching to me (without knowing the details of course . . . ). There is no requirement that the indirect provided be linked to the direct in the way you’ve described, and there is no requirement that more than one direct be provided to show “ongoing” process performance. Of course, it depends what’s in the direct you’ve provided, but that’s another issue :-). For most cases, if the artifact is complete, one is enough.
That said, if the Appraisal Team (and LA) believe that an artifact or affirmation was fabricated for the Appraisal, or that is has significant weakness they are within their rights to ask for additional information, but that is not as common as you might think.
In the appraisals I lead I do not often see this – although I have heard of it happening. In your example for SAM you should be providing the direct artifact thatdescribes the types of products you would need to acquire, and one or more examples of how the acquisition was managed.
On the face of it, it sounds like your appraisal team may need some additional training.
www.broadswordsolutions.com
We are a small organization; only about 20 people support the software projects. We recently completed a SCAMPI B in our quest to reach CMMI-SWML3.
I have a question about the numbers of direct artifacts required for each practice. When we look at Generic practices such as “Identify and Involve RelevantStakeholders,” I understand where it might require 2 direct artifacts to show that we do indeed first identify them, then involve them. But in other cases, how many examples do we need to show? For instance, SAM SP.1.1 wants a list of the acquisition types for each product orproduct component to be acquired. So, say we have 3 products we are acquiring, one CFE, one COTS, and one via subcontract. Now my question is, for all the rest of the SAM SP’s, do we need to show 3 differentdirect artifacts, one for each of the 3 products??
Our SCAMPI B observations revealed that some of the mini-teams repeatedly wanted to see “more such examples to show that the process is an ongoing activity.” I was surprised; I thought the SCAMPI way was to show one good direct and one indirect.
Finally, another thing surprised me from this appraisal team. I know the definition of an Indirect artifact: They are artifacts that are either a consequence of performing the practice, or that substantiate the practice. When we provided them a Direct artifact that they thought was strong, they wanted the Indirect artifact to be linked to that particular Direct artifact. So, if we showed, say, meeting minutes for the Direct artifact, they wanted the Indirect to be something associated with those particular meeting minutes, e.g., an action item that was generated from the meeting, relating to the practice. Is this normal? It presents a challenge for us, because, sometimes it was the case that the meeting minutes were discussing the issue related to the SP, but no action items were generated.
I would appreciate your opinions on any/all of my questions!!
Jeff Says: Whew! I'm tired just thinking about answering this question!
The minimum requirement for evidence in a SCAMPI A Appraisal is OneDirect + (one indirect OR one affirmation). More than the minimum could be required, if the artifacts were incomplete, but if that’s not the case it could easily create an appraisal that has an unreasonable scope. You may drive yourself nuts trying to map one artifact to one practice. In your example, ID and Involve Stakeholders, you might use a RASIC chart to ID the stakeholders, but your evidence of involving them could be partially in your workplan, partially in meeting minutes, meeting logs, emails, or calendar entries. Sometimes the evidence “lives”within another artifact that was meant to satisfy a totally different practice. This type of “synthesis” will greatly reduce the amount of artifacts you need to produce.
Ultimately it’s the Appraisal Team’s responsibility to ferret out that evidence, not your job to create a document for each and every practice. The evidence is out there . . .they just need to be creative in finding it. Of course, you can help them by creating a mapping to the model.
An appraisal is not a “QA Audit.” The team should not be auditing that“the correct stakeholders were identified for the project and that everyone of them was involved appropriately.” The CMMI isn’t magic – it doesn’t automatically create high performing clients that don’t show upf or meetings. They should be looking for the “infrastructure” you’ve put in place and some evidence that the process was indeed performed. But a functional audit may be too much.
You are correct in your definitions of Direct and Indirect, and your description of the Appraisal Team’s demands for more data seem to be overreaching to me (without knowing the details of course . . . ). There is no requirement that the indirect provided be linked to the direct in the way you’ve described, and there is no requirement that more than one direct be provided to show “ongoing” process performance. Of course, it depends what’s in the direct you’ve provided, but that’s another issue :-). For most cases, if the artifact is complete, one is enough.
That said, if the Appraisal Team (and LA) believe that an artifact or affirmation was fabricated for the Appraisal, or that is has significant weakness they are within their rights to ask for additional information, but that is not as common as you might think.
In the appraisals I lead I do not often see this – although I have heard of it happening. In your example for SAM you should be providing the direct artifact thatdescribes the types of products you would need to acquire, and one or more examples of how the acquisition was managed.
On the face of it, it sounds like your appraisal team may need some additional training.
www.broadswordsolutions.com
Subscribe to:
Posts (Atom)