bannerd

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

UNDER CONSTRUCTION

Tabsetup
01. Introduction
12. Independent V&V
23. IV&V Planning
34. IV&V Artifacts
45. IV&V Issues and Risks
Defining the Activity
Div
idtabs-1

1. Introduction

The software assurance and software safety activities provide a level of confidence that software is free from vulnerabilities, either intentionally designed into the software or accidentally inserted at any time during its life cycle, that the software functions in an intended manner, and that the software does not function in an unintended manner. The software assurance process is the planned and systematic set of activities that ensure the conformance of software life cycle processes and products to requirements, standards, and procedures.  Software assurance assures that the software and its related products meet their specified requirements, conform to standards and regulations, are consistent, complete, correct, safe, secure, and reliable as warranted for the system and operating environment, and satisfy customer needs. The objectives of software assurance and software safety activities include the following:

  1. Ensuring that the processes, procedures, and products used to produce and sustain the software conform to all specified requirements and standards that govern those processes, procedures, and products.
    • A set of activities that assess adherence to, and the adequacy of the software processes used to develop and modify software products.
    • A set of activities that define and assess the adequacy of software processes to provide evidence that establishes confidence that the software processes are appropriate for and produce software products of suitable quality for their intended purposes.
  2. Determining the degree of software quality obtained by the software products.
  3. Ensuring that the software systems are safe and that the software safety-critical requirements are followed.
  4. Ensuring that the software systems are secure.

1.1 Related Activities

  • SE-Initiation and Planning - Assurance activities are planned. They are dependent on a whole host of other project activities.  
  • SE-Estimation - Estimates are made and tracked for assurance activities. Assurance must be measured and controlled. 
  • SE-Schedules - Assurance Activities are scheduled and tracked to completion.  
  • SE-Training - Assurance tam members are trained in Assurance methods, the use of Assurance tools, and related subjects. 
  • SE-Scope Management - Requirements, defect management, change management, Non-conformance and Defect Management. 
  • SE-Testing - including V&V
  • SE-Operations, Maintenance and Retirement
  • SE-Configuration Mgmt - including code repository, builds, and releases 
  • Peer Reviews - including Assurance reviews
  • Measurements - related to Assurance

1.2 Related NPR 7150.2 SWEs

Note

Typically starts with a quote from the NPR that helps define the activity. Additional descriptive material is meant to help define the activity but not be so detailed that it pulls in all of the guidance from the SWEs in the activity. 

Panel
borderColorblue
titleNPR 7150.2B para 5.3.1

Software peer reviews and inspections are the in-process technical examination of work products by peers to find and eliminate defects early in the life cycle. Software peer reviews and inspections are performed following defined procedures covering the preparation for the review, the review itself is conducted, results are recorded, results are reported, and completion criteria is certified. When planning the composition of a software peer review or inspection team, consider including software testing, system testing, software assurance, software safety, software cybersecurity, and software IV&V personnel.


Examples of Some Documents Going Through Peer Review 

Image Added

1.1 Inputs

Note

List of some of the inputs from other activities that are necessary for the activity to begin. 

  • Planning - Peer Reviews are planned activities. They appear in the plans and schedules for the project
  • Requirements - These are the things that are Peer Reviewed
  • Architecture Items - These are the things that are Peer Reviewed
  • Design items - These are the things that are Peer Reviewed
  • Test Plans and Procedures - These are the things that are Peer Reviewed

1.2 Predecessor Activities

Note

List of some of the other activities that must be started (not necessarily completed) this activity to begin. 

Predecessor Activities are performed before Peer Reviews. These activities produce the work products that will be reviewed. 

  • Life Cycle Planning - Peer Reviews are planned activities. They are also used to review and improve all types of plans. 
  • Requirements -  Creating the things that are Peer Reviewed
  • Architecture Items - Creating the things that are Peer Reviewed
  • Design items - Creating the things that are Peer Reviewed
  • Test Plans and Procedures - Creating the things that are Peer Reviewed

1.3 Outputs

Note

List of some of the outputs or work products of the activity. These are typically used as inputs by the downstream activity. In some cases there is a supporting SWE associated with the work product. 

In the case of Peer Reviews, outputs cycle back to the activity that provided the inputs so that improvements to the work products can be made. The activities that initiated the Peer Review, receive the findings from Peer Reviews, Those activities then use those findings to to fix defects and implement improvements uncovered in the reviews. The improved work products are then used by downstream activities as the project proceeds. 

Output Work ProductUsed by Downstream Activity
  • Peer Review Findings
  • Life Cycle Planning
  • Software Architecture 
  • Software Design
  • Software Testing
  • Configuration Management
  • Coding


1.4 Successor Activities

Note

Links to Activities which might be started or supported by this activity. 

  • Life Cycle Planning
  • Software Architecture 
  • Software Design
  • Software Testing
  • Configuration Management
  • Coding

1.5 Repetition

Note

Describe what conditions determine if the activity needs to be repeated.

  • How much of the activity needs to be repeated
  • Frequency of repetition

Peer Reviews are planned activities and may be repeated as needed throughout the life cycle.

  • As Software Requirements, budgets, schedules, and technology changes are factored into the project, additional Peer Reviews of affected work products may be desirable.  

1.6 Center Resources From SPAN

Note

Add links to SPAN activity pages that are appropriate for this activity. Use links from the Activity section of the front page. SPAN

Several Centers Process Asset Libraries have materials related to this activity. Related Processes, templates, and other resources may be found in the following Activities in SPAN (available to NASA only). 

1.3 Related Topics and Process Assets


3. IV&V Planning

3.1 Related NPR 7150.2 SWEs

3.2 Related Topics and Process Assets

4. IV&V Artifacts

4,1 Related NPR 7150.2 SWEs

4.2 Related Topics and Process Assets

5. IV&V Issues and Risks

5.1 Related NPR 7150.2 SWEs

5.2 Related Topics and Process Assets

Div
idtabs-2

2

. Independent V&V

2.1 Related NPR 7150.2 SWEs

2.2 Related Topics and Process Assets

Div
idtabs-3
Div
idtabs-4
Div
idtabs-5
Div
idtabs-6

6.

Div
idtabs-7

7.

Div
idtabs-8

8.

Div
idtabs-9

9.

. Defining the Activity

Note

This tab contains the links to pages in the SWEHB that are at the heart of the activity. 

2.1 SWEs

Note

This section contains the links to SWE pages that form the heart of the activity. 

2.2 Topics and other Supporting Materials

Note

This section is for SWEHB pages, other than SWEs, that directly support the activity. This section contains Topics, document content pages, PATs, and other pages. 

2.3 Other Associated SWEs, Topics, etc.

Note

Includes other SWEHB pages that are indirectly associated with the activity. May include SWEs, Topics, document definition pages, PATs, etc. They may have been mentioned in the guidance of another page. 

2.3.1 Process Asset Templates 

Panel
borderColorgreen
titlePeer Reviews Assets Process Asset Templates

Include Page
Peer Review Process Asset Templates
Peer Review Process Asset Templates

Div
idtabs-10
10.