3. Guidance3.1 Using the Compliance MatrixThe requirements marked with an “X” in Appendix C are Agency requirements to implement NASA’s policy as delineated in NPD 7120.4. These requirements are “a designed set of requirements for protecting the Agency's investment in software engineering products and to fulfill its responsibility to the citizens of the United States. ... For engineers to effectively communicate and work seamlessly among Centers, a common framework of generic requirements is needed.” Compliance with the requirements in NPR 7150.2 ensures these goals are fulfilled. NPR 7150.2 establishes a baseline set of requirements to reduce software engineering risks on NASA projects and programs. Appendix C, Requirements Mapping Matrix, defines the default applicability of the requirements based on software classification and safety-criticality. Each project has unique circumstances and tailoring can be employed to modify the requirements set appropriate for the software engineering effort. Each project documents the tailoring in a compliance matrix (see SWE-125 - Requirements Compliance Matrix), including Technical Authority approved waivers and deviations. The project also captures in the compliance matrix any associated risks, risk mitigations, and rationale for requirements for which the project has received complete relief from the appropriate Technical Authorities (Engineering, Safety, and Mission Assurance (SMA) and CIO (as required in the NPR 7150.2)). See also SWE-152 - Review Requirements Mapping Matrices regarding OCE review of matrices, See also SWE-212 - NASA-STD-8739 Mapping Matrices regarding the mapping of SA tasks to NPR 7150.2 Requirements. 3.2 Requests for Software Requirements ReliefRequests for software requirements relief (partial or complete relief) at either the Center or Headquarters Technical Authority level may be submitted by project managers in the streamlined form of a compliance matrix to the Technical Authority identified in Appendix C. As part of the relief process, project managers obtain the required signatures from the responsible organizations and designated Technical Authorities (Engineering, Safety and Mission Assurance (SMA) and CIO (as required in the NPR 7150.2)). See also SWE-126 - Tailoring Considerations, SWE-139 - Shall Statements. 3.3 Requirements by ClassThe Requirements Mapping Matrix in NPR 7150.2 uses an “X” to identify the requirements that are designated by the Agency to be applied for each software class. The identified requirements are required activities for the identified software classification and safety-criticality. Within the compliance matrix in Appendix C, there are both project and institutional requirements. The project requirements are requirements levied on the project managers specific to handling the development of software projects. The institutional requirements focus on how NASA does business and is independent of any particular program or project. These requirements are levied on NASA Headquarters (including the Office of the Chief Engineer, Office of Safety Mission & Assurance, and Mission Directors) and Center organizations because they directly affect mission success, address risks, or may impact other NASA programs, projects, processes, or procedures. 3.4 Institutional RequirementsCenter Directors are responsible for institutional requirements (shown in Book B of this Handbook) and ensuring that projects fulfill project requirements identified in Appendix C of NPR 7150.2. The Center Director or designee regularly reviews the compliance matrix to make sure that projects remain in compliance with their approved requirements set. Downloadable compliance matrices for each class of software are available for NASA users in the Topic 7.16 - Appendix C. Requirements Mapping and Compliance Matrix. 3.5 Additional GuidanceAdditional guidance related to this requirement may be found in the following materials in this Handbook: 3.6 Center Process Asset Libraries
See the following link(s) in SPAN for process assets from contributing Centers (NASA Only). |