The application of Safe Scrum to IEC 61508 certifiable software

The application of Safe Scrum to IEC 61508 certifiable software
复制标题

Safe Scrum 在 IEC 61508 可认证软件中的应用

DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
Geir Hanssenb
Geir Hanssenb
中科院分区:
--
文献类型:
--
作者:
Tor Stålhanea;Thor Myklebustb;Geir Hanssenb

文献摘要

被引文献

相似文献

为了更好地理解Scrum在IEC61508可认证软件中的应用,我们对该标准进行了评估,以了解Scrum如何符合。标准第3部分的每个部分都被分配了一个类别:(1)“OK”--不需要对Scrum或IEC61508进行修改,(2)“?”--需要讨论,(3)“不好”--需要适应Scrum基于我们的评估,我们提出了安全的Scrum,其主要思想是关注点分离。不属于软件开发过程的所有内容都保留在Scrum之外,因此不会受到我们所选择的范例的影响。在安全Scrum中,所有需求被拆分成安全关键需求和其他需求,并插入到单独的产品待办事项中。然后,我们进行了一次新的评估,将安全Scrum考虑在内。我们发现了15个需要更改的问题,以使Scrum和安全评估员能够接受该流程:如何构建开发结构、计划安全性验证、创建、评审、选择、设计和确保安全性、编写模块测试需求以及测试和评估安全生命周期的输出。我们模型的第一部分包括开发环境描述的IEC61508步骤和SSRS阶段1-4。这些初始步骤产生了要开发的系统的初始要求,并且是模型的第二部分--安全Scrum过程的关键输入。使用迭代和增量方法意味着可以根据最近的产品经验不断地重新计划项目。在迭代之间,可以使用经验来重新确定产品待办事项的优先级。这使该过程变得灵活。当冲刺完成后,将完成最终的RAMS验证。由于大多数系统都在冲刺期间进行了增量验证,因此我们预计最终的RAM验证不会像使用其他开发范例时那样广泛。这也将有助于我们减少认证所需的时间和成本。
In order to develop a better understanding of the application of Scrum to IEC61508 certifiable software, we assessed the standard to see how Scrum could conform. Each section of part 3 of the standard was assigned one of the categories: (1) “OK” – no modification needed to Scrum or IEC61508, (2) “?” – need to be discussed, (3) “Not OK” – need adaptation of Scrum Based on our assessment we proposed the Safe Scrum where the main idea is separation of concerns. Everything that is not part of the software development process is kept outside Scrum and will thus not be influenced by our choice of paradigm. In Safe Scrum, all requirements are split into safety critical requirements and other requirements and inserted into separate product backlogs. We then did a new assessment where we took the Safe Scrum into consideration. We found 15 issues where we need changes in order to make the process acceptable to Scrum and the safety assessors: how to structure development, plan for validating safety, create, review, select, design and ensure safety, write requirements for module testing, and test and evaluate the outputs from the safety lifecycle The first part of our model consists of the IEC61508 steps of developing the environment description and the SSRS phases 1-4. These initial steps result in the initial requirements of the system that is to be developed and is the key input to the second part of the model – the Safe Scrum process. Using an iterative and incremental approach means that the project can be continuously re-planned based on recent product experience. Between the iterations, experience can be used to re-prioritize the product backlogs. This makes the process flexible. When the sprints are completed, a final RAMS validation will be done. Since most of the system has been incrementally validated during the sprints, we expect the final RAMS validation to be less extensive than when using other development paradigms. This will also help us to reduce the time and cost needed for certification.