Software EngineeringUnit 1012 min read
Software Project Management: Planning, Risks, Agile & Ethics
Unit 10 of Software Engineering explores core project management concepts—estimation (COCOMO), risk analysis, Agile methodologies, configuration management, and ethical practices—with real-world examples from Nepali tech (eSewa, Daraz) and global platforms (Google, WhatsApp). Learn how to plan timelines, mitigate risks
TAKEAWAYS:
- COCOMO Model: Calculate effort (person-months) and time for projects using Organic/Embedded modes, with a worked example for a 320 KLOC system.
- Risk Management: Identify, analyze (qualitative/quantitative), and mitigate risks (e.g., budget overruns, scope creep) using tools like risk matrices.
- Agile vs. Traditional: Compare Agile (Scrum, Kanban) with Waterfall, highlighting iterative development, user stories, and daily standups.
- Configuration Management: Track changes in software versions using version control (Git), baselines, and build automation.
- Ethics in SE: Apply ethical guidelines (ACM/IEEE) to conflicts like data privacy (e.g., eSewa’s user data handling) or intellectual property.
- Real-World Tie-Ins: See how Daraz uses Agile for inventory systems, Ncell applies risk management to network outages, and Google’s COCOMO-like estimation for Android updates.
1. Introduction to Software Project Management
Software Project Management (SPM) is the application of knowledge, skills, tools, and techniques to plan, execute, monitor, and control software development projects. It ensures projects are delivered on time, within budget, and meet quality standards. Key challenges include:
- Uncertainty: Requirements change, technologies evolve, and teams grow/shrink.
- Complexity: Interdependencies between modules, stakeholders, and external systems.
- Stakeholder Expectations: Balancing user needs, business goals, and technical feasibility.
Why SPM Matters:
- Nepal Example: eSewa’s digital payment system required SPM to integrate with banks, NTC, and mobile operators under tight deadlines.
- Global Example: WhatsApp’s end-to-end encryption rollout used Agile to manage security risks and user adoption.
2. Project Estimation: COCOMO Model
The Constructive Cost Model (COCOMO) estimates effort (person-months) and development time based on project size (measured in KLOC: thousands of lines of code).
COCOMO Modes
COCOMO has three modes, each with different effort multipliers (EM) and time multipliers (TM):
| Mode | Description | Effort Multiplier (EM) | Time Multiplier (TM) |
|---|---|---|---|
| Organic | Small teams, familiar tools, simple projects. | Lowest EM | Lowest TM |
| Semi-Detached | Medium complexity, some reuse, moderate team size. | Medium EM | Medium TM |
| Embedded | High complexity, real-time constraints, tight coupling with hardware. | Highest EM | Highest TM |
COCOMO Formulas
- Effort (E) in person-months:
- Organic:
- Embedded:
- Development Time (T) in months:
- Organic:
- Embedded:
Worked Example: Estimating a 320 KLOC Project
Scenario: A bank’s loan management system (embedded mode, real-time processing).
- Calculate Effort (E):
- Calculate Time (T): Result: ~20 months to develop, requiring ~168 person-years (2024/12).
Real-World Link:
- Ncell’s Billing System: Estimated using COCOMO-like models to predict team size for integrating with NTC’s fiber network. Overestimation led to hiring freeze; underestimation caused burnout.
3. Risk Management in Software Projects
Risks are uncertain events that can positively or negatively impact a project. SPM focuses on identifying, analyzing, and mitigating risks.
sequenceDiagram
participant User
participant Daraz
participant Logistics
participant PaymentGateway
User->>Daraz: Places order (Risk: Logistics delay)
Daraz->>Logistics: Dispatch (Risk: Delayed pickup)
Daraz->>PaymentGateway: Process payment (Risk: Gateway failure)
PaymentGateway-->>Daraz: Confirmation
Daraz-->>User: Order confirmed
alt Logistics Delay
Daraz->>User: Delay notification
endRisk scenario: Daraz order fulfillment with potential delaysRisk Types
| Category | Example Risks |
|---|---|
| Technical | Technology obsolescence, integration failures, performance bottlenecks. |
| Project Management | Scope creep, poor estimation, resource shortages. |
| External | Regulatory changes (e.g., Nepal’s new data privacy law), vendor failures. |
| Organizational | Lack of management support, cultural resistance to Agile. |
Risk Analysis Stages
- Risk Identification: Brainstorming, checklists, expert judgment.
- Example: For Daraz’s order fulfillment system, risks include third-party logistics delays and payment gateway failures.
- Risk Assessment:
- Qualitative: Probability (Low/Medium/High) × Impact (Low/Medium/High) → Risk Matrix.
- Quantitative: Assign numerical values (e.g., probability = 0.7, impact = $50K → Risk Score = 35).
- Risk Mitigation:
- Avoid: Change project scope (e.g., drop a low-priority feature).
- Transfer: Use insurance or outsourcing (e.g., NTC outsourcing fiber maintenance to a contractor).
- Reduce: Add buffers (e.g., extra testing time for Pathao’s ride-matching algorithm).
- Accept: Document and monitor (e.g., minor UI delays in a prototype).
Qualitative risk assessment for a software project (Image: Peter Gladdish, CC BY 4.0, via Wikimedia Commons)
4. Agile Software Development
Agile is an iterative, incremental approach that prioritizes flexibility, collaboration, and customer feedback. Unlike Waterfall (sequential phases), Agile delivers working software in short cycles (sprints).
Agile vs. Traditional (Waterfall)
| Feature | Agile | Waterfall |
|---|---|---|
| Approach | Iterative, incremental | Sequential, phased |
| Flexibility | Adapts to changes easily | Rigid; changes require formal approval |
| Customer Involvement | Continuous (user stories, sprint reviews) | Limited (requirements gathered upfront) |
| Documentation | Lightweight (just enough) | Heavy (detailed upfront) |
| Example | WhatsApp’s feature rollouts (e.g., payments) | NTC’s fiber network deployment (fixed phases) |
Agile Methodologies
- Scrum:
- Roles: Product Owner, Scrum Master, Development Team.
- Artifacts: Product Backlog, Sprint Backlog, Increment.
- Events: Sprint Planning, Daily Standup, Sprint Review, Retrospective.
- Kanban:
- Visual workflow (e.g., Trello board with "To Do," "In Progress," "Done").
- Limits work-in-progress (WIP) to avoid bottlenecks.
- Extreme Programming (XP):
- Practices: Pair programming, test-driven development (TDD), continuous integration.
Real-World Example:
- Google Play Store Updates: Uses Agile to release Android app updates in 2-week sprints. A failed sprint (e.g., buggy notification system) triggers a retrospective to improve testing.
5. Software Configuration Management (SCM)
SCM ensures consistency, traceability, and control of software changes. Key activities:
- Version Control: Track changes using tools like Git (e.g., Daraz’s codebase).
- Baselining: Freeze a version of software at a milestone (e.g., eSewa’s payment API v1.0).
- Build Automation: Automate compilation/testing (e.g., Jenkins for Ncell’s app).
- Change Control: Approve/modify requirements (e.g., NEPSE’s trading system updates).
erDiagram
Repository ||--o{ Commit : "contains"
Commit ||--o{ File : "tracks"
Commit {
int id PK
string hash
date timestamp
string author
}
File {
string path PK
string content
string status
}Git repository database schema (simplified)Why SCM is Required:
- Problem: Without SCM, teams may overwrite each other’s code (e.g., two developers editing the same file in Pathao’s ride-matching logic).
- Solution: Git’s branching model allows parallel development.
6. Software Engineering Ethics
Ethics in SPM involves moral principles guiding decisions. Key guidelines (ACM/IEEE):
- Public: Avoid harm to users (e.g., WhatsApp’s end-to-end encryption protects privacy).
- Client/Employer: Honest about project status (e.g., Ncell must disclose network outage causes).
- Product: Ensure software is reliable and safe (e.g., eSewa’s fraud detection system).
- Profession: Uphold integrity (e.g., not falsifying test results for NEPSE’s trading software).
- Colleagues: Respect teamwork (e.g., sharing knowledge in Agile retrospectives).
Example:
- Conflict: A Daraz developer discovers a security flaw in the payment gateway but risks losing their job if reported.
- Solution: Follow ethical guidelines to disclose internally, using SCM to trace the issue.
7. Exam Tip: How to Score Full Marks
COCOMO Questions:
- Always show formulas and step-by-step calculations.
- Label modes (Organic/Embedded) clearly.
- Example: For a 100 KLOC project in Organic mode:
Risk Management:
- Use a table to classify risks (technical, external, etc.).
- Describe mitigation strategies with real examples (e.g., "Ncell mitigates power outage risks by using backup generators").
Agile vs. Waterfall:
- Compare 3 key differences (e.g., flexibility, documentation, customer involvement).
- Use Nepali examples: "eSewa uses Agile for rapid updates, while NTC’s fiber network uses Waterfall for phased deployment."
Ethics:
- Relate to ACM/IEEE codes and real scenarios (e.g., "A developer at Khalti must report a data breach to comply with public ethics").
Diagrams:
- Draw mermaid sequenceDiagrams for Agile sprints or risk matrices.
- Label all components (e.g., "Product Owner → Sprint Planning → Dev Team").
sequenceDiagram
participant User
participant ProductOwner
participant ScrumMaster
participant DevTeam
User->>ProductOwner: Prioritizes backlog (user stories)
ProductOwner->>ScrumMaster: Defines sprint goals
ScrumMaster->>DevTeam: Sprint Planning (2-week cycle)
loop Daily
DevTeam->>ScrumMaster: Standup (3 questions: What did I do? What will I do? Blockers?)
end
DevTeam->>DevTeam: Develops increment
DevTeam->>ProductOwner: Sprint Review (demo)
ProductOwner->>DevTeam: Feedback
DevTeam->>ScrumMaster: Retrospective (process improvements)In the real world
- eSewa’s Digital Payments: Used Agile sprints to iteratively develop features like QR code payments, adapting to Nepal Rastra Bank’s evolving regulations mid-project.
- Ncell’s Network Outage Risk Management: Applied qualitative risk assessment to predict fiber cable failures (e.g., NTC’s 2023 Kathmandu–Pokhara backbone) by analyzing historical weather data and maintenance logs.
- Daraz’s Inventory System: Leveraged COCOMO-like estimation to forecast team size for integrating with third-party logistics (e.g., Nabil Bank’s warehouse automation), adjusting for seasonal demand spikes like Dashain.
Based on the TU BSc CSIT syllabus for Software Engineering (CSC364), unit 10.
Discussion
Loading…