CSC364 Software Engineering

Software EngineeringUnit 1012 min read

Software Project Management: Planning, Risks, Agile & Ethics

Unit 10 of Software Engineering explores core project management concepts—estimation (COCOMO), risk analysis, Agile methodologies, configuration management, and ethical practices—with real-world examples from Nepali tech (eSewa, Daraz) and global platforms (Google, WhatsApp). Learn how to plan timelines, mitigate risks

TAKEAWAYS:

  • COCOMO Model: Calculate effort (person-months) and time for projects using Organic/Embedded modes, with a worked example for a 320 KLOC system.
  • Risk Management: Identify, analyze (qualitative/quantitative), and mitigate risks (e.g., budget overruns, scope creep) using tools like risk matrices.
  • Agile vs. Traditional: Compare Agile (Scrum, Kanban) with Waterfall, highlighting iterative development, user stories, and daily standups.
  • Configuration Management: Track changes in software versions using version control (Git), baselines, and build automation.
  • Ethics in SE: Apply ethical guidelines (ACM/IEEE) to conflicts like data privacy (e.g., eSewa’s user data handling) or intellectual property.
  • Real-World Tie-Ins: See how Daraz uses Agile for inventory systems, Ncell applies risk management to network outages, and Google’s COCOMO-like estimation for Android updates.

1. Introduction to Software Project Management

Software Project Management (SPM) is the application of knowledge, skills, tools, and techniques to plan, execute, monitor, and control software development projects. It ensures projects are delivered on time, within budget, and meet quality standards. Key challenges include:

  • Uncertainty: Requirements change, technologies evolve, and teams grow/shrink.
  • Complexity: Interdependencies between modules, stakeholders, and external systems.
  • Stakeholder Expectations: Balancing user needs, business goals, and technical feasibility.

Why SPM Matters:

  • Nepal Example: eSewa’s digital payment system required SPM to integrate with banks, NTC, and mobile operators under tight deadlines.
  • Global Example: WhatsApp’s end-to-end encryption rollout used Agile to manage security risks and user adoption.

2. Project Estimation: COCOMO Model

The Constructive Cost Model (COCOMO) estimates effort (person-months) and development time based on project size (measured in KLOC: thousands of lines of code).

00.91.82.73.6Organic Mode2.4Semi-Detached3Embedded3.6
COCOMO Effort Multipliers (EM) for 320 KLOC project (higher = more effort)

COCOMO Modes

COCOMO has three modes, each with different effort multipliers (EM) and time multipliers (TM):

Mode Description Effort Multiplier (EM) Time Multiplier (TM)
Organic Small teams, familiar tools, simple projects. Lowest EM Lowest TM
Semi-Detached Medium complexity, some reuse, moderate team size. Medium EM Medium TM
Embedded High complexity, real-time constraints, tight coupling with hardware. Highest EM Highest TM

COCOMO Formulas

  1. Effort (E) in person-months:
    • Organic:
    • Embedded:
  2. Development Time (T) in months:
    • Organic:
    • Embedded:

Worked Example: Estimating a 320 KLOC Project

Scenario: A bank’s loan management system (embedded mode, real-time processing).

  1. Calculate Effort (E):
  2. Calculate Time (T): Result: ~20 months to develop, requiring ~168 person-years (2024/12).

Real-World Link:

  • Ncell’s Billing System: Estimated using COCOMO-like models to predict team size for integrating with NTC’s fiber network. Overestimation led to hiring freeze; underestimation caused burnout.

3. Risk Management in Software Projects

Risks are uncertain events that can positively or negatively impact a project. SPM focuses on identifying, analyzing, and mitigating risks.

sequenceDiagram
    participant User
    participant Daraz
    participant Logistics
    participant PaymentGateway
    User->>Daraz: Places order (Risk: Logistics delay)
    Daraz->>Logistics: Dispatch (Risk: Delayed pickup)
    Daraz->>PaymentGateway: Process payment (Risk: Gateway failure)
    PaymentGateway-->>Daraz: Confirmation
    Daraz-->>User: Order confirmed
    alt Logistics Delay
        Daraz->>User: Delay notification
    end
Risk scenario: Daraz order fulfillment with potential delays

Risk Types

Category Example Risks
Technical Technology obsolescence, integration failures, performance bottlenecks.
Project Management Scope creep, poor estimation, resource shortages.
External Regulatory changes (e.g., Nepal’s new data privacy law), vendor failures.
Organizational Lack of management support, cultural resistance to Agile.

Risk Analysis Stages

  1. Risk Identification: Brainstorming, checklists, expert judgment.
    • Example: For Daraz’s order fulfillment system, risks include third-party logistics delays and payment gateway failures.
  2. Risk Assessment:
    • Qualitative: Probability (Low/Medium/High) × Impact (Low/Medium/High) → Risk Matrix.
    • Quantitative: Assign numerical values (e.g., probability = 0.7, impact = $50K → Risk Score = 35).
  3. Risk Mitigation:
    • Avoid: Change project scope (e.g., drop a low-priority feature).
    • Transfer: Use insurance or outsourcing (e.g., NTC outsourcing fiber maintenance to a contractor).
    • Reduce: Add buffers (e.g., extra testing time for Pathao’s ride-matching algorithm).
    • Accept: Document and monitor (e.g., minor UI delays in a prototype).

risk management matrix**Qualitative risk assessment for a software project (Image: Peter Gladdish, CC BY 4.0, via Wikimedia Commons)


4. Agile Software Development

Agile is an iterative, incremental approach that prioritizes flexibility, collaboration, and customer feedback. Unlike Waterfall (sequential phases), Agile delivers working software in short cycles (sprints).

Agile vs. Traditional (Waterfall)

Feature Agile Waterfall
Approach Iterative, incremental Sequential, phased
Flexibility Adapts to changes easily Rigid; changes require formal approval
Customer Involvement Continuous (user stories, sprint reviews) Limited (requirements gathered upfront)
Documentation Lightweight (just enough) Heavy (detailed upfront)
Example WhatsApp’s feature rollouts (e.g., payments) NTC’s fiber network deployment (fixed phases)

Agile Methodologies

  1. Scrum:
    • Roles: Product Owner, Scrum Master, Development Team.
    • Artifacts: Product Backlog, Sprint Backlog, Increment.
    • Events: Sprint Planning, Daily Standup, Sprint Review, Retrospective.
  2. Kanban:
    • Visual workflow (e.g., Trello board with "To Do," "In Progress," "Done").
    • Limits work-in-progress (WIP) to avoid bottlenecks.
  3. Extreme Programming (XP):
    • Practices: Pair programming, test-driven development (TDD), continuous integration.

Real-World Example:

  • Google Play Store Updates: Uses Agile to release Android app updates in 2-week sprints. A failed sprint (e.g., buggy notification system) triggers a retrospective to improve testing.

5. Software Configuration Management (SCM)

SCM ensures consistency, traceability, and control of software changes. Key activities:

  1. Version Control: Track changes using tools like Git (e.g., Daraz’s codebase).
  2. Baselining: Freeze a version of software at a milestone (e.g., eSewa’s payment API v1.0).
  3. Build Automation: Automate compilation/testing (e.g., Jenkins for Ncell’s app).
  4. Change Control: Approve/modify requirements (e.g., NEPSE’s trading system updates).
erDiagram
    Repository ||--o{ Commit : "contains"
    Commit ||--o{ File : "tracks"
    Commit {
        int id PK
        string hash
        date timestamp
        string author
    }
    File {
        string path PK
        string content
        string status
    }
Git repository database schema (simplified)

Why SCM is Required:

  • Problem: Without SCM, teams may overwrite each other’s code (e.g., two developers editing the same file in Pathao’s ride-matching logic).
  • Solution: Git’s branching model allows parallel development.

6. Software Engineering Ethics

Ethics in SPM involves moral principles guiding decisions. Key guidelines (ACM/IEEE):

  1. Public: Avoid harm to users (e.g., WhatsApp’s end-to-end encryption protects privacy).
  2. Client/Employer: Honest about project status (e.g., Ncell must disclose network outage causes).
  3. Product: Ensure software is reliable and safe (e.g., eSewa’s fraud detection system).
  4. Profession: Uphold integrity (e.g., not falsifying test results for NEPSE’s trading software).
  5. Colleagues: Respect teamwork (e.g., sharing knowledge in Agile retrospectives).

Example:

  • Conflict: A Daraz developer discovers a security flaw in the payment gateway but risks losing their job if reported.
  • Solution: Follow ethical guidelines to disclose internally, using SCM to trace the issue.

7. Exam Tip: How to Score Full Marks

  1. COCOMO Questions:

    • Always show formulas and step-by-step calculations.
    • Label modes (Organic/Embedded) clearly.
    • Example: For a 100 KLOC project in Organic mode:
  2. Risk Management:

    • Use a table to classify risks (technical, external, etc.).
    • Describe mitigation strategies with real examples (e.g., "Ncell mitigates power outage risks by using backup generators").
  3. Agile vs. Waterfall:

    • Compare 3 key differences (e.g., flexibility, documentation, customer involvement).
    • Use Nepali examples: "eSewa uses Agile for rapid updates, while NTC’s fiber network uses Waterfall for phased deployment."
  4. Ethics:

    • Relate to ACM/IEEE codes and real scenarios (e.g., "A developer at Khalti must report a data breach to comply with public ethics").
  5. Diagrams:

    • Draw mermaid sequenceDiagrams for Agile sprints or risk matrices.
    • Label all components (e.g., "Product Owner → Sprint Planning → Dev Team").

sequenceDiagram
    participant User
    participant ProductOwner
    participant ScrumMaster
    participant DevTeam
    User->>ProductOwner: Prioritizes backlog (user stories)
    ProductOwner->>ScrumMaster: Defines sprint goals
    ScrumMaster->>DevTeam: Sprint Planning (2-week cycle)
    loop Daily
        DevTeam->>ScrumMaster: Standup (3 questions: What did I do? What will I do? Blockers?)
    end
    DevTeam->>DevTeam: Develops increment
    DevTeam->>ProductOwner: Sprint Review (demo)
    ProductOwner->>DevTeam: Feedback
    DevTeam->>ScrumMaster: Retrospective (process improvements)

In the real world

  • eSewa’s Digital Payments: Used Agile sprints to iteratively develop features like QR code payments, adapting to Nepal Rastra Bank’s evolving regulations mid-project.
  • Ncell’s Network Outage Risk Management: Applied qualitative risk assessment to predict fiber cable failures (e.g., NTC’s 2023 Kathmandu–Pokhara backbone) by analyzing historical weather data and maintenance logs.
  • Daraz’s Inventory System: Leveraged COCOMO-like estimation to forecast team size for integrating with third-party logistics (e.g., Nabil Bank’s warehouse automation), adjusting for seasonal demand spikes like Dashain.

Based on the TU BSc CSIT syllabus for Software Engineering (CSC364), unit 10.

Discussion

Loading…