Software EngineeringUnit 1015 min read

Project Mgmt & Quality: Plans, Metrics, Risks & Standards

Unit 10 of Software Engineering covers project management frameworks (Agile, Waterfall, Hybrid), quality models (ISO/IEC 25010, CMMI), risk management, cost/schedule estimation, and quality assurance techniques—with real-world examples from Nepali and global tech companies.

TAKEAWAYS:

  • Project management uses frameworks like Waterfall (sequential) and Agile (iterative) to plan, execute, and deliver software projects efficiently.
  • Quality management relies on standards (ISO 25010) and models (CMMI) to ensure software meets functional and non-functional requirements.
  • Risk management identifies, analyzes, and mitigates risks (technical, schedule, budget) using techniques like SWOT and risk matrices.
  • Cost and schedule estimation uses methods like COCOMO and PERT to predict project timelines and budgets accurately.
  • Quality assurance (QA) involves reviews, testing, and metrics (defect density, cyclomatic complexity) to maintain software reliability.
  • Tools and techniques (e.g., Gantt charts, Kanban boards, defect tracking) help track progress and ensure quality in real-world projects.

1. Software Project Management

Software project management (SPM) is the application of knowledge, skills, tools, and techniques to plan, execute, and deliver software projects within constraints like time, cost, and quality. It ensures projects are completed successfully while meeting stakeholder expectations.

1.1 Project Management Frameworks

Different frameworks guide how projects are structured and executed. The two most common are:

Framework Description When to Use Advantages Disadvantages
Waterfall Linear, sequential approach (requirements → design → implementation → testing → maintenance). Projects with clear, stable requirements. Simple, easy to manage. Inflexible; late changes are costly.
Agile Iterative and incremental (work in sprints, adapt to changes). Dynamic projects with evolving requirements. Flexible, customer feedback early. Requires disciplined teams; documentation can lag.
Hybrid (e.g., V-Shaped, Spiral) Combines Waterfall and Agile (e.g., V-Shaped adds testing phases in parallel). Large projects needing structure but some flexibility. Balances stability and adaptability. Complex to manage; requires expertise.

1.2 Work Breakdown Structure (WBS)

A WBS breaks down a project into smaller, manageable tasks. It helps in:

  • Estimating time and cost.
  • Assigning responsibilities.
  • Tracking progress.

Example (Nepali Context): Suppose Nepal Electricity Authority (NEA) is developing a new billing system. The WBS might look like this:

Requirements GatheringDatabase DesignUI/UX DesignSystem DesignFrontend (React)Backend (Node.js)API IntegrationDevelopmentUnit TestingIntegration TestingUser Acceptance TestingTestingDeploymentMaintenanceNEA Billing System Project
Hierarchical WBS for NEA Billing System (Nepali context)

1.3 Gantt Charts and Critical Path Method (CPM)

  • Gantt Charts: Visualize project timelines, dependencies, and progress.
  • CPM: Identifies the longest path of tasks (critical path) to determine project duration.

Example (Pathao Driver App): Pathao’s app development might have dependencies like:

  1. User authentication → 2. Ride booking → 3. Payment integration → 4. Driver matching. If payment integration is delayed, the entire project timeline shifts.
gantt
    title Pathao App Development Timeline
    dateFormat  YYYY-MM
    section Planning
    Requirements Gathering :a1, 2023-01-01, 2023-01-15
    section Design
    UI/UX Design :design, after a1, 30d
    Database Schema :db, after a1, 20d
    section Development
    Frontend :frontend, after design, 45d
    Backend :backend, after db, 60d
    API Integration :api, after frontend, 20d
    section Testing
    QA Testing :qa, after api, 30d
    section Deployment
    Launch :launch, after qa, 10d

2. Software Quality Management

Quality management ensures software meets functional (what it does) and non-functional (performance, security, usability) requirements.

2.1 Quality Models

Model Description Key Metrics
ISO/IEC 25010 Standard for software product quality (functional suitability, reliability, usability, etc.). Defect density, mean time between failures (MTBF).
CMMI (Capability Maturity Model Integration) Maturity levels (1-5) for process improvement. Process maturity, defect prevention rate.
McCabe’s Cyclomatic Complexity Measures code complexity (higher = harder to test/maintain). Cyclomatic complexity score (V(G)).

Example (Khalti Payment System): Khalti must ensure:

  • Functional Quality: Correct transaction processing.
  • Non-Functional Quality: Fast response time (<2s), 99.9% uptime, secure encryption (PCI-DSS compliance).

2.2 Quality Assurance (QA) Techniques

Technique Description When to Use
Reviews (Fagan Inspection) Peer reviews to catch defects early. Code reviews, design walkthroughs.
Static Testing Analyzing code without execution (e.g., linting). Early development phases.
Dynamic Testing Executing code to find defects (unit, integration, system testing). Before release.
Defect Tracking Tools like Jira, Bugzilla to log and track fixes. Throughout development.

Example (Daraz Order Fulfillment System):

  • Static Testing: Check if the order processing logic handles edge cases (e.g., out-of-stock items).
  • Dynamic Testing: Simulate 10,000 concurrent users to test scalability.

2.3 Quality Metrics

Metric Formula Interpretation
Defect Density Total Defects / Size (LOC or FP) Lower = better quality.
Mean Time Between Failures (MTBF) Total Time / Number of Failures Higher = more reliable.
Cyclomatic Complexity (V(G)) #Decision Points + 1 <10 = simple; >20 = complex (hard to test).
021.2542.563.7585Defect Density0.5Mean Time to Repair2.1Code Coverage85Customer Satisfaction4.2
Example quality metrics for a software project (hypothetical values)

Example (Ncell App): If the Ncell app has 50 defects in 10,000 lines of code, the defect density is: (Acceptable range: <0.01 defects/LOC).


3. Risk Management in Software Projects

Risk management identifies potential issues and plans responses to minimize their impact.

3.1 Risk Identification and Analysis

Risk Type Example (Nepali Context) Mitigation Strategy
Technical Risk Legacy system integration (e.g., NEA’s old billing system). Use APIs or middleware; incremental migration.
Schedule Risk Delayed government approval (e.g., NEPSE trading system). Buffer time; parallel approval processes.
Budget Risk Cost overruns in hardware (e.g., NTC fiber expansion). Contingency funds; vendor negotiations.
Team Risk Key developer leaves mid-project (e.g., at a startup). Cross-training; backup resources.

3.2 Risk Matrix

A risk matrix prioritizes risks based on probability and impact.

Probability \ Impact Low Medium High
Low Accept Monitor Mitigate
Medium Monitor Mitigate Mitigate
High Mitigate Mitigate Avoid

Example (eSewa Project):

  • Risk: Cyberattack on payment gateway (High probability, High impact) → Mitigation: Implement DDoS protection and regular audits.

3.3 SWOT Analysis for Projects

Strengths Weaknesses
Experienced team (e.g., at Pathao). Limited budget.
Strong stakeholder support (e.g., NTC for fiber project). Regulatory delays (e.g., NEPSE).
StrengthsWeaknessesOpportunitiesThreatsSWOT Analysis for Ncell App Update
SWOT framework applied to a Nepali telecom project
Opportunities Threats
Government incentives (e.g., for digital payments). Competition (e.g., Khalti vs. IME Pay).
Cloud adoption (e.g., AWS for Daraz). Cybersecurity threats.

4. Cost and Schedule Estimation

Accurate estimation ensures projects stay on budget and timeline.

4.1 Estimation Techniques

Technique Description Example
COCOMO (Constructive Cost Model) Estimates effort based on lines of code (LOC). A 10,000 LOC project may take 6 months.
PERT (Program Evaluation and Review Technique) Uses optimistic, pessimistic, and most likely estimates. For a task: (4 + 6 + 8)/3 = 6 weeks.
Analogous Estimation Uses past project data for similar projects. If a similar app took 8 months, estimate 8 months.

Example (Bank Loan Processing System): Using COCOMO: For 5 KLOC: (Assuming 3 developers: 18/3 = 6 months.)

4.2 PERT Example (Ncell App Update)

Task Optimistic (O) Most Likable (M) Pessimistic (P) Expected Time (ET) Variance (σ²)
Backend API Update 2 weeks 3 weeks 4 weeks (2+4*3+4)/6 = 3 weeks (4-2)²/36 = 0.22
Frontend UI Redesign 3 weeks 4 weeks 6 weeks (3+4*4+6)/6 = 4.33 weeks (6-3)²/36 = 0.56
Critical Path 7.33 weeks
53462ABCDE
PERT network diagram for Ncell app update (optimistic durations)

5. Tools for Project and Quality Management

Tool Category Tools Use Case
Project Management Jira, Trello, MS Project Task tracking, Gantt charts.
Quality Assurance SonarQube, Checkmarx Static code analysis.
Defect Tracking Bugzilla, Mantis Logging and fixing bugs.
Version Control Git, GitHub, GitLab Code collaboration.
Estimation COCOMO Calculator, PERT Tools Effort and timeline prediction.

In the Real World

  1. Khalti (Digital Payments)

    • Quality Management: Uses ISO 25010 for security (encryption, PCI-DSS compliance) and CMMI Level 3 for process maturity.
    • Risk Management: Mitigates fraud risks via two-factor authentication (2FA) and real-time transaction monitoring.
    • Project Management: Hybrid model (Agile for app development, Waterfall for compliance documentation).
  2. Pathao (Ride-Hailing App)

    • Cost Estimation: Used COCOMO to estimate the backend system (15 KLOC → ~25 person-months).
    • Quality Assurance: Static testing (SonarQube) to reduce defects before release.
    • Risk Management: SWOT analysis identified "driver shortages" as a threat → solution: referral bonuses.
  3. Nepal Electricity Authority (NEA) Billing System

    • Project Management: Waterfall model (due to strict regulatory requirements).
    • Schedule Estimation: PERT used to account for delays in government approvals.
    • Quality Metrics: Defect density tracked to ensure <0.01 defects/LOC.

Exam Tip

  1. Project Management (30% weight)

    • Know the differences between Waterfall, Agile, and Hybrid (when to use each).
    • Be able to draw a Gantt chart and identify the critical path.
    • Worked Example: Given a scenario (e.g., "Ncell wants to update its app"), explain which framework to use and why.
  2. Quality Management (25% weight)

    • ISO 25010 vs. CMMI: Define key terms (e.g., "reliability," "process maturity").
    • Quality Metrics: Calculate defect density and cyclomatic complexity.
    • QA Techniques: Differentiate between static and dynamic testing.
  3. Risk and Cost Estimation (20% weight)

    • Risk Matrix: Given a scenario, classify risks and suggest mitigations.
    • COCOMO/PERT: Solve numerical problems (e.g., "Estimate effort for a 10 KLOC project").
    • SWOT Analysis: Apply to a real Nepali project (e.g., eSewa, Daraz).
  4. Tools and Standards (15% weight)

    • Name 2 tools for each category (project management, QA, defect tracking).
    • Explain how ISO 25010 applies to a given system (e.g., Khalti’s security).
  5. Case Study (10% weight)

    • Expect a real-world scenario (e.g., "NTC is deploying fiber in Kathmandu"). Answer should include:
      • Framework choice (Agile/Waterfall/Hybrid).
      • Risk analysis (top 3 risks + mitigations).
      • Quality metrics (e.g., uptime goals).
      • Estimation (COCOMO or PERT).

Pro Tip: Always relate answers to Nepali examples (Ncell, Khalti, NEA, Daraz). Examiners love context!

Based on the PU BE Computer (PU) syllabus for Software Engineering (CMP348), unit 10.

Discussion

Loading…