Software EngineeringUnit 1015 min read
Project Mgmt & Quality: Plans, Metrics, Risks & Standards
Unit 10 of Software Engineering covers project management frameworks (Agile, Waterfall, Hybrid), quality models (ISO/IEC 25010, CMMI), risk management, cost/schedule estimation, and quality assurance techniques—with real-world examples from Nepali and global tech companies.
TAKEAWAYS:
- Project management uses frameworks like Waterfall (sequential) and Agile (iterative) to plan, execute, and deliver software projects efficiently.
- Quality management relies on standards (ISO 25010) and models (CMMI) to ensure software meets functional and non-functional requirements.
- Risk management identifies, analyzes, and mitigates risks (technical, schedule, budget) using techniques like SWOT and risk matrices.
- Cost and schedule estimation uses methods like COCOMO and PERT to predict project timelines and budgets accurately.
- Quality assurance (QA) involves reviews, testing, and metrics (defect density, cyclomatic complexity) to maintain software reliability.
- Tools and techniques (e.g., Gantt charts, Kanban boards, defect tracking) help track progress and ensure quality in real-world projects.
1. Software Project Management
Software project management (SPM) is the application of knowledge, skills, tools, and techniques to plan, execute, and deliver software projects within constraints like time, cost, and quality. It ensures projects are completed successfully while meeting stakeholder expectations.
1.1 Project Management Frameworks
Different frameworks guide how projects are structured and executed. The two most common are:
| Framework | Description | When to Use | Advantages | Disadvantages |
|---|---|---|---|---|
| Waterfall | Linear, sequential approach (requirements → design → implementation → testing → maintenance). | Projects with clear, stable requirements. | Simple, easy to manage. | Inflexible; late changes are costly. |
| Agile | Iterative and incremental (work in sprints, adapt to changes). | Dynamic projects with evolving requirements. | Flexible, customer feedback early. | Requires disciplined teams; documentation can lag. |
| Hybrid (e.g., V-Shaped, Spiral) | Combines Waterfall and Agile (e.g., V-Shaped adds testing phases in parallel). | Large projects needing structure but some flexibility. | Balances stability and adaptability. | Complex to manage; requires expertise. |
1.2 Work Breakdown Structure (WBS)
A WBS breaks down a project into smaller, manageable tasks. It helps in:
- Estimating time and cost.
- Assigning responsibilities.
- Tracking progress.
Example (Nepali Context): Suppose Nepal Electricity Authority (NEA) is developing a new billing system. The WBS might look like this:
1.3 Gantt Charts and Critical Path Method (CPM)
- Gantt Charts: Visualize project timelines, dependencies, and progress.
- CPM: Identifies the longest path of tasks (critical path) to determine project duration.
Example (Pathao Driver App): Pathao’s app development might have dependencies like:
- User authentication → 2. Ride booking → 3. Payment integration → 4. Driver matching. If payment integration is delayed, the entire project timeline shifts.
gantt
title Pathao App Development Timeline
dateFormat YYYY-MM
section Planning
Requirements Gathering :a1, 2023-01-01, 2023-01-15
section Design
UI/UX Design :design, after a1, 30d
Database Schema :db, after a1, 20d
section Development
Frontend :frontend, after design, 45d
Backend :backend, after db, 60d
API Integration :api, after frontend, 20d
section Testing
QA Testing :qa, after api, 30d
section Deployment
Launch :launch, after qa, 10d2. Software Quality Management
Quality management ensures software meets functional (what it does) and non-functional (performance, security, usability) requirements.
2.1 Quality Models
| Model | Description | Key Metrics |
|---|---|---|
| ISO/IEC 25010 | Standard for software product quality (functional suitability, reliability, usability, etc.). | Defect density, mean time between failures (MTBF). |
| CMMI (Capability Maturity Model Integration) | Maturity levels (1-5) for process improvement. | Process maturity, defect prevention rate. |
| McCabe’s Cyclomatic Complexity | Measures code complexity (higher = harder to test/maintain). | Cyclomatic complexity score (V(G)). |
Example (Khalti Payment System): Khalti must ensure:
- Functional Quality: Correct transaction processing.
- Non-Functional Quality: Fast response time (<2s), 99.9% uptime, secure encryption (PCI-DSS compliance).
2.2 Quality Assurance (QA) Techniques
| Technique | Description | When to Use |
|---|---|---|
| Reviews (Fagan Inspection) | Peer reviews to catch defects early. | Code reviews, design walkthroughs. |
| Static Testing | Analyzing code without execution (e.g., linting). | Early development phases. |
| Dynamic Testing | Executing code to find defects (unit, integration, system testing). | Before release. |
| Defect Tracking | Tools like Jira, Bugzilla to log and track fixes. | Throughout development. |
Example (Daraz Order Fulfillment System):
- Static Testing: Check if the order processing logic handles edge cases (e.g., out-of-stock items).
- Dynamic Testing: Simulate 10,000 concurrent users to test scalability.
2.3 Quality Metrics
| Metric | Formula | Interpretation |
|---|---|---|
| Defect Density | Total Defects / Size (LOC or FP) | Lower = better quality. |
| Mean Time Between Failures (MTBF) | Total Time / Number of Failures | Higher = more reliable. |
| Cyclomatic Complexity (V(G)) | #Decision Points + 1 | <10 = simple; >20 = complex (hard to test). |
Example (Ncell App): If the Ncell app has 50 defects in 10,000 lines of code, the defect density is: (Acceptable range: <0.01 defects/LOC).
3. Risk Management in Software Projects
Risk management identifies potential issues and plans responses to minimize their impact.
3.1 Risk Identification and Analysis
| Risk Type | Example (Nepali Context) | Mitigation Strategy |
|---|---|---|
| Technical Risk | Legacy system integration (e.g., NEA’s old billing system). | Use APIs or middleware; incremental migration. |
| Schedule Risk | Delayed government approval (e.g., NEPSE trading system). | Buffer time; parallel approval processes. |
| Budget Risk | Cost overruns in hardware (e.g., NTC fiber expansion). | Contingency funds; vendor negotiations. |
| Team Risk | Key developer leaves mid-project (e.g., at a startup). | Cross-training; backup resources. |
3.2 Risk Matrix
A risk matrix prioritizes risks based on probability and impact.
| Probability \ Impact | Low | Medium | High |
|---|---|---|---|
| Low | Accept | Monitor | Mitigate |
| Medium | Monitor | Mitigate | Mitigate |
| High | Mitigate | Mitigate | Avoid |
Example (eSewa Project):
- Risk: Cyberattack on payment gateway (High probability, High impact) → Mitigation: Implement DDoS protection and regular audits.
3.3 SWOT Analysis for Projects
| Strengths | Weaknesses |
|---|---|
| Experienced team (e.g., at Pathao). | Limited budget. |
| Strong stakeholder support (e.g., NTC for fiber project). | Regulatory delays (e.g., NEPSE). |
| Opportunities | Threats |
|---|---|
| Government incentives (e.g., for digital payments). | Competition (e.g., Khalti vs. IME Pay). |
| Cloud adoption (e.g., AWS for Daraz). | Cybersecurity threats. |
4. Cost and Schedule Estimation
Accurate estimation ensures projects stay on budget and timeline.
4.1 Estimation Techniques
| Technique | Description | Example |
|---|---|---|
| COCOMO (Constructive Cost Model) | Estimates effort based on lines of code (LOC). | A 10,000 LOC project may take 6 months. |
| PERT (Program Evaluation and Review Technique) | Uses optimistic, pessimistic, and most likely estimates. | For a task: (4 + 6 + 8)/3 = 6 weeks. |
| Analogous Estimation | Uses past project data for similar projects. | If a similar app took 8 months, estimate 8 months. |
Example (Bank Loan Processing System): Using COCOMO: For 5 KLOC: (Assuming 3 developers: 18/3 = 6 months.)
4.2 PERT Example (Ncell App Update)
| Task | Optimistic (O) | Most Likable (M) | Pessimistic (P) | Expected Time (ET) | Variance (σ²) |
|---|---|---|---|---|---|
| Backend API Update | 2 weeks | 3 weeks | 4 weeks | (2+4*3+4)/6 = 3 weeks | (4-2)²/36 = 0.22 |
| Frontend UI Redesign | 3 weeks | 4 weeks | 6 weeks | (3+4*4+6)/6 = 4.33 weeks | (6-3)²/36 = 0.56 |
| Critical Path | 7.33 weeks |
5. Tools for Project and Quality Management
| Tool Category | Tools | Use Case |
|---|---|---|
| Project Management | Jira, Trello, MS Project | Task tracking, Gantt charts. |
| Quality Assurance | SonarQube, Checkmarx | Static code analysis. |
| Defect Tracking | Bugzilla, Mantis | Logging and fixing bugs. |
| Version Control | Git, GitHub, GitLab | Code collaboration. |
| Estimation | COCOMO Calculator, PERT Tools | Effort and timeline prediction. |
In the Real World
Khalti (Digital Payments)
- Quality Management: Uses ISO 25010 for security (encryption, PCI-DSS compliance) and CMMI Level 3 for process maturity.
- Risk Management: Mitigates fraud risks via two-factor authentication (2FA) and real-time transaction monitoring.
- Project Management: Hybrid model (Agile for app development, Waterfall for compliance documentation).
Pathao (Ride-Hailing App)
- Cost Estimation: Used COCOMO to estimate the backend system (15 KLOC → ~25 person-months).
- Quality Assurance: Static testing (SonarQube) to reduce defects before release.
- Risk Management: SWOT analysis identified "driver shortages" as a threat → solution: referral bonuses.
Nepal Electricity Authority (NEA) Billing System
- Project Management: Waterfall model (due to strict regulatory requirements).
- Schedule Estimation: PERT used to account for delays in government approvals.
- Quality Metrics: Defect density tracked to ensure <0.01 defects/LOC.
Exam Tip
Project Management (30% weight)
- Know the differences between Waterfall, Agile, and Hybrid (when to use each).
- Be able to draw a Gantt chart and identify the critical path.
- Worked Example: Given a scenario (e.g., "Ncell wants to update its app"), explain which framework to use and why.
Quality Management (25% weight)
- ISO 25010 vs. CMMI: Define key terms (e.g., "reliability," "process maturity").
- Quality Metrics: Calculate defect density and cyclomatic complexity.
- QA Techniques: Differentiate between static and dynamic testing.
Risk and Cost Estimation (20% weight)
- Risk Matrix: Given a scenario, classify risks and suggest mitigations.
- COCOMO/PERT: Solve numerical problems (e.g., "Estimate effort for a 10 KLOC project").
- SWOT Analysis: Apply to a real Nepali project (e.g., eSewa, Daraz).
Tools and Standards (15% weight)
- Name 2 tools for each category (project management, QA, defect tracking).
- Explain how ISO 25010 applies to a given system (e.g., Khalti’s security).
Case Study (10% weight)
- Expect a real-world scenario (e.g., "NTC is deploying fiber in Kathmandu"). Answer should include:
- Framework choice (Agile/Waterfall/Hybrid).
- Risk analysis (top 3 risks + mitigations).
- Quality metrics (e.g., uptime goals).
- Estimation (COCOMO or PERT).
- Expect a real-world scenario (e.g., "NTC is deploying fiber in Kathmandu"). Answer should include:
Pro Tip: Always relate answers to Nepali examples (Ncell, Khalti, NEA, Daraz). Examiners love context!
Based on the PU BE Computer (PU) syllabus for Software Engineering (CMP348), unit 10.
Discussion
Loading…