
Today, many companies allow their employees to work from anywhere, which has changed how employees coordinate their work and align toward the same goals. Objectives and Key Results (OKRs) is a goal-setting framework applied in such distributed settings. This research aimed to investigate how OKRs are used in large-scale agile contexts. We interviewed team members and analyzed documents, including a survey. Our study's results provide both enabling and limiting situations that make team members' utilization of the framework either easier or more difficult. We found that OKRs aided knowledge sharing and improved transparency between teams. We present four strategies used for overcoming challenges and maximizing the benefits of using a goal-setting framework. An important takeaway is that companies that employ OKRs must support their employees, especially in defining key outcomes that align and encourage teams toward a common goal.
The purpose of this paper is to advance the idea that corporations can be regarded as artificial cognitive entities. Viewed as black boxes, corporations can be seen as widely and frequently regulated, regarded, and active in the same ways as conscious, thinking human beings. Viewed as white boxes, corporations can be seen to incorporate structures and functions analogous to those in the human mind that give rise to awareness and cognition, and they may possess other features that contribute to the realization of cognition in ways not found in humans. While there are certainly differences between humans and corporations in the basis and expression of cognition, the study of cognition in corporations is interesting and instructive and can be pursued as a field of inquiry in its own right. The relevance of software and systems process to corporate cognition is fundamental. Put directly, cognition is a process and corporate cognition is programmable. Thus, what we know from software engineering, process programming, and software and systems process engineering should be directly applicable to the programming (broadly construed) of corporate cognitive systems. An assessment framework such as CMMI (perhaps with a grounding on key cognitive capabilities) should remain broadly applicable to corporate cognitive processes and should serve as a guide to applying best practices in an organization. The study of corporations as artificial cognitive entities should lead to results of scientific interest and practical consequence in many areas, including codification and quantification of measures of corporate cognition, better understanding of corporate cognitive mechanisms, identification of best cognitive practices for corporations, broadening of the discipline of cognitive science, and opportunities for synergism with artificial intelligence applications in corporations. The results may be broadly applicable in society in areas of regulation; investing; employment; business contracting, mergers, and acquisitions; and with respect to ESG (Environmental, Social, and Governance) concerns.
This paper presents the lessons learned, and the observations and insights gained, from observing a software development effort for a large, well-funded, and highly regulated program that adopted Agile and DevSecOps principles during a 12-month period of iterative software development. The program was originally set up to use the waterfall software development approach with a traditional earned value (EV) scheme. It completed several iterations of development using this structure. The program then shifted to using a combination of Agile and DevSecOps. In this paper, we describe challenges encountered during this transition that inhibited realization of some of the benefits associated with Agile and DevSecOps. Largely, these challenges were a result of poor planning, engineering, and communication. We present this advisory account to others undertaking similar DevSecOps and Agile transitions, particularly in large organizations, so that they may better strategize and prepare methods to diminish similar shortcomings and increase the odds of a successful transition.
Companies often combine agile and plan-based methods to so-called hybrid development approaches to benefit from the advantages of both. Recent research highlights conflicts introduced when combining agile and plan-based approaches in the different phases of the software lifecycle. For example, using both agile and plan-based methods during the requirements engineering of a project requires a decision on how many requirements should be gathered up-front and how many can be gathered during the runtime of a project. These conflicts need to be solved in order to construct a successful development approach. In order to investigate why the conflicts exist, how they are addressed in industry, and how they are related to each other, we performed a multi-case interview study with 15 practitioners. Our results reveal that the conflicts exist because companies use plan-based approaches to structure their agile development and define spaces of freedom and flexibility at the same time. From this insight and our results, we derive a theory that shows how companies structure their development stepwise by defining frames.
Software systems have become an integral part of our daily lives. However, users tend to forget that they are not only consuming information, but also delivering personal information to service providers. This data collection means that users' privacy sphere is increasingly at stake. Informing users about what and how data is collected is pivotal for reaching transparency, trustworthiness, and ethics in modern systems. The main purpose of privacy policies is to inform users about what happens to their personal data. But instead they are extensive and purposefully obfuscating. Information about data practices are hidden in long and ambiguous text passages. To mitigate this, in this paper, we present a concept implemented as a web extension to support the end-user in dealing with privacy policies by providing easier access and visual explanations to privacy-related information. We evaluated the usefulness of our tool in a user study with 65 participants. The results show that our approach helps users to find a privacy policy faster and also supports users to better comprehend the relevant information. Our tool is a first step towards facilitating to deal with privacy policies from the end-user perspective. The results of the study and the positive feedback from the participants show a high degree of acceptance and potential for the tool to increase users' privacy awareness.
The software industry needs universities to train developers to have besides the technical skills, also strong soft skills to collaborate in globally distributed software development projects. To develop these soft skills, we organized a distributed online software development project course, during which student Scrum teams of 5–8 members from five Belarusian universities worked in industrial projects for Danish customers. The course aimed to 1) teach students the Scrum framework and soft skills, such as teamwork and communication with international customers; and 2) to give Belarusian teachers ideas for organizing similar courses in the future. Based on 20 post-course semi-structured interviews with students and stakeholders, and the analysis of 24 student learning diaries we studied the learning outcomes and challenges related to soft skills. The main reported learning outcomes were: communication, methodical use of Scrum, problem solving, organizational/planning skills, teamwork, interpersonal skills, and time management.
Companies are misled into thinking they solve their security issues by using tooling that is advertised as aligning with DevSecOps principles. This paper aims to answer the question: Could the misuse of the DevOps pipeline subject applications to malicious behavior? To answer the question, we designed a typical DevOps pipeline utilizing Kubernetes (K8s) as a case study environment and analyzed the applicable threats. Then, we developed four attack scenarios against the case study environment: maliciously abusing the user’s privilege of deploying containers within the K8s cluster, abusing the Jenkins instance to modify files during the continuous integration, delivery, and deployment systems (CI/CD) build phase, modifying the K8s DNS layer to expose an internal IP to external traffic, and elevating privileges from an account with create, read, update, and delete (CRUD) privileges to root privileges. The attacks answer the research question positively: companies should design and use a secure DevOps pipeline and not expect that utilizing software ”advertised as aligning” with DevSecOps principles alone is sufficient to deliver secure software.
Eldorado is an R&D Institute responsible for OS customization for Android Smartphone Software worldwide. Eldorado is based in Brazil and works closely with other teams worldwide (China, United States, and India). Handling the project management considering this complex GSD scenario brings many challenges, one of them is the knowledge sharing on new development processes. As each region has its own set of procedures and specific carriers, the newcomers need to learn the new working processes. Even having a Wiki space to share information, the members report great difficulty using it, especially when they start to work on a project from a different region. For this reason, we developed a labeling-oriented project management approach based on identifying and defining project patterns. This experience report describes how we reduced the knowledge information required to manage a mobile software development process, the lessons learned applying the developed approach in mobile projects, and the future steps to improve it.
Startups play a key role in software-based innovation. They make an important contribution to an economy's ability to compete and innovate, and their importance will continue to grow due to increasing digitalization. However, the success of a startup depends primarily on market needs and the ability to develop a solution that is attractive enough for customers to choose. A sophisticated technical solution is usually not critical, especially in the early stages of a startup. It is not necessary to be an experienced software engineer to start a software startup. However, this can become problematic as the solution matures and software complexity increases. Based on a proposed solution for systematic software development for early-stage startups, in this paper, we present the key findings of a survey study to identify the methodological and technical priorities of software startups. Among other things, we found that requirements engineering and architecture pose challenges for startups. In addition, we found evidence that startups' software development approaches do not tend to change over time. An early investment in a more scalable development approach could help avoid long-term software problems. To support such an investment, we propose an extended model for Entrepreneurial Software Engineering that provides a foundation for future research.
Repairing software models may be a laborious task, as the number of alternatives that must be considered by engineers can be large. This is more evident in collaborative environments, where the stream of changes applied to models by different engineers is constant and unanticipated. These changes can cause multiple inconsistencies that must be fixed while preserving the changes applied. However, performing this task is not trivial, as analyzing the changes and the possible large amount of repair alternatives requires time and effort. In this work, we present an approach that aids this repair process by analyzing the stream of changes (i.e., history of changes) while exploring repair alternatives alongside their side effects. The approach generates repairs for inconsistencies identified in the model. These repairs are explored by simulating their execution while re-analyzing the model to find potential new inconsistencies created. Then, new repairs are generated to fix these new inconsistencies. This cycle repeats until the model reaches a consistent state or until repairs can no longer be generated. The approach also analyzes conflicts between repairs and changes. This analysis brings valuable information to engineers regarding how each repair alternative would impact their models and may conflict with changes as well as other repairs. We evaluated our approach in a set of 11 UML models that contain a history of changes. Our findings show how our approach can be applied in a variety of models with a different number of model elements and inconsistencies within a reasonable amount of time.
Continuous deployment has become a widely used practice in web-based software applications. Deploying a new software version to production is a seamless automated process executed thousands of times per day. Continuous deployment reduces the time between a code commit and that commit is active in production. While continuous deployment promises many advantages to software development organizations, the adoption of continuous deployment in the software-intensive embedded systems industry is limited. Several empirical studies have highlighted the challenges associated with software-intensive embedded systems. However, very few studies, if any at all, have attempted to provide a practical approach to realize continuous deployment to these systems. This paper proposes a Controlled Continuous Deployment (CCD) approach, which considers the constraints software-intensive embedded systems have, such as high reliability and availability requirements, limited possibility for rollback after deployment, and the high volume of in-service systems in the market. We derived the approach by conducting a case study at Ericsson AB, focusing on three Radio Access Networks (RAN) technologies embedded software used in 3G, 4G, and 5G mobile networks.
The COVID-19 pandemic introduced several changes in the work environment. The main change was the adoption of remote work by software development teams around the globe. This change was significant within the mobile software development field because of its dependency on physical devices to perform tests. Therefore, some companies adopted remote access tools to address this issue, where developers can handle devices online through a server. In this sense, the present work surveyed 62 developers at SIDIA R&D Institute, located in Manaus, Brazil, regarding the usefulness of mobile access tools. The results show that the tools are helpful (62% of employees found them very helpful), even though some developers still prefer to use the physical devices while working from the office. However, the tool promoted collaboration between developers, where users would frequently add new devices to be accessed by others remotely. Thus, although remote access tools cannot replace physical devices, mobile software developers consider them a welcome addition.
Model-based systems engineering (MBSE) can address many challenges of modern systems development. However, due to its comprehensive coverage, process maturity improvement can take many directions, potentially leading to sub-optimal solutions. Therefore, selecting disciplines most aligned to the development team context and goal is key to higher returns on investment. This research aims to relate goals driving MBSE process maturity improvement and candidate capabilities, thus, providing recommendations that highest yield the expected benefits. For this means, we propose a goal-benefit model and respective operationalization method. The model relates MBSE capabilities with benefits generated upon implementation and process improvement goals. Our approach results in a list of MBSE capabilities prioritized according to the improvement goal. The approach was applied to eight development teams located in Germany and Brazil. We also provide a sensitivity analysis to validate the model. The approach was assessed positively by the case study participants, who stated that it provides a starting ground for process maturity improvement efforts.
Quality aspects such as ethics, fairness, and transparency have been proven to be essential for trustworthy software systems. Explainability has been identified not only as a means to achieve all these three aspects in systems, but also as a way to foster users' sentiments of trust. Despite this, research has only marginally focused on the activities and practices to develop explainable systems. To close this gap, we recommend six core activities and associated practices for the development of explainable systems based on the results of a literature review and an interview study. First, we identified and summarized activities and corresponding practices in the literature. To complement these findings, we conducted interviews with 19 industry professionals who provided recommendations for the development process of explainable systems and reviewed the activities and practices based on their expertise and knowledge. We compared and combined the findings of the interviews and the literature review to recommend the activities and assess their applicability in industry. Our findings demonstrate that the activities and practices are not only feasible, but can also be integrated in different development processes.
Engineering artifacts share interdependent properties, which must be kept consistent during the engineering process. Existing works propose the unification of heterogeneous artifacts in a single collaborative engineering environment where artifacts are analysed for consistency. The work presented in this paper expands such environments by adopting hierarchically organized work areas storing artifact changes. Engineers are provided with a unique perspective on their engineering artifacts, which is immediately checked for consistency whenever new changes are made within the hierarchy.
Agile methodology has been a trending topic over the past two decades. Organizations are establishing agile transformation programs to reap its benefits, and cope with the everchanging business and technology landscape. Yet, making sense of the manifold domains contributing to the success of an agile transformation, and orchestrating them with a great synergy is not a simple task. To navigate in this complexity and establish roadmaps, organizations primarily need to understand where they stand. There are a multitude of Agile Assessment Models (AAM) that are designed with the intent of identifying the state of an agile transformation in an organization. Designing an AAM is a valuable step towards this need, however, such models tend to lack vital aspects. Although “What” is needed seems straightforward, in our research, we are trying to focus on “Why” lacking aspects are vital, and “How” to enable effective and efficient value creation through Agility.
As the trend of interest in DevOps continues to rise significantly among industry practitioners, so does the need for software development organisations to understand how to successfully implement DevOps as they are faced with a wide range of choices, and very few guidelines on how to navigate through a plethora of valuable information.An important question is the skillset required, and its role in the determination of suitable DevOps implementation strategy for organisations. This study contributes to the above and provides insight by critically investigating the DevOps implementation of 14 organisations through interviews with practitioners who lead the transformation in these organisations. Interviews were transcribed, coded and analysed by a method informed by Grounded Theory. We identified six strategies used by organisations to implement DevOps, which we named Platform, Greenfield Application, Monolith Decomposition, Process Improvement, Cultural Improvement, and Advocacy. Based on our analysis, we conclude the following: 1. A striking correlation exists between the skillset and the strategy adopted by organisations to implement DevOps. 2. The inclination of an organisation towards upskilling is relevant for the determination of appropriate DevOps implementation strategy. From our research, we have come to believe that the choice of organisational DevOps implementation strategy should generally be based on a consideration of technologies, processes, culture, and skillsets as top-level concerns.
Software innerSourcing has been attracting attention over the past decade in terms of procuring human resources. It can make any employee become a member of all projects in the company by adopting an Open Source Software (OSS) development style. For encouraging healthy employee participation on software innerSourcing, it is important to understand what motivates them. This report creates a visual model using the iStar framework, a goal and actor-oriented modeling methodology, to develop an understanding of employee motivation for software innerSourcing. We interview six employees who participated in one web application development project via software innerSourcing. We then create iStar models based on the interview results. They can be used to explain what motivates employees to use their time for other projects in software innerSourcing.
Engineering projects typically involve many engineers who work concurrently on a multitude of engineering artifacts such as requirements, models, code, or even non-software artifacts, e.g., drawings or computations. These projects require tight collaboration within and across engineering disciplines in order to guarantee a consistent engineering process. Existing collaborative engineering tools provide limited functionality in this regard. Inconsistencies among engineering artifacts are currently identified only after all involved engineers merge their artifacts. This is problematic because considerable amount of time may elapse between these merges and engineers inadvertently may spend considerable time working under wrong/changed assumptions. This leads to more inconsistencies. This paper proposes an approach for checking the consistency of the engineers' artifacts against the continuously evolving, timestamped version history of a public artifact storage. This avoids costly reworks as engineers understand the implications of their work long before they merge their engineering artifacts. To evaluate our work, we conducted an empirical study utilizing the proposed approach.
Video games have become the most dominant and successful entertainment industry worldwide; however, many video game development (VGD) projects and studios struggle to succeed. At present, there are no commonly accepted VGD best practices or frameworks that can bring together the complex and competing needs of software engineering and creative production. Although studios are reportedly using agile frameworks, the actual extent of application and effectiveness of agile practices in the VGD context is unclear. Therefore, the aim of this study is to empirically determine how and why agile frameworks are applied in VGD. Semi-structured interviews were conducted with eight New Zealand VGD studios. It was found that the agile frameworks, Scrum and Kanban, must often be adapted from their conventional use to meet the needs of different pipelines and delivery milestones within the phases of VGD. However, it seems that not all the needs of VGD can be met by current agile frameworks. Furthermore, inexperience with agile practices often leads to misunderstanding and misimplementing them in ways that seem to contribute to commonly experienced collaboration challenges.