Project portfolio management (PPM) goes beyond rational calculative methods, due to its complex environment. In fact, organizations struggle in successfully implementing portfolios despite significant efforts in tools, methodologies, and processes. Imperfect rationality of project portfolio decision-makers in their perspective of the environment reduces project portfolio implementation success. The article examines how sharing knowledge increases decision-makers' rationality and improves PPM strategic decisions. Based on literature investigation, the authors develop a conceptual model that illustrates PPM and the relationship between knowledge sharing (KS) and PPM quality and success. This work enriches knowledge management (KM) theory, positions KS as a strategic mechanism for portfolio effectiveness, expands the PPM definition, and provides a new conceptual foundation for project portfolio theory.
Evolving technologies urge IT workers to keep up with the latest developments, leading to psychological and behavioral consequences (aka technostress). This study aims at investigating the impact of technostress on workarounds performed by software engineers and the moderating roles of neutralization, autonomy, and behavioral controls. Drawing from theories of stress and coping, stress-strain-outcome, and planned behavior, we apply structural equation modeling to survey data of 306 software engineers. Findings reveal that complexity, overload, and invasion, which are dimensions of technostress, are significant to strain, which is in turn significant to workarounds, whereas overload and insecurity, which are further dimensions of technostress, directly impact workarounds. Furthermore, the results report a moderating role of neutralization and autonomy on the impact of overload and a moderating role of autonomy on the impact of overload and insecurity, whereas behavioral control only moderates the impact of strain. The study extends the understanding of technostress in the context of software engineering workarounds.
Background: Recent statistics reveal that 56% of software attacks are caused by insider negligence and 26% are caused by malicious insiders. They also show that 67% of organizations experience at least 21 incidents per year. Most of these incidents require significant time and effort to contain them. In this re-gard, ensuring compliance with corporate policies, regulations, and industry best practices is paramount.Purpose: This study investigates software compliance requirements, factors, and policies together with the challenges they address. By taking a wider perspective, this study aims at bringing an understanding of existing research foci, evolving issues, and research directions.Method: The study uses a systematic literature review and keyword analysis, to identify relevant studies that address the derived research questions. Considering scholarly articles published in the last decade, 4,772 results were retrieved and checked through an initial screening. A thorough screening is then con-ducted to further reduce the results to 77 primary articles.Findings: The requirement on security of end users is gaining more attention. There is an emphasis on the gap between domain and compliance experts on the one side and software engineers on the other side. The review also identified 55 factors (and their underlying theories) that impact behavioral com-pliance with a majority of them focusing on individuals. Our results also list nineteen policies and com-pliance challenges they address. No distinction is found between open-source and proprietary software among the reviewed studies. The most mentioned policies are security education, training, and awareness (SETA), compliance automation, and organizational climate. The evolving topics in the field are: theory of workarounds, compliance and privacy by design, policy as code, security stress, and home-office users.Implications: The review provides 9 recommendations, comprising practical implications for decision makers, theoretical implications for future research, and potential enhancement of the underlying the-ories.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
Containerization technology helps achieving not only better portability and interoperability but also better performance and efficiency on various cloud computing arrangements. Such technology is expected to empower cloud federations by enhancing portability and scalability across the federation. In this paper, we propose an architecture by adding two subcomponents to the NIST reference architecture for identifying resources and managing container orchestration in cloud federation environments. The architecture adds two subcomponents to the NIST reference architecture. The proposed two new sub-components enable resource identification and container orchestration across cloud federation members. These names of the two subcomponents are the Resource Identifier and the Container Orchestrator, respectively. The Resource Identifier component identifies the appropriate federated member for allocating tasks based on previous experience and current status. The Container Orchestrator facilitates the management and orchestration of containers at the federation level. We also identified several techniques, which can be used for resource identification. Among those, linear regression technique is selected for resource provisioning and identification of federation members. Further, these techniques are also expected to learn from log files from previous executions and prioritize resources based on the current resource status and previous experience.
According to the laws of software evolution, the size and complexity of software systems continue to increase over time and, simultaneously, if not maintained rigorously, the quality decreases. Quality degradation typically happens due to changes in policies, regulations, and industry requirements, which, in turn, complicates compliance management over time. Among the key challenges in managing the evolution of software are the modelling and the enforcement of compliance rules. Moreover, the gap between compliance experts and software engineers has worsened the problem. The topology and orchestration specifications for cloud applications (TOSCA), which is an OASIS standard, has the potential to offer a relief by enabling different levels of abstractions for modeling and enforcing compliance policies. This work aims at investigating the potential of using TOSCA service templates for modelling and enforcing non-functional requirements and policies. Then, it proposes an approach that maximizes involvement of stakeholders in modeling and auditing such requirements and policies. Findings can help enterprises and policy makers achieve better governance and compliance on software services.
This paper proposes an architecture for artificial-intelligence-based container orchestration in cloud federation environments. The paper adapts the architecture proposed by Kurze et al. [1] and enhances it with two subcomponents in the federation layer to enable resource identification and container orchestration across cloud federation members. These two subcomponents are the AI Resource Identifier and the Container Orchestrator. The AI Resource Identifier is responsible for identifying the available resource in the federated environment whenever needed. It optimizes resource allocation of federation members by using Artificial Intelligence (AI) techniques for learning from the past. The Container Orchestrator sub-component is responsible for organizing jobs to be allocated along with all the necessary files and dependencies in a containerized way. This, in turn, enhances scalability and portability in a federated environment.
. With the emergence of new software development paradigms (e.g., distributed teams and crowd-sourcing), the software supply chain became more complicated than ever. This, in turn, raises concerns in software compliance in many industries, as ensuring adherence beyond functional requirements is very critical. This paper uses a systematic literature review, to investigate the frameworks used for managing compliance of software and software services and their applications across different industries. The review also looked into industry-specific software compliance requirements. A total of 156 primary studies have been collected, of which 63 studies match the criteria indicated in the review protocol. The study develops a classification of these frameworks based on industry-specific needs, business requirements, and the context of compliance. Findings of this research help researchers and practitioners to identify important aspects of software compliance and set directions for future research and development.
Purpose - Many countries nowadays look at cloud computing as an opportunity because it holds great advantages for governments. Public sector in Yemen...