DevOps is a collection of practices that reduces barriers between development and operations within software organisations, with the aim of increasing product release frequency and reliability. DevOps is increasingly important in the software industry. However, although existing research suggests that organisations face barriers to adoption, there are few case studies of how DevOps is adopted in practice. Therefore many organisations may face challenges in the transition to DevOps and lack guidance from prior experience as to successful strategies for managing the change.This paper presents a case study of DevOps adoption in a software development team within a large financial organisation. The study used a mixed-methods approach of surveys, interviews, and retrospectives to investigate the team’s experience. We collected evidence from 47 team members and document how the team has adopted the different practices. The findings highlight the factors influencing adoption, the benefits realised and the challenges faced. The results provide insights into practitioners’ perspective on DevOps adoption, as well as contributing to the evidence base on this practice in the literature as a basis for future research.
Reflecting upon recent advances in Natural Language Processing (NLP), this paper evaluates the effectiveness of context-aware NLP models for predicting software task effort estimates. Term Frequency–Inverse Document Frequency (TF-IDF) and Bidirectional Encoder Representations from Transformers (BERT) were used as feature extraction methods; Random forest and BERT feed-forward linear neural networks were used as classifiers. Using three datasets drawn from open-source projects and one from a commercial project, the paper evaluates the models and compares the best performing model with expert estimates from both kinds of datasets. The results suggest that BERT as feature extraction and classifier shows slightly better performance than other combinations, but that there is no significant difference between the presented methods. On the other hand, the results show that expert and Machine Learning (ML) estimate performances are similar, with the experts’ performance being slightly better. Both findings confirmed existing literature, but using substantially different experimental settings.
User friendly tools have lowered the requirements of high-quality game design to the point where researchers without development experience can release their own games. However, there is no established best-practice as few games have been produced for research purposes. Having developed a mobile game without the guidance of similar projects, we realised the need to share our experience so future researchers have a path to follow. Research into game balancing and system simulation required an experimental case study, which inspired the creation of"RPGLite", a multiplayer mobile game. In creating RPGLitewith no development expertise we learned a series of lessons about effective amateur game development for research purposes. In this paper we reflect on the entire development process and present these lessons.
Reliable cost effective effort estimation remains a considerable challenge for software projects. Recent work has demonstrated that the popular Planning Poker practice can produce reliable estimates when undertaken within a software team of knowledgeable domain experts. However, the process depends on the availability of experts and can be time-consuming to perform, making it impractical for large scale or open source projects that may curate many thousands of outstanding tasks. This paper reports on a full study to investigate the feasibility of using crowd workers supplied with limited information about a task to provide comparably accurate estimates using Planning Poker. We describe the design of a Crowd Planning Poker (CPP) process implemented on Amazon Mechanical Turk and the results of a substantial set of trials, involving more than 5000 crowd workers and 39 diverse software tasks. Our results show that a carefully organised and selected crowd of workers can produce effort estimates that are of similar accuracy to those of a single expert.
Sciit is a distributed issue tracker. Distributed issue tracking eliminates much of the friction that is otherwise necessitated by separately maintaining source code in a source control management system (SCM) and task information in an issue tracker. Sciit goes beyond the state of the art in distributed issue tracking by treating issues as first class change control items, represented as fragments of text anywhere within the SCM. This approach treats issues as representations of work in progress alongside other project artefacts, allowing much of the metadata about an issue, such as status, affected components and participants to be inferred directly from the state of the SCM, rather than requiring additional maintenance by a developer. (C) 2021 Elsevier B.V. All rights reserved.
This study explores the introduction of agile software development within an avionics company engaged in safety-critical system engineering. There is increasing pressure throughout the software industry for development efforts to adopt agile software development in order to respond more rapidly to changing requirements and make more frequent deliveries of systems to customers for review and integration. This pressure is also being experienced in safety-critical industries, where release cycles on typically large and complex systems may run to several years on projects spanning decades. However, safety-critical system developments are normally highly regulated, which may constrain the adoption of agile software development or require adaptation of selected methods or practices. To investigate this potential conflict, we conducted a series of interviews with practitioners in the company, exploring their experiences of adopting agile software development and the challenges encountered. The study also explores the opportunities for altering the existing software process in the company to better fit agile software development to the constraints of software development for safety-critical systems. We conclude by identifying immediate future research directions to better align the tempo of software development for safety-critical systems and agile software development.
Successful implementation of information security policies (ISP) and IT controls play an important role in safeguarding patient privacy in healthcare organizations. Our study investigates the factors that lead to healthcare practitioners’ neutralisation of ISPs, leading to non-compliance. The study adopted a qualitative approach and conducted a series of semi-structured interviews with medical interns and hospital IT department managers and staff in an academic hospital in Saudi Arabia. The study’s findings revealed that the MIs imitate their peers’ actions and employ similar justifications when violating ISP dictates. Moreover, MI team superiors’ (seniors) ISP non-compliance influences MI’s tendency to invoke neutralisation techniques. We found that trust between medical team members is an essential social facilitator that motivates MI’s to invoke neutralisation techniques to justify violating ISP policies and controls. These findings add new insights that help us to understand the relationship between the social context and neutralisation theory in triggering ISP non-compliance.
The book was inadvertently published with an error in the last name of the second author’s name as Karen Renoud. The spelling of the second author’s name was corrected.
Behaviour driven development (BDD) has gained widespread use in the software industry. System specifications can be expressed as test scenarios, describing the circumstances, actions and expected outcomes. These scenarios are written in a structured natural language (Gherkin), with each step in the scenario associated with a corresponding step implementation function in the underlying programming language. A challenge recognised by industry is ensuring that the natural language scenarios, step implementation functions and underlying system implementation remain consistent with one another, requiring on-going maintenance effort as changes are made to a system. To address this, we have developed behave_nicely, a tool, for automatically generating step implementation functions from structured natural language steps, with the intention of eliminating the need for maintaining step implementation functions. We evaluated our approach on a sample of 20 white box and 50 black box projects using behaviour driven development, drawn from GitHub. Our results show that behave_nicely can generate step implementation functions for 80% of the white box and 17% of black box projects. We conclude that (a) there is significant potential for automating the process of code generation for BDD tests and (b) that the development of guidelines for writing tests in Gherkin would significantly improve the results.
This paper proposes the use of responsibility modelling as a tool to support the process of contingency planning for civil emergencies. Existing contingency planning techniques produce documents which are difficult to analyse for vulnerabilities, particularly across organisational boundaries and are likely to be largely unused during an actual emergency. This paper presents a new approach to contingency planning based on the notion of responsibility modelling combined with HAZOPS analysis of information requirements. Whilst the work described in this paper represents research in progress, the example models presented do illustrate the potential use of responsibility modelling concepts to assist in the contingency planning process.
An increasing number of cybersecurity incidents prompts organizations to explore alternative security solutions, such as threat intelligence programs. For such programs to succeed, data needs to be collected, validated, and recorded in relevant datastores. One potential source supplying these datastores is an organization's security incident response team. However, researchers have argued that these teams focus more on eradication and recovery and less on providing feedback to enhance organizational security. This prompts the idea that data collected during security incident investigations may be of insufficient quality for threat intelligence analysis. While previous discussions focus on data quality issues from threat intelligence sharing perspectives, minimal research examines the data generated during incident response investigations. This paper presents the results of a case study identifying data quality challenges in a Fortune 500 organization's incident response team. Furthermore, the paper provides the foundation for future research regarding data quality concerns in security incident response.
Online discussion platforms can face multiple challenges of abusive behaviour. In order to understand the reasons for persisting such behaviour, we need to understand how users behave inside and outside a community. In this paper, we propose a novel methodology to generate a dataset from offline and online group discussion conversations. We advocate an empirical-based approach to explore the space of abusive behaviour. We conducted a user-study ( N = 15) to understand what factors facilitate or amplify forms of behaviour in cases of online conversation that are less likely to be tolerated in face-to-face. The preliminary analysis validates our approach to analyse large-scale conversation dataset.
This paper presents sciit, a distributed issue tracker. Distributed issue tracking eliminates much of the friction that is otherwise necessitated by separately maintaining source code in a distributed source control management system (SCM) and task information in a centralised issue tracker. Sciit goes beyond the state of the art in distributed issue tracking by treating issues as first class change control items, represented as fragments of text anywhere within the SCM. This approach treats issues as representations of work in progress alongside other project artefacts. This alignment allows much of the meta-data about an issue, such as status, affected components and participants to be inferred directly from the state of the SCM, rather than requiring maintenance of this information by a developer. The paper presents a scenario to illustrate the benefits of sciit and an outline of the tool's architecture.
A key task during software maintenance is the refinement and elaboration of emerging software issues, such as feature implementations and bug resolution. It includes the annotation of software tasks with additional information, such as criticality, assignee and estimated cost of resolution. This paper reports on a first study to investigate the feasibility of using crowd workers supplied with limited information about an issue and project to provide comparably accurate estimates using planning poker. The paper describes our adaptation of planning poker to crowdsourcing and our initial trials. The results demonstrate the feasibility and potential efficiency of using crowds to deliver estimates. We also review the additional benefit that asking crowds for an estimate brings, in terms of further elaboration of the details of an issue. Finally, we outline our plans for a more extensive evaluation of planning poker in crowds.
With the rapid growth of mobile applications and the increase number of mobile users, many cloud storage services started to design stand-alone mobile applications that can be used to access files remotely from mobile and share them. In this paper, an in-depth analysis has been performed on the privacy policies of zero knowledge cloud storage applications on mobile. The analysis includes the type of information collected, collection mechanisms, purpose for collection, sharing of information, user controls and information retention period. The results showed that most privacy policies addressed important areas of information collection, purposes of collection, information sharing and users' controls. On the other hand, many policies lacked detailed information of the data retention period.
In this paper we contend that the engineering of information systems is hampered by a paucity of tools to tractably model, simulate and predict the impact of realistic user behaviours on the emergent properties of the wider socio-technical system, evidenced by the plethora of case studies of system failure in the literature. We address this gap by presenting a novel approach that models ideal user behaviour as workflows, and introduces irregularities in that behaviour as aspects which fuzz the model. We demonstrate the success of this approach through a case study of software development workflows, showing that the introduction of realistic user behaviour to idealised workflows better simulates outcomes reported in the empirical software engineering literature.
Voter-verifiable voting systems place significant demands of both effort and knowledge onto ordinary voters who have only limited incentives to participate. We suggest the use of third-party verifiable voting systems, harnessing the very strong incentives for candidates and observers to verify that votes are correctly counted. A generic modification enabling this via the use of pre-filled ballots and secure depositing is outlined and we demonstrate this modification by applying it to two major voter-verifiable voting systems. Additionally, potential vulnerabilities of this approach are discussed.
This item was submitted to Loughborough University's Institutional Repository by the/an author. Citation: LOCK, R. et al., 2010. Responsibility modelling for risk analysis. IN: BRIS, R. et al. (eds.). Reliability, risk and safety : theory and applications : proceedings of the European Safety and Reliability Conference, ESREL 2009, Prague, Czech Republic, 7-10 September 2009. Boca Raton ; London : CRC Press.
Babak Esfandiari合作论文数4
K. El-Khatib合作论文数Faculty of Business and Information Technology, University of Ontario Institute of Technology4