Idetifyig Risks i Outsourcig Software-Itesive Projects Dr. Maliha Haddad Assistat Professor Maagemet Sciece Departmet School of Busiess ad Public Maagemet George Washigto Uiversity Washigto, DC Dr. Aita J. La Salle Professor ad Chair, Iformatio Techology Departmet Director, Masters of IT Maagemet Program Kogod School of Busiess America Uiversity Washigto, DC 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 1 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects Some practical experiece ad isights ito outsourced project risks. w Idetifies some risks iheret i subcotractig software projects. w Serves as guidelie to both software cotractors ad customers egaged i software cotracts. 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 2 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects wsoftware out-sourcig as a tred/ecessity 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 3 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects Some [obvious] backgroud o software developmet process improvemet methodologies: w Natioal ad iteral treds i process models for software developmet. (e.g., SEI s SW-CMM models) w Treds i process models for software acquisitio. (e.g., SEI s SA-CMM) w Foci o risk maagemet (e.g., SEI Risk Eval., Cotiuous Risk Mgt., Team Risk Mgt.) 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 4 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects wreport based o formal research ito orgaizatioal practices ad o-site (iformal) observatios: wsurvey/iterviews of 26 orgs. About acquisitio practices. (Fed. Govt., Telecomm.,DoD, Fiacial Ist.) wcotracts for $30K to $50M wprojects: Busiess, Eg., AI/ES, Hybrids 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 5 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects Before, durig ad after product deploymet Study focus: w$ to cotractig orgaizatio durig SDLC to acquire, maage, cotrol, ad support the software cotract. wtime effort of persoel to support the cotract. wrisk post-mortems. 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 6 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects Some iitial research observatios: w [lack of] Orgaizatioal awareess of models w [lack of] Formal istitutioalized software acquisitio plas or project trackig plas w Traditioal order ad wait scearios w [lack of] Software requiremets documet specificity 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 7 Salle
Idetifyig Risks i Outsourcig Some iitial research observatios (cotiued): w [lack of] Acquisitio project maagemet processes for: Software-Itesive Projects Cotract maagemet Cofiguratio maagemet for trackig Iteral/exteral persoel oversight processes Trackig progress agaist requiremets ad costs Artifact ispectios Risk idetificatio ad maagemet Metrics gatherig 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 8 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects The first part of research results [briefly]: w The hidde costs of cotractig software is substatial mea value is 190% of the cotract. w Liear relatioship betwee hidde costs ad project size: M = 2.2 * KLOC + 52 (perso moths) 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad La 9 Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects The secod part: Risk Idetificatio ad Maagemet as a Major Compoet of Software Cotractig Customer-Cotractor relatioships 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 10 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects w Nature of risks i software cotractig w Impacts of cotractig risks o orgaizatios w Sources of software cotractig risks: Customer: Iteral Risks Iterface Risks Cotractor: Iteral Risks Our focus 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 11 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects As a customer, what are some of your iteral risk sources? Iaccurate estimates of of effort (time, scope, $) $) Persoel kowledge (software + acquisitio) User availability ad ivolvemet Specificatio of of customer (your) requiremets Cotract specificity (processes ad iterfaces) Creepig requiremets Uaticipated coordiatio ad oversight 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 12 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects w What are the cotractor s iteral risks? [Igored for this presetatio Because adherece to process models such as SEI s CMM is meat to reduce or elimiate may of cotractors risks or provide guidelies for risk maagemet pla.] [BUT -- Additioal problems arise if your cotractor is sub-cotractig!] 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 13 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects As a customer, what are some of the sources of risk at your iterface with your software cotractor? Mutually accepted ambiguous cotract Ill-defied iterfaces (users cotract maager(s) developers system) Pathological [multiple] cotacts Atagoistic iterfaces Deficiet ispectios Loosely defied checkpoits Uavailable testig criteria, processes, data, bechmarks 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 14 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects As a customer, what are some of the sources of risk at your iterface with your software cotractor (cotiued)? Shared repositories Cofiguratio maagemet of of artifacts Risk maagemet [icompatible] program Quality assurace [icompatible] program Expectatios of of re-use ad maitaiability Missed schedules 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 15 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects As a customer, what are some of the sources of risk at your iterface with your software cotractor (cotiued)? Costs of of tools ad maagemet software Icompatible deploymet ad developmet ifrastructures Security Trasiet persoel Uaticipated direct costs 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 16 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects As a customer, what are some of the sources of risk at your iterface with your software cotractor (cotiued)? Icompatible processes ad stadards Activity sychroizatio Gutless oversight Maager ed-aroud play Negotiatig chage Test site requiremets Cotract termiatio ad litigatio 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 17 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects Coclusios: w Process is is [still] Kig/Quee w Egage i i software outsourcig oly whe you uderstad the pitfalls w Be prepared: maage costs, maage risks w Get it it all i i writig w Avoid the customer-victim role. 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 18 La Salle
Idetifyig Risks i Outsourcig Software-Itesive Projects Questios? 3rd Aual Coferece - Acquisitio of Software Itesive Systems -- Jauary 2004 -- Haddad ad 19 La Salle