Saturday, February 05, 2005

Deliverables in the Analysis Phase of the SDLC

There are three deliverables that the development team must build in the Analysis Phase before the Design Phase begins. What are they and why are they important to the customers of the new system? What are the three deliverables?

Deliverable #1: Design Strategy

It is composed of several alternative designs for the new system. It can include several choices for the system’s functionality, hardware, system software platform, and method for acquisition. These are possible courses of actions proposed by the development team. The customers are asked to choose between three designs that differ in cost and functionality.

Low-end: This the least costly that the other two solutions. This is the basic solution that has no extra amenities or enhancement. One could compare Windows Notepad as a basic barebones word processor and lacks many of the features of Microsoft Word 2003. Because it is basic it is the fastest to develop.

High-end: This is the most expensive solution that would contain many enhancements, features and functionality. Microsoft Word 2003 would be a good example of this as compared to Notepad. The extra features for this application is the main focus not the cost.

Middle: This is a in between solution that is basic but with moderate features within a certain set cost that is much less than the high-end solution, and more than the low end solution. Microsoft WordPad would be a good example. It is a very basic Word with formatting and rich text like Word 2003, but without the additional nice features and cost.


Deliverable #2: Recommended Course of Action
This is the course of action that the development team thinks is the best to build and why. The recommendation helps address customer issues before they commit to the project.

Requirements:
- Will all the customer requirements be incorporated in the new system?
- What functions were added or left out and why?

Software:- Will the new system run on a mainframe platform, standalone personal computers, or a client/server platform?
- What are the advantages and disadvantages of each?

Hardware:- Can the new system run on the current hardware or will the company have to spend money to upgrade their computer systems?

Infrastructure:- Will the company be able to trains and support the users.
- How big of a change will the new system require the company to make to the way it does business?

Implementation:- How difficult or easy will the system be to implement?

Organization:- Does the new system work well with the company’s organization?
- Will the users accept it?
- Can the users even understand the new system?
- How will it help the organization?

Deliverable #3: Baseline Project Plan

The plan should show task sequences, dependencies, time requirements and the project critical path. This can be in a Gantt chart like is used in Microsoft Project. It is important to have a plan for both you and the customer. This allows the development team to give the customer a feel for the amount of work involved in the recommended course of action.

Why are they important to the customers of the new system? They are important to the customer because it gives them a understanding of the design, costs and the amount of work involved in the project. It also helps them understand if the project is addressing their needs and goals. By having them sign-off on it means that they claim that they understand the project and agree with the course of action.

In addition to this the deliverables are the bases in which the development team will be their design. The deliverables must be signed-off before proceeding to the design phase. This will provide your CYA and that the customer has committed to paying you for the project.


EFS Network Management
 can help you with the management of your network, servers or desktops systems. Your Expert IT Support.

Monday, January 31, 2005

About Feasibility Studies for the SDLC

Why is it so important?

As the title of the report states, is the project capable of being accomplished or brought about? Is it possible?Is it logical? It answers these questions. It is to establish whether or not at an early stage as possible the project is realistic.
  • The principal work areas for the project will have been identified.
  • Any needs for specialist staff to be involved in the later stages of the project willhave been noted.
  • Possible improvement or potential for savings may have become apparent duringthe investigation.
What is its purpose? It is to establish the feasibility of introducing a computer system. There three main areas: economic, technical and organizational.
Economics
  • Costs (Systems analysis and design, Purchase of hardware, Software costs, Training costs, Installation costs, Conversion and changeover costs, Redundancy costs)
  • Benefits (Savings in labour costs, Benefits due to faster processing, Better decision making, Better customer service, Error reduction)
  • Cost Benefit Comparison (This weights the difference in the hard costs and the non-measurable benefits.)
Technical
This is the technical possibility and desirability of a computer solution. There are several categories that are desired that can make the project more feasible:
  • Does it follow Rule-governed tasks?
  • Does it eliminate Repetitive task?
  • Does it solve Complex tasks?
  • Does it have a High degree of accuracy?
  • Does it have Speed of response?
  • Can the Data used for many tasks?
Organizational Feasibility This is also known as "Operational Feasibility". It addresses:
  • Will the organization accept the system or will there be conflict?
  • Will people be able to cope with the new system?
  • Is the organizational structure compatible with the new system?

Who is it written for?
It is for everyone involved in the process the developers, management and the customer.

Why is SIGN-OFF necessary on this deliverable? Sign off means that all parties agree and it is a must in order to move onto the next stage. It is also there for the CYA factor. The fact that someone signed off means that they understand the project being proposed and are giving the ok to proceed.



EFS Network Management
 can help you with the management of your network, servers or desktops systems. Your Expert IT Support.

Pharming - The New Buzzword

Let me be the first to introduce to you a new security buzzword that I just read about today.

Pharming

Like Phishing it attempts to capture your user name and password by directing you to an evil web site that appears to be legit. Phishing requires the user to click on a link in SPAM. Pharming is handled at the DNS level. The evil doer changes your local host file to direct your request to your banking site to their evil server.

Another methods is to change your default ISP DNS server in your TCP/IP setting to the evil doers evil DNS server. Once that happens you can not tell if you are really at your banks web site or the evil doers web site. Once you enter your user name and password they have your banking account.

We have seen this with spyware putting entries into the local host file and changing the DNS settings over the last six months. Now evil doers are going for your bank account using the same methods.

More on Pharming
http://www.theregister.co.uk/2005/01/31/pharming/

Here is an article about Phishing.
http://security.efsnm.com/index.php/weblog/phishing_scams/



EFS Network Management
 can help you with the management of your network, servers or desktops systems. Your Expert IT Support.


System Audits Tools

There are hundreds of different tools out there. For example: When I do a network audit I use three different companies audit tools. They all claim to do the same thing, but I have found each has it strengths and weakness.

So I run all three to get the information I really need and disregard where they over lap or do not provide any new information. I have not found a single be all do all tool. So you will have to try several for the project that you may be working on.

Once you have identify the system you need to audit, let me know I can point you to a couple that you can try. Most provide a 15 to 30 day free trial. You will know on the first one or two audits if the tool is right for the job at hand.

Here are a couple of network audit tools that I use.

GFI: Network Security Scanner (Affordable)
http://www.gfi.com/lannetscan/

Shavlik: HFNETCHKPro: Security & Patch Management (Free for small businesses)
http://www.shavlik.com/hfn_windows.aspx

Sunbelt Network Security Inspector (Very Expensive, but not only ID's the issues, but provides supporting detailed documentation on how to fix the issues)
http://www.sunbeltsoftware.com/product.cfm?id=987

If systems are automated with self documentation, company policy mandates it, and the SDLC a lots time for it, then it can stay up to date. To get a company to get to that point really takes a lot of time and growth.

Sunday, January 30, 2005

What Diagrams Provide

1. Flow block diagrams: (If available, it has answers) Questions can be derived for the information contained or missing from them.

2. Organizational charts: (If available, it has answers) Questions can be derived for the information contained or missing from them.

3. Task templates: (If available, it has questions) The task templates a good baseline start but do not contain all the questions for everything.

4. Data flow diagrams: (If available, it has answers) Questions can be derived for the information contained or missing from them.

They are all important and merit value. The more data you have the better an informed decision you can make.


EFS Network Management
 can help you with the management of your network, servers or desktops systems. Your Expert IT Support.

Analysts Channels of Information

Contrast and compare the five Analysts Channels of Information

There are five channels are as follows:.
  • Documentation
  • Interviews
  • Observation
  • Questionnaires
  • Measuring

I would also like to add to this with "System Audits". I will explain more in a moment.

Documentation
It has been said that this channel provides the least value. Ten years ago I would say that this is true, and it may still hold true for a number of organizations today. However our customer management database and work order system have become invaluable tools in keeping documentation up to date and current. So many people rely on it, it has become self updating as work is planned and completed.

The drug company that I used to be a consultant at now has a wonderful change control database and it is company policy that all systems documentation be kept current and the time to keep them current is built into the project. They have come a long ways from no or obsolete documents to very current and detailed documentation on all systems, the networks, severs, and mainframe systems.

The worlds biggest bank that a friend of mine works at carries it to level even more detailed. For example that have a specialist group for each phase of a project. Let's say you are the HR department and you need a new server. There is one groups that does the specs, one group that does the order from the vendor, one group that does the hardware build, testing and certification, one group that loads the baseline OS, one group that does all the updates and certifies the OS. The server is handed off to the group that handles the third party enterprise applications on the server. It is then hand to the security group and certified. Then the installation team does the install, testing for the customer/department. The server is then handed off the final group that does the support. This group is handed all the documentation for every phase and has detailed instructions on how to do each step and includes the log files and certification from the different groups. This is the most extreme documentation on a system that I have known. From the time of request for a server to the time of deliver is five to six months for a single server.

Interviews
These are very important. Spending a few minutes with a key player can yield huge insights that could save you from chasing a rabbit down a dead end hole and save you time and resources during your research.

Observation
Working with people is a must. Setting back and watch them drive the application can be an interesting experience. Each user has developed their own personal method of interacting with the system based upon their knowledge level, skills and usage of the system. As a developer it is very important to watch a user. They will have a different interpretation of the system and interface. The amazing part is they will do things that you would never have conceived possible, or why they are doing a task a certain way. Then you modified the system to trap for their issues or make it better for them. What is really incredible is the ways users will adapt the system to track or do something that it was never indented by the developer to do.

Questionnaires
These are great, but getting people to fill them out is like pulling teeth. You have to have it mandated, corner them or do it during an interview.

Measuring
This is important to size up the scale of the project, the scale for the database need, the number of users, the number of database transactions, etc. all aid in better understanding the systems.

System Audits
This is not part of the lecture or the reading material. This comes from my experience. In the old days most all system audits had to be done manually. Where is the system physically located? How is it connected? What is it used for? What is it's configuration? What are it's specs? What is it's current software update level. This is for all components involved, hardware, software, OS's, databases, network connectivity, etc.

With software interconnected components it has become too time consuming and too overwhelming complex with too many parts. In recent years there are new software tools that can do the job for you. There are network scanning and management tools. There are database reverse engineering and documentation tools. There are project development code management tools. There are tools for just about all aspects for creating data flow diagrams and flow charts automatically. All these tools can create the documentation that you need for your research.

White Papers
White Papers really help as case studies, lessons learned, a detail insight and the gotchas of a certain system. If there are white papers available for your project or a part of your project I encourage you to take a little time and review them. They can shape your ideas and opinions. The really nice thing is you can learn from other peoples pain and mistakes and avoid those in your project.

A Vendor created White Paper about their product DNS:
http://support.microsoft.com/default.aspx?scid=kb;en-us;810733

A Third Party White Paper about the Vendors DNS:
http://itresearch.forbes.com/data/detail?id=1094838407_866&type=RES&src=TRM_TOPN

What is a White Paper:
http://www.whitepapercompany.com/pages/387998/index.htm

Why White Papers:
http://www.whitepapercompany.com/pages/387343/index.htm

Here are IT White Paper Sources. The UoP Library contains some too.
http://itpapers.com/index.aspx

http://www.bitpipe.com/

Example of how you used one on a development project.
I recently did a security audit for a 15 user network with two servers for the purpose of checking overall security of their system, so they could allow a customer to connect and gain access to their network and database systems from a remote office. The auditing tool I used took about 20 minutes to complete the entire network and yielded 183 pages of quality current documentation. A manual audit would have taken me several days, and I still would not have the level of detail. Now do an audit on a very large system and you will have a new problem. That is information overload. The next thing is to learn what information is important and relative to the project.

All these are part of the documentation process and aid in your research and analysis.


Friday, January 28, 2005

Prototyping Methodology

Prototyping is one modern method of development. The first Apple computer was developed in the manner in 1976/77 by Steve Wozniak in Steve Job's garage with off the self parts in a wooden case.

Compared to SDLC:
This method is less structured, planned organized than the SDLC (Software Development Life Cycle). It is often off the hip last min assembly, testing or development. It is more or less for a smaller project often done as a proof of concept to test ideas, processes and systems before committing vast about of resources to a larger project.

A recent advancement in a fairly med size project in prototyping and testing unproven methods and ideas would be SpaceShipOne http://www.xprize.com/ with it's historical flight into space. It tested light weight materials, new engine designs, new methods of a control re-entry without heat shielding, new wind breaking systems, new computer systems and how it performs when the computers systems fails. Lastly it proved that space flight is not limited to government dollars and budgets. It's flight is in comparison to the first Apple computer as prototyping and leading to new production systems changing the world in the process.

Advantages:
It allows for more creativity and possibly new world changing solutions could be developed, where they might be hindered on the SDLC's control process.

Disadvantages:
In prototyping scope creep, cost over runs, miss management, and lack of focus are more likely to occur in this type of project. SpaceShipOne is a good example. It required Paul Allan and Virgin Records additional funding to complete the project. The total cost of the mission was 20 million dollars and the X-Prize was only 10 million dollars. While they did go over budget, I should point out it was one of the cheapest space flights in history, using less than 10% of the budget of a simple satellite launch that is not a manned flight.

While I am sure that SpaceShipOne had some type of development plan, prototyping can include a whole host of unknown variables that can not be determined until testing has been completed.

Prototyping is not a best practice method for getting your project completed, but it does have a place in developing something new.

Thursday, January 27, 2005

Analysis Phase of the SDLC

Valuable/important to the Analysis Phase of the SDLC

All the items that are listed could have some impact on the SDLC (Software Development Life Cycle), depending upon what type of information they contained. I use all the items all the time. However one should note that the information contained in each of the ones listed may be dated, obsolete or incorrect. Having to choose one I choose the Data Flow Diagrams.
Although systems flowcharts provide a useful tool for analyzing a physical description they may impede the design process.


Why is it so valuable?
It is the heart of the system design. It gives the design and flow of data across many systems, databases and sites.
  • Identifies the major processes.
  • Identifies the major data sources, sinks and stores.
  • Identifies the major data flows.
  • Names the data flows, processes, sources, sinks and stores.

What information does it contain?
It shows all the pathways and connects to the varies systems, and databases. It would give the overall concept and configurations of the systems. It can also be data flows at varies levels of detail. It can be an overall view, then drilling down to a nuts and bolts view of great detail.

Data flow diagrams assist in building a logical model of the system independent of physical commitments. They show the various flows of data between the processes that transform it. Data stores and the points at which data enters and leaves a system are also shown.


How does it move the Analysis Phase forward?
It provides a place where to start looking first to begin your analysis. It would give you a base line to compare your findings, and prepare a number of questions. It is the base line data design that strip away the hardware layer and focuses more on the logic design and can allow for a clear understanding of the process. It could even make it possible to see new ways to improve the design. It's layering allows for the scaling of ideas, sections and data flows to different degrees of detail.

The data flow design is an important tool of structured analysis and design. It ensures that a top-down approach is taken. This promotes a logical, as opposed to physical, view of data stores, flows and processes.

Learning from Failure

Having worked in IT for many years, I have seen a lot of failure. I do not consider failure as being a bad thing. In IT in many cases it can be a good thing. Sometimes when things go very wrong, initially no one may know what is the cause of a problem. A series of failures can be like bread crumbs leading to the real problem. Being a good sleuth to read, understand and interpret the failures as to what are they telling us, leading us, or NOT telling us is just as important.

Having a problem and having no failures to help guide you to a successful resolution can take a lot of time and resources. It can be very frustrating just trying to identify the root cause of a problem.

So I embrace failure as a key to solving the root of a problem.

Wednesday, January 26, 2005

Qualify the Project

One of the very first questions that should get asked right up front is "Who is paying for the project?".

If this is an internal project then it may be a special budget, or a specific department or multiple budgets or departments.

If it is a customer external to the organization it is best to qualify them to see if they are willing to pay x dollars for projects and check their payment history.

The last thing you want to do is a lot of leg work only to find out the customer never had any intention of buying or they did not realize the scope of the project that they were asking for or there is no budget or funding for the project.

Tuesday, January 25, 2005

What's in a Title for System Analyst?

You may find when working for a very large company that a system analyst maybe a generic title/term associated with a pay grade. However your title being a system analyst you may be limited to a certain area in a certain department.

I have two real world examples:

Employee A & B works for the worlds largest drug company. His & Her title(s) are both systems analyst and they both have the same pay grade within the company. Both work in the MIS Group. Employee A works as a Lotus Notes Administrator. Employee B works as a Java Developer. Neither do what is described in the text as a systems analyst.

Employee X & Y works for the worlds largest bank. Both are systems analysts and have the same pay grade. One is a network engineer and the other builds servers for the enterprise.

Neither of these big companies follow what a systems analyst description is. So when applying for a systems analyst job, make sure you understand the duties and responsibility of a systems analyst are for that job.

I am not trying to confuse what a systems analyst is. I am just trying to make you aware of a potential surprise.

Improving Your SDLC

I am sure that you will find that the US bugs are much different that the Belgium bugs!!! I found out the hard way with my own database development project.

When we first started beta testing of the application we had a Canadian company that makes plastic parts for cars that was Japanese own/run company call us to be a beta test site. So we went there and installed the application on site with the customer, as we were still a year away from a production version, but they really wanted to beta test it anyway. Then we went to enter their data into our system. We could not get their data into the application. We could not completely fill out and use the contact information for employees, vendors and their customers. We use this information throughout the program to prevent having to re-enter the data and save time on data entry.

Why? Silly me I used the Microsoft wizards to set the format masking on the fields for currency, phone numbers and zip codes. Well duh! Canada does NOT use the same formats. So it was cripple before we started. That night in the hotel I had to edit over a hundred places and strip out all field format masking to allow for Canadian formats so they could use the application.

Since then we have had an equal response from overseas test sites that I had to make allowances for more localization and date formats. We never thought we would get the response we have from over seas. We even worked with the local University in Costa Rica to allow for special characters and assistance with translation into Spanish for a major drug manufacturing company that makes plastic parts. We had only envisioned the good ole USA.

We did NOT make the connection or observation that US companies would also have plants in other countries. So the moral here is our version of the SDLC did not include or consider localization issues for other countries.

Monday, January 24, 2005

Not Using the SDLC

What if there is a small company that does not believe in the SDLC process?? Does this mean they will fail as a company???

Of course not! As with all things, there are several ways to do the same thing. A small business method could not follow the SDLC at all, but upon closer examination it might have traces of the SDLC process and they do not even know they are using it regardless of their belief.

When your home computer is broken and/or you want to upgrade it, you take it to your favorite computer store or you do it yourself. This meets the definition of a project.

http://dictionary.reference.com/search?r=67&q=project

Does a simple repair or upgrade require an elaborate SDLC? ...for the most part no. It is reasonable and manageable to do it without SDLC.

Now lets scale this a bit. Lets say you have 5 computers that need service. Would you need a SDLC? ...for the most part no, because the number of devices and the complexity are still minimized.

Ok, lets scale this a little more. Lets say you have 35 computers to upgrade. Would you need a SDLC. ...yes and no. I would highly recommend that you come up with an action plan and costs before taking on such a project both for your sake and the customers.

Finally let really scale this up. Lets say you now have 10,000 computers to upgrade. Would you need a SDLC. Absolutely yes There are too many devices and too many variables that not having a SDLC could result is a huge disaster and be very costly. Then everything that is being taught in the lecture and text are applicable to a very high degree, and yes you had better have your CYA component in place.

Sunday, January 23, 2005

Systems Analyst

What are the attributes/skills of an effective Systems Analyst?

Attributes:
  • Analytical skills: The ability to understand the organization and its functions, to identify opportunities and problems, and to analyze and solve problems.
  • Technical skills: The ability to understand the potential and the limitations of information technology.
  • Management skills: The ability to manage projects, resources, risk, and change.
  • Interpersonal skills: The ability to work with end-users, other analysts and programmers. You must also act as the liaison between users, programmers, and other systems professionals.
  • Additional skills not listed in the lecture or the reading text that are a must are self discipline, the ability to work alone without direction and a healthy dose of problem solving skills. These can apply and enhance the four skills listed above.


Two ways a person can develop those attributes/skills.

Skill development is a life long process that is never ending. We are all imperfect and have areas that could use refinement, and enhancement. The moment you stop developing your skills is the moment that you could handicap yourself in certain areas.

First you must poses the desire for self improvement.

Second you must poses persistence. You must be determined to get backup on your feet after you have been knocked on the ground. Dust your self off and resume professionally your task at hand. Without persistence your desire can be squash by unforeseen events.

Next is simply do. Practice, Practice, Practice, Practice!

Next, do not fear failure. Embrace it and use it as a learning tool to achieve success. Learning from ones mistakes can lead to huge rewards in the future. Also learning from others failures is just as important.


Developing your Systems Analyst skills in your working environment.

There is opportunity of every moment of every day where one has the opportunity to develop their skills. Even though I have been out of traditional school for a very long time. I have never stopped learning, practicing and enhancing my skills. Sometimes it is easy; sometime it is hard. Sometimes it is very successful; sometimes it is a failure.

I was once told that you fail 100% of the time you do not try. This is something that I always keep in the back of my mind when evaluating my next move.

Scale usage of the SDLC

What if there is a small company that does not believe in the SDLC process? Does this mean they will fail as a company??

Of course not! As with all things, there are several ways to do the same thing. A small business method could not follow the SDLC (Software Development Life Cycle) at all, but upon closer examination it might have traces of the SDLC process and they do not even know they are using it regardless of their belief.

When your home computer is broken and/or you want to upgrade it, you take it to your favorite computer store or you do it yourself. This meets the definition of a project.

http://dictionary.reference.com/search?r=67&q=project

Does a simple repair or upgrade require an elaborate SDLC? ...for the most part no. It is reasonable and manageable to do it without SDLC.

The scale usage of SDLC:
  • BIG: Use SDLC in all it's glory for big business and big projects, but not as company LAW.
  • MEDIUM: Use a scaled down version(s) of SDLC for medium size business and projects.
  • SMALL: Use a checklist type format and/or quick evals without all the massive detail of a formal SDLC.
  • REALLY SMALL: For really small projects and small business hardly any SDLC at all is needed.
Now lets scale this a bit. Lets say you have 5 computers that need service. Would you need a SDLC? ...for the most part no, because the number of devices and the complexity are still minimized.

Ok, lets scale this a little more. Lets say you have 35 computers to upgrade. Would you need a SDLC. ...yes and no. I would highly recommend that you come up with an action plan and costs before taking on such a project both for your sake and the customers.

Finally let really scale this up. Lets say you now have 10,000 computers to upgrade. Would you need a SDLC. Absolutely yes There are too many devices and too many variables that not having a SDLC could result is a huge disaster and be very costly. Then everything that is being taught in the lecture and text are applicable to a very high degree, and yes you had better have your CYA component in place.

Small Business and SDLC

The SDLC (Software Development Life Cycle) is not as attractive to smaller business and projects. The business dynamics between the two are very much different in many ways. Small business and small projects are low budget and need to react quickly. Since the small budgets and business have very limited resources there is a great need to compress the timeframe and detail analysis. Since the smaller projects have less of an impact and do not cascade multiple sites and millions of dollars the risk analysis and assessments are much more limited and easier to scope. Therefore that teams and recourses would be a few people doing most all the work.

As a small business every moment of my time is tied to a billable resources in which I am accountable in order to pay the bills and put food on the table. The needs of volume and scope of work is not as great as an SAP type project. To attempt a full formal SDLC process would be too costly for both the customer and myself.

In the stages in the lecture where there is a lot of analysis prior to proceeding on the project, your company is paying the tab for the evaluation as both the developer and the customer. In my case we are separate and one is paying the other for the analysis. In your lecture everyone is getting paid as being part of the big organization. In my case I would have to create and estimate for each phase of the project and the customer would have to sign off at each phase and pay.

If I am asked to create a simple program or utility that would take me several hours as I do now. It would greatly increase the time and cost using a formal SDLC. So a $1,000 project without SDLC might cost the customer $6,000 with a formal SDLC. If the customer knows it may cost $6,000 for a small utility, then there may not be a project and that would be zero dollars earned. Do that 100 times a year and one would have made far less with the formal SDLC than compressing the scale of SDLC or none at all.

So profitably for the vendor and cost saving for the customer with working on a small project would be a definite reason NOT to follow a full formal SDLC.

The SDLC is a very delicate engine that requires a lot of fine tuning and self discipline to keep it on track and working. It can easily break down if all parties are not participating equally. In some cases they do not and you have to be flexible to compensate for the absence of their effort.

The SDLC is usually driven by management as they are the ultimate responsible person. That said having been a consulting analyst working for a large company you can be pigeon holed into just one area and not aloud to work in multiple areas at once or gain additional experience.

On a large scale project where there is a budget and people get paid no matter the outcome for a larger organization, I agree that SDLC should be used and have no argument with the text and your lecture in that respect.

So the moral here is use the right size hammer for the project.

Saturday, January 22, 2005

The Important Stages of the SDLC

Explain why the first phases of the Software Development Life Cycle (SDLC) are more important than the later steps. Reasons why they are and/or reasons why they are not.

Explain why the first phases of the SDLC are more important than the later steps.

Setting: Large company with deep pockets.

Why: The first three phases in the text is very important as it is the foundation upon which the project is based and are the most important. A great deal of leg work in preparation is required. It requires a great deal of time and effort to compile and analyze the project long before a single line of code is written.


STAGE 1 DETERMINATION OF SCOPE AND OBJECTIVES
I believe that this is self explanatory.

STAGE 2 SYSTEMS INVESTIGATION AND FEASIBILITY STUDY
This phase in the text is very weak in its explanation. It is basically a simple analysis "Do we think we have the resources, man powers and money to do this?" What assets can we utilization, sharing or do we need to acquisition of new capital hardware and/or expenses?

STAGE 3 SYSTEMS ANALYSIS
There are a lot of variation on what needs to do at this stage. I agree with what has been published about this phase, however it is not all inclusive. There are additional items that need to be look at during this phase.
  • Risk analysis: (to company, people, process)
  • Security Analysis (to company, people, process)
  • Impact Analysis (to company, people, process)
  • Regulatory Analysis (for company, people, process)
  • Company Policy Analysis (for company, people, process)
  • What are the Bench marks, water marks, goals achievement points (for company, people, process)

STAGE 4 SYSTEMS DESIGN
Wow, now we get to start writing code...


Reasons why they are and/or reasons why they are not.

As with anything situation dictates the need. The bottom-line is there is no magic bullet for all situations. The reading text SDLC theory is great for a large organization with really deep pockets and does a good job of keeping the giant wheel balanced.

For the small projects, a lot can be knocked out with simple evaluations of the situation, it's impact and gains. An elaborate SDLC is not required in many cases, and would be too costly for the smaller projects. The need for a structured development process should be used, but not in all cases.

Examples a user needs to convert data from one data source to another. This is a one time thing and will not be needed again. A quick assessment by the developer that it will only take about 8 hours to do the data conversion by writing a small program. The SDLC process would be too much over kill as one can quickly assess that all the above analysis is not needed.

So bigger projects SDLC is a good fit, but may require a bit of modification. SDLC for smaller projects can be skipped for the most part as the assessment can determined that the SDLC is not needed in its entire form.


Large Projects and the SDLC


This is a good example where Software Development Life Cycles (SDLC) is appropriate and needed. A very large project, being done over a very long time where lots of money, people and resources are required is a when the SDLC should be used.

However the larger the project it can be frustrating manage and coordinate. The more people added to the mix the more personality collide and defenders of territory come into play. SDLC would help guide the project, but it does create an unavoidable human element of frustration with other groups, areas, vendors, consultants or departments.

This is not a project that I would recommend go without some type of SDLC process.

CYA: If a formal SDLC is not in place, the initial formation of a SDLC could meet resistance from the existing management structure and org chart. The initial formation can be stifled by politics and personal agendas. After it is established and everyone understand the process then Ray is correct. It aids in damping the effects of politics.

This is a good concept for vendor to customer relationship and maybe in some business organizations, however this will not work in all cases. Every large company has different polices and procedures. It is more difficult to be creative and to correct a known customer requested design flaw with this method. It also greatly extents the development cycle which is why SAP, Peoplesoft and other very large deployments take so long.

The level of detail and interpretation between the customer and vendor can be annoying. The steps of clarification by phases so the customer knows exactly what they got matches what they asked for can take time. That is not a billable process in some cases.

However it is a good tool to keep things in check. It is good where it is appropriate.

Friday, January 21, 2005

When Not to use the SDLC

Reasons and Examples why developers or support analysts would NOT want to use a FORMAL Software Development Life Cycle?

There are a number of reasons why a formal SDLC is not a good fit.

The following are contributing factors that directly affect the formation of the SDLC process, its structure and organization.

  • Logistics
  • Costs
  • Available Skill sets of people
  • Number of people in the project
  • Budget, Funding, Retainer or PO
  • Available tools (software, hardware, communications and connectivity)
  • Collaboration tools (software, hardware, remote access)
  • The utilization of the most current RAD tools
  • Leadership Skills
  • Team Developer Skills
  • End User process knowledge and skills
  • Time-Frame
  • Project "In-Demand" need
  • The personal motivations of all the people involved in the project
  • This is NOT and all inclusive list. There are many more factors too.

With each factor being a variable the SDLC structure as presented in the text does not allow for flexibility. A development process success is dependant upon many factors to include all parties being flexible to change as things change. The only constant in IT is change.

Areas of application development were SDLC is not a good fit are:

  • Proof of Concept Testing
  • Running a series of never before performed processes, functions or methods.
  • Running a series of combination tests to see what happens.
  • Running a series of tests to intentionally try to break the application process to examine for security and potential points of failure.
  • Running a series of unorthodox user tests to observe the reaction and behavior of untrained or unskilled users to trap for the unexpected use of the applications.
  • Experimentation
  • Developing algorithms to perform tasks that do not yet exist.
  • Refining existing methods and procedures for better performance and smaller footprint.
    Individual Projects
  • An individual user doing small utility development.
  • There are many more, but these are a few.

One might argue that these are individual components of the SDLC. Situation dictates the scale and perception of where and when the SDLC process begins and ends. The SDLC can be a used by single user or by a massive army of developers. In the development community the term SDLC is not used. Common terms that mean the same thing are process development, application development, team development and systems development. The life cycle part is a MBA buzz word.

SDLC can provide structure where chaos is, however if the SDLC is in acted as company Law it can actually impede, hinder and prevent creative application development.

Examples of where the SDLC was NOT used that resulted in creative and industry changing applications.

  • Compaq's original IBM compatible XT PC
  • The original Compaq system BIOS
  • The original Apple computer
  • Tim Berners-Lee development of HTML and the first Mozilla Browser
  • Shawn Fanning's development of Napster
  • The development of the original UNIX and DOS OS's
  • The original spreadsheet application
  • The original email application
  • I could go on and on....

So the moral here is for the carpenter to apply the right size hammer to the right size nail.


Using the Software Development Life Cycle

Why is a formal systems development process needed for developing IT systems? What are its advantages and how does it help prevent a systems development effort from failing? Give an example where you think it could help.


Why is a formal systems development process needed for developing IT systems?

A skilled leader and skilled teammates drive the development process. The theory in the text leads you to believe that the Software Development Life Cycle (SDLC) is the end all be all to development. That is simply not the case. The SDLC is a tool like a hammer. The carpenter is the one that uses the hammer to drive the nail. The hammer is useless without the skilled carpenter. Likewise the carpenter needs to know how to use the hammer. He also needs to understand that there are different hammers for different nails. If the hammer is too big, use a smaller one. If the hammer appears to not work, make one that will.


What are its advantages and how does it help prevent a systems development effort from failing?

The SDLC is a formal process and not a law, it is a guide that should be modified for the need. The SDLC is a process that was developed after many failed or inefficient attempts at success. The SDLC is to provide a better way of doing things, but is not the only way to do process development.


Give an example where you think it could help.

Since SDLC is not part of the three worlds largest software developers vocabulary, I would think that the Longhorn development team at Microsoft could use a skilled carpenter with a big hammer. If they continue to chop off major portions of the proposed product from 4 years ago, then there will not be much of a product left to use.