{"id":300,"date":"2018-07-25T06:41:25","date_gmt":"2018-07-25T06:41:25","guid":{"rendered":"http:\/\/csp8.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=300"},"modified":"2018-08-08T06:00:34","modified_gmt":"2018-08-08T06:00:34","slug":"risk-management-ii","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/chapter\/risk-management-ii\/","title":{"rendered":"Risk Management II"},"content":{"raw":"<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>SOFTWARE RISK MANAGEMENT<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Project risks are defined as the undesirable event, the chance that an event might occur and the consequences of all possible outcomes. Risk management attempts to identify such events, minimize their impact &amp; provide a response if the event is detected.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>LEARNING OBJECTIVES\u00a0<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify\">To identify potential software risks as required by the grading level.<\/li>\r\n \t<li style=\"text-align: justify\">To determine the Likelihood and consequences of the safety software failure.<\/li>\r\n \t<li style=\"text-align: justify\">To elaborate on risk management policies and process.<\/li>\r\n \t<li style=\"text-align: justify\">To establishment of risk thresholds for the safety software application.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>RISK MANAGEMENT PARADIGM<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">The risk management includes the following:<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify\"><strong>Identify: <\/strong>Search for the risks before they create a major problem.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Analyze: <\/strong>Understand the nature, kind of risk and gather information about the risk.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Plan: <\/strong>Convert them into actions and implement them.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Track: <\/strong>We need to monitor the necessary actions.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Control: <\/strong>Correct the deviation and make any necessary amendments.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Communicate: <\/strong>Discuss about the emerging risks and the current risks and the plans to be undertaken.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Planning: <\/strong>Looking for the desired results, the strategies to be applied.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Organizing: \u00a0<\/strong>Getting all the things together so that the desired results are obtained. By organizing the efficiency is increased and lot of time is saved.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Directing: <\/strong>Communication takes place and exchange of ideas is formatted in this phase.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Controlling: <\/strong>In the last phase feedback and evaluation is done.<\/li>\r\n<\/ul>\r\n<\/div>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">TEAM RISK MANAGEMENT PRINCIPLES<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Team risk management involves two principles which are as follows:<\/span><\/p>\r\n\r\n<div style=\"text-align: justify\">\r\n<ul>\r\n \t<li><strong>Shared \u00a0Product \u00a0Vision<\/strong>: \u00a0The \u00a0common \u00a0goal \u00a0between \u00a0the \u00a0team \u00a0and \u00a0the \u00a0supplier \u00a0is established so that the vision is very lucid.<\/li>\r\n \t<li><strong style=\"text-align: initial;font-size: 1em\">Team work: <\/strong><span style=\"text-align: initial;font-size: 1em\">Working collectively towards achieving a common goal. The best way to\u00a0<\/span>snub the risks to some extent is to involve the customers\u2019 right from the beginning and build a team oriented approach.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n<strong>RISK MANAGEMENT IN SMALL PROJECT\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Risk Management in small projects comprises of preparing for risks which include external and internal risks such as uncertain requirements, unknown technology, infeasible design, and cost schedule uncertainty. The risks are identified and analyzed to understand the nature of risks and prioritize the risks and try to solve the risks. Mitigation of the risks is done which involves risk acceptance, risk transfer, risk avoidance and risk control.<\/p>\r\n&nbsp;\r\n\r\n<strong>Assessing the Risk Impact\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">All risks need not be subject to monitoring and control. Scenario Analysis is used to assess the risk event impact. All consequences and their severity are determined if the event happen. When the event is likely to happen during the project is identified and the probability that the risk event will occur is estimated. The difficulty in detecting the event occurrence is determined.<\/p>\r\n\r\n<\/div>\r\n<img class=\"aligncenter wp-image-202\" src=\"http:\/\/csp8.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/53\/2018\/07\/Assessing-the-Risk-Impact.png\" alt=\"\" width=\"691\" height=\"292\" \/>\r\n<p style=\"text-align: justify\"><strong>Risk response strategies<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Risk response strategies include the following:<\/span><\/p>\r\n\r\n<div style=\"text-align: justify\">\r\n<ul>\r\n \t<li><strong>Mitigating risk: <\/strong>Actions are taken during the project to either reduce the likelihood of a risk or reduce the impact of the risk. For example, testing electrical components after receipt would reduce the likelihood that \u201cbad\u201d parts would be used in a circuit.<\/li>\r\n \t<li><strong style=\"text-align: initial;font-size: 1em\">Retaining risk: <\/strong><span style=\"text-align: initial;font-size: 1em\">Risks are retained usually for events with low probability but high impact\u00a0<\/span>when no alternate strategy is feasible. \u00a0A contingency plan is kept ready, in case an event occurs.<\/li>\r\n \t<li><strong style=\"text-align: initial;font-size: 1em\">Sharing risk: <\/strong><span style=\"text-align: initial;font-size: 1em\">Multiple units associated with the project assume some portion of the risk.<\/span><\/li>\r\n \t<li><strong style=\"text-align: initial;font-size: 1em\">Transferring risk: <\/strong><span style=\"text-align: initial;font-size: 1em\">Risk is assumed and managed by a unit outside the immediate project.<\/span><\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\nFor example, risks associated with the balloon vehicle are transferred to the project management.\r\n\r\n&nbsp;\r\n\r\n<strong>Response development for risks\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A risk response plan identifies the primary components necessary for managing the risk and the response strategy that will be used is identified. Response development involves the understanding and detection of risk event so a response can be triggered. It involves in employing a plan in response to the event occurred and assigns who will be responsible for monitoring and controlling the risk. The response development for risk events, the contingency plan, the action triggered and the assignment of the responsibility is depicted in the following figure.<\/p>\r\n&nbsp;\r\n\r\n<img class=\"aligncenter wp-image-304\" src=\"http:\/\/csp8.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks.png\" alt=\"\" width=\"723\" height=\"195\" \/>\r\n\r\n<strong>Contingency Planning<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em;text-align: initial\">The risks associated with the technical aspects of a project can have the most severe outcomes. It can be mitigated by building and testing prototypes of critical components. The risks can be mitigated by having available backup or alternate designs that have much lower risk. The risks associated with costs usually result from estimate errors and omissions as time &amp; cost are related and the trade-off schedule delays with lower cost. \u201cDescope\u201d options remove components of the project, but still allow the primary mission to proceed.<\/span><\/p>\r\n\r\n<\/div>\r\n<div style=\"text-align: justify\">\r\n\r\n&nbsp;\r\n\r\n<strong>Risk Management\u00a0<\/strong>\r\n\r\n&nbsp;\r\n\r\nThe risks that occur in a project can be managed by employing the following steps:\r\n<ul>\r\n \t<li>Determine risk sources and their categories.<\/li>\r\n \t<li>Determine risk parameters.<\/li>\r\n \t<li>Establish a risk management strategy.<\/li>\r\n \t<li>Identify risks.<\/li>\r\n \t<li>Evaluate and prioritize the risks.<\/li>\r\n \t<li>Develop and implement risk mitigation plans.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n<strong>Risk Mitigation\u00a0<\/strong>\r\n\r\n&nbsp;\r\n\r\nAn effective strategy for dealing with risk must consider the following three issues (these are not mutually exclusive):\r\n<ul>\r\n \t<li>Risk mitigation (i.e., avoidance).<\/li>\r\n \t<li>Risk monitoring.<\/li>\r\n \t<li>Risk management and contingency planning.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Risk mitigation (avoidance) is the primary strategy and is achieved through a plan. Example: Risk of high staff turnover. The strategy for reducing staff turnover involves meeting with the current staff to determine causes for turnover (e.g., poor working conditions, low pay and competitive job market). Mitigate those causes that are under our control before the project starts. Once the project commences, assume turnover will occur and develop techniques to ensure continuity when people leave. Project teams are organized so that information about each development \u00a0activity \u00a0is \u00a0widely \u00a0dispersed. \u00a0The \u00a0documentation \u00a0standards \u00a0are defined \u00a0and\u00a0<span style=\"font-size: 1em;text-align: initial\">mechanisms are established to ensure that documents are developed in a timely manner. Peer reviews of all work are conducted so that more than one person is \"up to speed\". The backup staff member for every critical technologist is assigned to avoid risks that arise due to the absence of the critical technologist.<\/span><\/p>\r\n\r\n<\/div>\r\n<div style=\"text-align: justify\">\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">During risk monitoring, the project manager monitors factors that may provide an indication of whether a risk is becoming more or less likely. Risk management and contingency planning assume that mitigation efforts have failed and that the risk has become a reality. RMMM steps incur additional project cost as large projects may have identified 30 \u2013 40 risks. Risk is not limited to the software project itself but can occur after the software has been delivered to the user.<\/p>\r\n&nbsp;\r\n\r\n<strong>Software safety and hazard analysis\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">These are software quality assurance activities that focus on the identification and assessment of potential hazards that may affect software negatively and cause an entire system to fail. If hazards can be identified early in the software process, software design features can be specified that will either eliminate or control potential hazards.<\/p>\r\n&nbsp;\r\n\r\n<strong>RMMM PLAN\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The RMMM plan may be a part of the software development plan or may be a separate document. Once RMMM has been documented and the project has begun, the risk mitigation, and monitoring steps begin. Risk mitigation is a problem avoidance activity and risk monitoring is a project tracking activity.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Risk monitoring has three objectives that include the assessment whether the predicted risks do, in fact, occur. It ensures that risk aversion steps defined for the risk are being properly applied and collects information that can be used for future risk analysis. The findings from risk monitoring may allow the project manager to ascertain what risks caused which problems throughout the project.<\/p>\r\n&nbsp;\r\n\r\n<strong>SEVEN PRINCIPLES OF RISK MANAGEMENT<\/strong>\r\n\r\n<\/div>\r\n<ul>\r\n \t<li style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\"><strong>Maintain a global perspective \u2013 <\/strong>It involves viewing software risks within the context\u00a0a system and the business problem that is intended to solve.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Take a forward-looking view<\/strong><span style=\"text-align: initial;font-size: 1em\">- Think about risks that may arise in the future and establish contingency plans.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Encourage open communications <\/strong><span style=\"text-align: initial;font-size: 1em\">- Encourage all stakeholders and users to point out risks at any time.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Integrate risk management <\/strong><span style=\"text-align: initial;font-size: 1em\">-Integrate the consideration of risk into the software process<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Emphasize a continuous process of risk management <\/strong><span style=\"text-align: initial;font-size: 1em\">- Modify identified risks which are known and add new risks so better insight is achieved<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Develop a shared product vision <\/strong><span style=\"text-align: initial;font-size: 1em\">- A shared vision by all stakeholders facilitates better risk identification and assessment.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Encourage teamwork when managing risk <\/strong><span style=\"text-align: initial;font-size: 1em\">- Pool the skills and experience of all stakeholders when conducting risk management activities<\/span><\/li>\r\n<\/ul>\r\n<div style=\"text-align: justify\">\r\n\r\n&nbsp;\r\n\r\n<strong>RISK RESPONSE PROCESS CONTROL\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The Risk Management Plan should specify the risks, risk responses, and mechanisms used to control the process. Risks must be continuously monitored for risk triggers. Potential risk events should be identified early in a project and monitoring for such events immediately commence. Each risk is assigned to a specific person who has the expertise and authority to identify and provide a response to an event. Risk response process control needs an environment where problems are readily reported, embraced and solved. Changes in any aspect of the project need to be documented and communicated. The authority to approve a change must be assigned and the changes must be communicated to the team. Written forms are employed to track hardware, software and document changes. The members who are notified of changes, when the change is made and the change that is made must be documented.<\/p>\r\n&nbsp;\r\n\r\n<strong>Summary\u00a0<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Whenever much is riding on a software project, common sense dictates risk analysis. Yet, most project managers do it informally and superficially, if at all. However, the time spent in risk management results in less upheaval during the project, provides a greater ability to track and control a project and incorporates confidence as plans for problems are devised before problems occur. Risk management can absorb a significant amount of the project planning effort, but the\u00a0<span style=\"font-size: 1em\">effort is worth it.<\/span><\/p>\r\n&nbsp;\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n<strong>Web Links<\/strong>\r\n<ul>\r\n \t<li>https:\/\/www.theirm.org\/the-risk-profession\/risk-management.aspx<\/li>\r\n \t<li>www.rmmagazine.com\/<\/li>\r\n \t<li>https:\/\/www.mcxindia.com\/education-training\/knowledge-series\/risk-management<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n<strong>Supporting &amp; Reference Materials<\/strong>\r\n<ul>\r\n \t<li>Roger S. Pressman, \u201cSoftware Engineering: A Practitioner\u2019s Approach\u201d, Fifth Edition, McGraw Hill, 2001.<\/li>\r\n \t<li>Pankaj Jalote, \u201cAn Integrated Approach to Software Engineering\u201d, Second Edition, Springer Verlag, 1997.<\/li>\r\n \t<li>Ian Sommerville, \u201cSoftware Engineering\u201d, Sixth Edition, Addison Wesley, 2000.<\/li>\r\n<\/ul>","rendered":"<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>SOFTWARE RISK MANAGEMENT<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Project risks are defined as the undesirable event, the chance that an event might occur and the consequences of all possible outcomes. Risk management attempts to identify such events, minimize their impact &amp; provide a response if the event is detected.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>LEARNING OBJECTIVES\u00a0<\/strong><\/p>\n<ul>\n<li style=\"text-align: justify\">To identify potential software risks as required by the grading level.<\/li>\n<li style=\"text-align: justify\">To determine the Likelihood and consequences of the safety software failure.<\/li>\n<li style=\"text-align: justify\">To elaborate on risk management policies and process.<\/li>\n<li style=\"text-align: justify\">To establishment of risk thresholds for the safety software application.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>RISK MANAGEMENT PARADIGM<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The risk management includes the following:<\/p>\n<ul>\n<li style=\"text-align: justify\"><strong>Identify: <\/strong>Search for the risks before they create a major problem.<\/li>\n<li style=\"text-align: justify\"><strong>Analyze: <\/strong>Understand the nature, kind of risk and gather information about the risk.<\/li>\n<li style=\"text-align: justify\"><strong>Plan: <\/strong>Convert them into actions and implement them.<\/li>\n<li style=\"text-align: justify\"><strong>Track: <\/strong>We need to monitor the necessary actions.<\/li>\n<li style=\"text-align: justify\"><strong>Control: <\/strong>Correct the deviation and make any necessary amendments.<\/li>\n<li style=\"text-align: justify\"><strong>Communicate: <\/strong>Discuss about the emerging risks and the current risks and the plans to be undertaken.<\/li>\n<li style=\"text-align: justify\"><strong>Planning: <\/strong>Looking for the desired results, the strategies to be applied.<\/li>\n<li style=\"text-align: justify\"><strong>Organizing: \u00a0<\/strong>Getting all the things together so that the desired results are obtained. By organizing the efficiency is increased and lot of time is saved.<\/li>\n<li style=\"text-align: justify\"><strong>Directing: <\/strong>Communication takes place and exchange of ideas is formatted in this phase.<\/li>\n<li style=\"text-align: justify\"><strong>Controlling: <\/strong>In the last phase feedback and evaluation is done.<\/li>\n<\/ul>\n<\/div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">TEAM RISK MANAGEMENT PRINCIPLES<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Team risk management involves two principles which are as follows:<\/span><\/p>\n<div style=\"text-align: justify\">\n<ul>\n<li><strong>Shared \u00a0Product \u00a0Vision<\/strong>: \u00a0The \u00a0common \u00a0goal \u00a0between \u00a0the \u00a0team \u00a0and \u00a0the \u00a0supplier \u00a0is established so that the vision is very lucid.<\/li>\n<li><strong style=\"text-align: initial;font-size: 1em\">Team work: <\/strong><span style=\"text-align: initial;font-size: 1em\">Working collectively towards achieving a common goal. The best way to\u00a0<\/span>snub the risks to some extent is to involve the customers\u2019 right from the beginning and build a team oriented approach.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>RISK MANAGEMENT IN SMALL PROJECT\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Risk Management in small projects comprises of preparing for risks which include external and internal risks such as uncertain requirements, unknown technology, infeasible design, and cost schedule uncertainty. The risks are identified and analyzed to understand the nature of risks and prioritize the risks and try to solve the risks. Mitigation of the risks is done which involves risk acceptance, risk transfer, risk avoidance and risk control.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Assessing the Risk Impact\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">All risks need not be subject to monitoring and control. Scenario Analysis is used to assess the risk event impact. All consequences and their severity are determined if the event happen. When the event is likely to happen during the project is identified and the probability that the risk event will occur is estimated. The difficulty in detecting the event occurrence is determined.<\/p>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-202\" src=\"http:\/\/csp8.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/53\/2018\/07\/Assessing-the-Risk-Impact.png\" alt=\"\" width=\"691\" height=\"292\" \/><\/p>\n<p style=\"text-align: justify\"><strong>Risk response strategies<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Risk response strategies include the following:<\/span><\/p>\n<div style=\"text-align: justify\">\n<ul>\n<li><strong>Mitigating risk: <\/strong>Actions are taken during the project to either reduce the likelihood of a risk or reduce the impact of the risk. For example, testing electrical components after receipt would reduce the likelihood that \u201cbad\u201d parts would be used in a circuit.<\/li>\n<li><strong style=\"text-align: initial;font-size: 1em\">Retaining risk: <\/strong><span style=\"text-align: initial;font-size: 1em\">Risks are retained usually for events with low probability but high impact\u00a0<\/span>when no alternate strategy is feasible. \u00a0A contingency plan is kept ready, in case an event occurs.<\/li>\n<li><strong style=\"text-align: initial;font-size: 1em\">Sharing risk: <\/strong><span style=\"text-align: initial;font-size: 1em\">Multiple units associated with the project assume some portion of the risk.<\/span><\/li>\n<li><strong style=\"text-align: initial;font-size: 1em\">Transferring risk: <\/strong><span style=\"text-align: initial;font-size: 1em\">Risk is assumed and managed by a unit outside the immediate project.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>For example, risks associated with the balloon vehicle are transferred to the project management.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Response development for risks\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A risk response plan identifies the primary components necessary for managing the risk and the response strategy that will be used is identified. Response development involves the understanding and detection of risk event so a response can be triggered. It involves in employing a plan in response to the event occurred and assigns who will be responsible for monitoring and controlling the risk. The response development for risk events, the contingency plan, the action triggered and the assignment of the responsibility is depicted in the following figure.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-304\" src=\"http:\/\/csp8.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks.png\" alt=\"\" width=\"723\" height=\"195\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks.png 1489w, https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks-300x81.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks-768x207.png 768w, https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks-1024x276.png 1024w, https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks-65x18.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks-225x61.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-content\/uploads\/sites\/53\/2018\/07\/Response-development-for-risks-350x94.png 350w\" sizes=\"auto, (max-width: 723px) 100vw, 723px\" \/><\/p>\n<p><strong>Contingency Planning<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em;text-align: initial\">The risks associated with the technical aspects of a project can have the most severe outcomes. It can be mitigated by building and testing prototypes of critical components. The risks can be mitigated by having available backup or alternate designs that have much lower risk. The risks associated with costs usually result from estimate errors and omissions as time &amp; cost are related and the trade-off schedule delays with lower cost. \u201cDescope\u201d options remove components of the project, but still allow the primary mission to proceed.<\/span><\/p>\n<\/div>\n<div style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p><strong>Risk Management\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The risks that occur in a project can be managed by employing the following steps:<\/p>\n<ul>\n<li>Determine risk sources and their categories.<\/li>\n<li>Determine risk parameters.<\/li>\n<li>Establish a risk management strategy.<\/li>\n<li>Identify risks.<\/li>\n<li>Evaluate and prioritize the risks.<\/li>\n<li>Develop and implement risk mitigation plans.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Risk Mitigation\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>An effective strategy for dealing with risk must consider the following three issues (these are not mutually exclusive):<\/p>\n<ul>\n<li>Risk mitigation (i.e., avoidance).<\/li>\n<li>Risk monitoring.<\/li>\n<li>Risk management and contingency planning.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Risk mitigation (avoidance) is the primary strategy and is achieved through a plan. Example: Risk of high staff turnover. The strategy for reducing staff turnover involves meeting with the current staff to determine causes for turnover (e.g., poor working conditions, low pay and competitive job market). Mitigate those causes that are under our control before the project starts. Once the project commences, assume turnover will occur and develop techniques to ensure continuity when people leave. Project teams are organized so that information about each development \u00a0activity \u00a0is \u00a0widely \u00a0dispersed. \u00a0The \u00a0documentation \u00a0standards \u00a0are defined \u00a0and\u00a0<span style=\"font-size: 1em;text-align: initial\">mechanisms are established to ensure that documents are developed in a timely manner. Peer reviews of all work are conducted so that more than one person is &#8220;up to speed&#8221;. The backup staff member for every critical technologist is assigned to avoid risks that arise due to the absence of the critical technologist.<\/span><\/p>\n<\/div>\n<div style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">During risk monitoring, the project manager monitors factors that may provide an indication of whether a risk is becoming more or less likely. Risk management and contingency planning assume that mitigation efforts have failed and that the risk has become a reality. RMMM steps incur additional project cost as large projects may have identified 30 \u2013 40 risks. Risk is not limited to the software project itself but can occur after the software has been delivered to the user.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Software safety and hazard analysis\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">These are software quality assurance activities that focus on the identification and assessment of potential hazards that may affect software negatively and cause an entire system to fail. If hazards can be identified early in the software process, software design features can be specified that will either eliminate or control potential hazards.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>RMMM PLAN\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The RMMM plan may be a part of the software development plan or may be a separate document. Once RMMM has been documented and the project has begun, the risk mitigation, and monitoring steps begin. Risk mitigation is a problem avoidance activity and risk monitoring is a project tracking activity.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Risk monitoring has three objectives that include the assessment whether the predicted risks do, in fact, occur. It ensures that risk aversion steps defined for the risk are being properly applied and collects information that can be used for future risk analysis. The findings from risk monitoring may allow the project manager to ascertain what risks caused which problems throughout the project.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>SEVEN PRINCIPLES OF RISK MANAGEMENT<\/strong><\/p>\n<\/div>\n<ul>\n<li style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\"><strong>Maintain a global perspective \u2013 <\/strong>It involves viewing software risks within the context\u00a0a system and the business problem that is intended to solve.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Take a forward-looking view<\/strong><span style=\"text-align: initial;font-size: 1em\">&#8211; Think about risks that may arise in the future and establish contingency plans.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Encourage open communications <\/strong><span style=\"text-align: initial;font-size: 1em\">&#8211; Encourage all stakeholders and users to point out risks at any time.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Integrate risk management <\/strong><span style=\"text-align: initial;font-size: 1em\">-Integrate the consideration of risk into the software process<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Emphasize a continuous process of risk management <\/strong><span style=\"text-align: initial;font-size: 1em\">&#8211; Modify identified risks which are known and add new risks so better insight is achieved<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Develop a shared product vision <\/strong><span style=\"text-align: initial;font-size: 1em\">&#8211; A shared vision by all stakeholders facilitates better risk identification and assessment.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Encourage teamwork when managing risk <\/strong><span style=\"text-align: initial;font-size: 1em\">&#8211; Pool the skills and experience of all stakeholders when conducting risk management activities<\/span><\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p><strong>RISK RESPONSE PROCESS CONTROL\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The Risk Management Plan should specify the risks, risk responses, and mechanisms used to control the process. Risks must be continuously monitored for risk triggers. Potential risk events should be identified early in a project and monitoring for such events immediately commence. Each risk is assigned to a specific person who has the expertise and authority to identify and provide a response to an event. Risk response process control needs an environment where problems are readily reported, embraced and solved. Changes in any aspect of the project need to be documented and communicated. The authority to approve a change must be assigned and the changes must be communicated to the team. Written forms are employed to track hardware, software and document changes. The members who are notified of changes, when the change is made and the change that is made must be documented.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Summary\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Whenever much is riding on a software project, common sense dictates risk analysis. Yet, most project managers do it informally and superficially, if at all. However, the time spent in risk management results in less upheaval during the project, provides a greater ability to track and control a project and incorporates confidence as plans for problems are devised before problems occur. Risk management can absorb a significant amount of the project planning effort, but the\u00a0<span style=\"font-size: 1em\">effort is worth it.<\/span><\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong>Web Links<\/strong><\/p>\n<ul>\n<li>https:\/\/www.theirm.org\/the-risk-profession\/risk-management.aspx<\/li>\n<li>www.rmmagazine.com\/<\/li>\n<li>https:\/\/www.mcxindia.com\/education-training\/knowledge-series\/risk-management<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Supporting &amp; Reference Materials<\/strong><\/p>\n<ul>\n<li>Roger S. Pressman, \u201cSoftware Engineering: A Practitioner\u2019s Approach\u201d, Fifth Edition, McGraw Hill, 2001.<\/li>\n<li>Pankaj Jalote, \u201cAn Integrated Approach to Software Engineering\u201d, Second Edition, Springer Verlag, 1997.<\/li>\n<li>Ian Sommerville, \u201cSoftware Engineering\u201d, Sixth Edition, Addison Wesley, 2000.<\/li>\n<\/ul>\n","protected":false},"author":4,"menu_order":30,"template":"","meta":{"_acf_changed":false,"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["dr-r-baskaran"],"pb_section_license":""},"chapter-type":[],"contributor":[58],"license":[],"class_list":["post-300","chapter","type-chapter","status-publish","hentry","contributor-dr-r-baskaran"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/chapters\/300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":7,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/chapters\/300\/revisions"}],"predecessor-version":[{"id":416,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/chapters\/300\/revisions\/416"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/chapters\/300\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/wp\/v2\/media?parent=300"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/pressbooks\/v2\/chapter-type?post=300"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/wp\/v2\/contributor?post=300"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp8\/wp-json\/wp\/v2\/license?post=300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}