Thursday, July 15, 2010
Query on CMMI for Development v1.3
Wednesday, July 7, 2010
REQM and RD in the CMMI
Tuesday, July 6, 2010
Implementing CMMI Along With ISO 9001
Friday, March 19, 2010
PPQA After Maturity Level 2
Sunday, December 6, 2009
SCAMPI A Appraisal Questions for FAR Groups
I am looking for some questions based on each Process Area, so the FAR Group Members will be prepared to answer them.
I have searched on Google but not able to find any information. :(
I am not surprised that you have not been able to find what you are looking for on the internet. A Lead Appraiser will not share his or her questions with you. Simply because the Lead Appraiser does not want the interviewees to be trained on what answers to provide, thereby biasing the results of any SCAMPI appraisal. If you and the organization are nervous about the appraisal, don’t be. There is no preparation for the interviews necessary. All that is expected by the Lead Appraiser is that any interviewee should be able to talk about HOW they perform their job duties. If people cannot do that, then the organization is not ready for an appraisal.
If you still feel uneasy, talk to your Lead Appraiser and have him or her conduct a Class B appraisal with interviews. A Class B or SCAMPI B appraisal can function as a dress rehearsal for a SCAMPI A without having the organization and the people worry about “flunking” or “passing” the appraisal. The interviewees will have the experience of being interviewed.
If you still want to perform an internal set of interviews, simply take the CMMI and step through the applicable practices with different groups of people (project managers, configuration managers, developers, testers, etc.) and ask them HOW they perform the Specific and Generic Practices. There is no set of standard questions. Each Lead Appraiser has their own style of questioning interviewees.
Tuesday, December 1, 2009
CMMI Practices for Documentation Teams
Our organization is CMMI Maturity Level 3 Ver 1.2 certified. Our delivery teams are going to implement CMMI practices soon. I did see the processes of the organization and though all the roles appeared from project leader to developer to manager, except for documentation teams. In the same context, I am very curious to see if there are any set of practices to be followed for the documentation department in CMMI as all the processes at CMMI ML2, ML3 are specific to project management, engineering, support, organization areas.
Your question actually raises some other questions:
- What are the roles and responsibilities of your documentation teams and documentation department?
- If this group of people is responsible for the technical documentation (e.g. requirements, design, etc.) and the user documentation, how and why were they excluded from your ML 3 SCAMPI A?
- How are the delivery teams different from the organization that achieved Maturity Level 3?
What is puzzling with your question is that REQM, RD, TS, PI, and CM cover the different aspects of writing and controlling the various documents associated with designing, developing, maintaining, operating, using, and deploying products. And then VER covers the inspection/review of the documents before placing them in the baseline and controlling them with CM.
It does appear from your description that your organization omitted the documentation people as a process role from your process documentation. In my opinion, at a minimum, your PPQA audits should have identified this omission long before your SCAMPI A appraisal. Then your Lead Appraiser should have identified this gap during the appraisal planning process before the SCAMPI A and should have taken steps to address the gap or postponed your appraisal until the documentation group was included in the scope. Since your documentation group was apparently not included in the scope of your appraisal, this oversight also calls into question your Lead Appraiser’s credentials and quite possibly the validity of your SCAMPI A results.
The bottom line, in my opinion, and based on only what you stated, your documentation group should have been included in the scope of your ML 3 SCAMPI A. Even if all they do is Document Configuration Control (which would be covered under CM) or Document Quality Assurance (which would be covered under PPQA).
The answers to my above questions could provide additional information that would change my opinion.
Thursday, August 13, 2009
Rationale for Maturity Level 5
The question that needs to be asked is why does your organization want to achieve Maturity Level 5 (ML 5)? If the organization has already achieved Maturity Level 3 (ML 3), what is the motivation for achieveing ML 5? Most likely it is not mandated in a contract or by its customers. But achieving ML 5 is desirable to be competitive in the marketplace. Therefore, the reasons for achieving ML 5 should provide some indication of the short term and long term benefits.
The first step in becoming a High Maturity organization is defining your Quality and Process Performance Objectives (QPPOs) that are based on your business goals and objectives as well as your customer needs. The QPPOs should be stated in a form such that they specify a timeframe. And that information will provide some ideas of the short term and long term benefits.
However, the best advice that I can provide is to hire an SEI-certified High Maturity Lead Appraiser (HMLA) who will work with you to help explain the benefits of ML 5 to the CEO. The HMLA should have experience working with many different organizations at various Maturity Levels and be able to talk about the different challanges that have been faced by other organizations, as well as the challenges and risks within your organization.
At this point, it sounds like your organization is just beginning its journey to ML 5, so I would have to be convinced that your processes are stable enough to provide the data needed to quantify any short term and long term benefits. I think that the best you could do at this point is communicate this information in qualitative terms. Any quantitative information may not be accurate until you have implemented High Maturity.
Friday, August 7, 2009
Identifying Risks
What is the difference between PP SP 2.2 Identify Project Risk and RSKM SP 2.1 Identify Risks?
What you are asking about is one of the basic differences between Maturity Level 2 (ML 2) and Maturity Level 3 (ML 3). Project Planning (PP) is a ML 2 Process Area (PA) and Risk Management (RSKM) is a ML 3 PA. At ML 2, the project only needs to be able to identify risks and that is what PP Specific Practice (SP) 2.2 addresses. At ML 3, RSKM builds upon the foundation of identifying and tracking risks put in place by PP and Project Monitoring and Control (PMC). RSKM SP 2.1 therefore builds upon PP SP 2.2 by adding more rigor for risk identification. Just read the informative material and sub-practices for both SPs and you will immediately see and understand the difference.
Monday, August 3, 2009
Software Sizing
I would strongly urge you to forget the ML 3 Process Areas until you have mastered ML 2. There is a fundamental difference between how a ML 2 Project Manager approaches Project Planning (PP) and Project Monitoring and Control (PMC) vs. a ML 3 Project Manager. Estimation being one of the differences. Use Case Points and Functions Points are fairly sophisticated concepts and there are challenges with getting consistency in determining what each of these things are. I would recommend that you take a step back from the model and the projects and look at your historical project data. Use the actual effort, costs, etc. from previous projects to estimate a new project. Forget about Use Case Points and Function Points for now. Once you have mastered being able to use historical information to build an empirical estimation model, then it might make sense to add a layer of sophistication by considering Use Case Points or Function Points.
Another recommendation is let the Project Manager create the project estimates and then review them with the practitioners as a sanity check rather than ask the practitioners to create the estimates. Over time as the organization gains experience estimating projects etc., then it makes sense to involve the practitioners up front in the estimation process. You have to learn to crawl first with estimation before you can sprint with the big boys.
Thursday, July 30, 2009
Why SAM is excluded ?
Supplier Agreement Management (SAM) is not excluded from the CMMI-DEV or CMMI-SVC. When you say L3, I assume you mean Maturity Level 3 and SAM is definitely NOT excluded from ML 3. If, however, the Lead Appraiser in working with the organization determines that SAM is not applicable to the work performed by the organization, SAM will be considered Not Applicable to the scope of the appraisal. And that could be at any Maturity Level. Please read previous my posts regarding SAM for more information. http://ppqc.blogspot.com/2009/04/excluding-supplier-agreement-management.html and http://ppqc.blogspot.com/2009/07/cmmi-novice-question.html
Tuesday, July 28, 2009
Measurement and Analysis vs. Generic Practice 2.8
This is a good question. So let’s take a step backwards and look at the CMMI and Generic Practice – PA Relationships. The summary table in the Generic Practice section of the model clearly states that Project Monitoring and Control (PMC) can implement GP 2.8 for all project-related processes. And MA provides general guidance about measuring, analyzing, and recording information that can be used in establishing measures for monitoring actual performance of the process. Please note that this information is GUIDANCE and part of the INFORMATIVE material. Therefore, it is not required that the org use MA for GP 2.8. HOWEVER, from a practical point of view, why would MA be part of the model if there wasn’t a requirement and expectation that it would be implemented? Since it is a ML 2 PA and you are asking about ML 3, as a Lead Appraiser I would expect to see that MA was used for defining, collecting, analyzing, and reporting both the project and process measures. Without implementing MA for the process measures, the org would be receiving little to no benefit from GP 2.8. And as I have seen GP 2.8 implemented, sometimes the process measures are embedded in the project measures that have been defined using MA.
Wednesday, May 20, 2009
Levying CMMI Requirements on Your Suppliers
The answer is yes. The acquirer can specify any requirements they want the vendors to meet. In my experience, I have seen acquirers specifying that the bidders be either at ML 2 or ML 3. What this means though is that the acquirer has done its homework and appropriately determined the necessary Maturity Level for the vendor to support the acquirer’s business and quality goals and objectives. There should be a good match between the ML of the acquirer and the ML of the vendor, to work well it may be best if both organizations are at the same ML. Otherwise, there can be problems.
As the acquirer, you probably would find benefit from implementing the CMMI for Acquisition (CMMI-ACQ). The CMMI-ACQ provides a lot of guidance for tenders and contracts that meet the acquirer’s needs.
Tuesday, March 10, 2009
Evaluating the CMMI for Services
A major problem I see in CMMI-SVC, is the disregarded sufficient differentiation of practices over different maturity levels. Maybe I´m wrong with my opinion and someone can help me fixing this mess.
I´d like to give a background for a better understanding o f what I mean:
- In my opinion many (internal) IT service units in mid-size companies don´t have any official agreements (nor contracts) with their business customer to specify service content, service levels or support. Sometimes these things are partly available and if at all, then often are informally and silently accepted.
- In such (above) described IT service units you will find quite often an official HelpDesk (mostly official because it´s a specific function within IT) or minimum some guys necessary for service support (like handling service incidents) to keep the business process running.
Now take a look at the CMMI-SVC Process Areas and their associated Maturity Levels. You will find Service Development (SD) at Maturity Level 2 including specific practices:
SP 1.1 Analyze Existing Agreements and Service Data
SP 1.2 Establish the Service Agreement
SP 2.1 Establish the Service Delivery Approach
SP 2.2 Prepare for Service System Operations
SP 2.3 Establish a Request Management System
SP 3.1 Receive and Process Service Requests
SP 3.2 Operate the Service System
SP 3.3 Maintain the Service System
and you will find Incident Resolution and Prevention (IRP) at maturity level 3 including specific practices:
SP 1.1 Establish an Approach to Incident Resolution and Prevention
SP 1.2 Establish an Incident Management System
SP 2.1 Identify and Record Incidents
SP 2.2 Analyze Incident Data
SP 2.3 Apply Workarounds to Selected Incidents
SP 2.4 Address Underlying Causes of Selected Incidents
SP 2.5 Monitor the Status of Incidents to Closure
SP 2.6 Communicate the Status of Incidents
SP 3.1 Analyze Selected Incident Data
SP 3.2 Plan Actions to Address Underlying Causes of Selected Incidents
SP 3.3 Establish Workarounds for Selected Incidents
To come to an end I would expect that it is an essential part of any IT unit to solve service incidents, to fulfill the main goal of the company, and keep the business process working. Therefore I would assign half of the listed IRP practices to Maturity Level 2 and would other way around assign half of the SD practices to Maturity Level 3. The CMMI-SVC therefore seems for me to be not sufficient in differentiating practices over Maturity Levels, and would lead to the conclusion that CMMI-SVC is not useful for Maturity Level determination.
I appreciate any explanation if there is a misunderstandig or if there exists a grain of truth.
Your position is much the same as the kind of statements we heard regarding the engineering practices being at ML 3 in the CMMI-DEV. Just because these practices are at ML 3 does not mean that they are not important and are probably even performed at ML 1. What you have to bear in mind is that the CMMI is a set of process improvement guidelines , as well as the definition and purpose of ML 2 and ML 3. At ML 2, projects establish the foundation for an organization to become an effective service provider by institutionalizing basic project management and service establishment and delivery practices. Basically, ML 2 is about gaining control over the projects and service delivery and that is why there is only one service PA at ML 2. You have to get delivery under control before you can focus improving the other aspects of services like Incident Resolution and Prevention. And at ML 3, service providers use defined processes for managing projects. They embed tenets of project management and services best practices, such as service continuity and incident resolution and prevention, into the standard process set.
Monday, March 9, 2009
Moving to Maturity Level 4
I can give you a list of items and practices that you need to have in place, but that is not enough. I highly recommend that you and your company hire a High Maturity Lead Appraiser and/or consultant and have them work with you to implement OPP and QPM. I also suggest that you take the SEI’s Understanding CMMI High Maturity Concepts or equivalent. This class will greatly help your understanding of ML 4 and ML 5. You will need to have someone on your staff that has a good understanding of statistics and statistical methods to help you build your Process Performance Baselines (PPBs) and Process Performance Models (PPMs) that support your Quality and Process Performance Objectives (QPPOs). In addition, in order for all this to work, your processes have to be stable so you can perform meaningful statistical analyses. This also means having a repository of historical data from the stable processes. So not only do you need expert help, you also need a sufficient amount of historical data, which could range from months to years in order to achieve ML 4.
Friday, October 3, 2008
What is the cost of a CMMI v1.2 L3 certification?
- What are the costs involved (Internal & External)?
- Are there any SEI cerfication bodies in India?
The answers to your questions are highly variable depending on the size and scope of your organization and your geographical location. The best place to obtain realistic estimates is to ask several local SEI-authorized CMMI consulting and appraisal providers for their cost proposals, then you will have a handle on the external costs. Internal costs really cannot be determined until you figure out how much work you have to do in order to implement the CMMI and prepare for an appraisal. Suffice it to say, your internal costs will most likely be greater than your external costs.
Tuesday, September 30, 2008
Query on Process Change Management
Now, my questions are:
- Will adopting the practices prescribed by a new department head, which is based on his experiences, affect his subordinates' work( who are the actual practitioners) in an adverse manner?
- Will organic growth of existing practices (due to collective experience of the practitioners) be ruined due to implementing new practices?
- Will allowing practice changes from new department heads make an organisation fall behind from process to people driven? (even though this may last until the organisation get accustomed to the new practices) And is this permissible, if we consider the organisation's overall development?
First off, the impacts depend upon the organization’s Maturity Level. A Maturity Level 2 organization doesn’t necessarily have standard procedures for all projects to follow, though I have seen many ML 2 organizations take this approach. Therefore at Maturity Level 2 you can have multiple ways of doing the same thing, from project to project and from manager to manager.
When the organization matures to Maturity Level 3, the premise is that the organization has examined the multiple ways of performing a given practice and determined the Best Practice for the organization and then documents these Best Practices as the set of standard processes for the organization. This examination, coordination, and distribution of the standard processes is typically the responsibility of the Process Group. The Process Group manages the processes and is responsible for coordinating all process changes.
Now having said this, a new department head can make any process changes he or she wants to make. At ML 2 these changes could provide a Best Practice for consideration or additional information on things not to do. However, at ML 3 the organization should have established OPF and OPD processes for making process changes. The new department head would have to follow these change processes to propose his new processes. The Process Group would evaluate his proposals and pilot them as appropriate so the changes could be evaluated in a controlled manner. The outcome of the pilot(s) would determine whether or not the changes are made.
By following these steps, there shouldn’t be any of the problems you allude to in your note. However, if your organization does not have processes in place for making changes to the organization’s processes or the new department head mandates process changes without following the process, then you do have some serious issues to address.
- Making uncontrolled process changes will impact the practitioners, most likely adversely. People most likely will be frustrated because of the changes.
- Replacing existing procedures with new ones in an uncontrolled manner will adversely disrupt any process improvements and process evolution you have already made.
- Making uncontrolled process changes can cause the organization to regress in Maturity Levels, probably drop from whatever ML you are currently at to ML 1.
Monday, August 25, 2008
Full Time Resources for Implementing the CMMI
I have been asked to estimate the number of full time resources required by my company to facilitate its drive to Maturity Level 3 PM, SYS, SW, HW and ACQ. Is there any documentation or published information that will help in putting together a robust estimate of resources required?
First and foremost the driving factor for estimating the number of full time resources needed to implement the CMMI is the size of the organization. Over time we have seen that it takes 3 – 5% of the organization to perform PPQA, 3- 5 % of the organization to perform CM, and 3 – 5% of the organization to perform the necessary CMMI implementation activities.
So, if your organization is about 20 – 30 people, then you may only need one full time resource. However, if your organization is about 100 people, then you may need 3 to 5 full time resources.
Other factors contributing to this estimate is how strong a ML 2 foundation is already in place and how much of what you currently have in place is at ML 3. Documenting the processes and procedures is the easy part, and it can be done by a small core group. The larger task is deploying the new processes and process assets and having people use them to change how they approach their jobs.