Software Test & Evaluation Summit/Workshop Review

Similar documents
Advancing the Role of DT&E in the Systems Engineering Process:

Defense Engineering Excellence

NDIA SE Conference 2016 System Security Engineering Track Session Kickoff Holly Dunlap NDIA SSE Committee Chair Holly.

DoD Software Assurance Initiative. Mitchell Komaroff, OASD (NII)/DCIO Kristen Baldwin, OUSD(AT&L)/DS

Department of Defense (DoD) Joint Federated Assurance Center (JFAC) Overview

Systems Engineering Division

DoD Strategy for Cyber Resilient Weapon Systems

Introducing Cyber Resiliency Concerns Into Engineering Education

T&E Workforce Development

Engineering for System Assurance Legacy, Life Cycle, Leadership

Information Systems Security Requirements for Federal GIS Initiatives

Implementing a Modular Open Systems Approach (MOSA) to Achieve Acquisition Agility in Defense Acquisition Programs

Systems Engineering for Software Assurance

Instructions for Completing a Key Leadership Position Joint Qualification Board Application

Modularity and Open Systems: Meaningful Distinctions

Security and Privacy Governance Program Guidelines

Cybersecurity in Acquisition

Achieving DoD Software Assurance (SwA)

Risk Management Framework for DoD Medical Devices

Acquisition and Intelligence Community Collaboration

American Society for Quality

9 th Annual NDIA Systems Engineering Conference 2006

DoD Software Assurance (SwA) Update

2016 SPONSORSHIP OPPORTUNITIES

INTEGRITY ASSURANCE: Safety/Security Extensions to CMMI and icmm

Appendix 12 Risk Assessment Plan

Systems Engineering Update/SD-22

IT123: SABSA Foundation Training

ROS-M Summary NDIA GRCC 2017

Retrofitting Ground Systems to improve Cyber Security

Cloud-based Open Architecture Approach for Common Enterprise Ground Services

Solutions Technology, Inc. (STI) Corporate Capability Brief

Building an Assurance Foundation for 21 st Century Information Systems and Networks

SYMANTEC: SECURITY ADVISORY SERVICES. Symantec Security Advisory Services The World Leader in Information Security

NDAA Section 804 Accelerated Test, Evaluation and Certification What is it and How Will it Impact IT Acquisitions?

PECB Certified ISO Lead Auditor. Master the Audit of Occupational Health and Safety Management System (OHSMS) based on ISO 45001

DoD SPēD Certification Program 21 July 2016

CMPIC s CM Training & Certification Courses

RISK MANAGEMENT Education and Certification

The Success of the AMRAAM DBMS/DAS

Association for International PMOs. Expert. Practitioner. Foundation PMO. Learning.

An Overview of TOGAF Version 9.1

Joint Federated Assurance Center (JFAC): 2018 Update. What Is the JFAC?

Progress Report National Information Assurance Partnership

Appendix 12 Risk Assessment Plan

The Perfect Storm Cyber RDT&E

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive

ISTE SEAL OF ALIGNMENT REVIEW FINDINGS REPORT

Revitalizing Education and Training in Systems Engineering

Assessing the impacts of Amended Toxic Substances Control Act (TSCA) to the DoD Mission and the Defense Industrial Base (DIB)

IT Consulting and Implementation Services

Request for Proposal To develop and teach a Training Course on RTCA Airworthiness Security Documents (DO-326A, DO-355, and DO-356A)

Course Fees: 850 euro

Defining IT Security Requirements for Federal Systems and Networks

Master the implementation and management of a Cybersecurity Program based on ISO/IEC 27032

Impact of Enterprise Security Risk Assessments on Integrators & Manufacturers. J. Kelly Stewart Steve Oplinger James Marcella

Test Resource Management Center Directed Energy T&E Conference A Joint DEPS ITEA Event

Training Catalog. Decker Consulting GmbH Birkenstrasse 49 CH 6343 Rotkreuz. Revision public. Authorized Training Partner

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

Simplifying IT through Virtualization

Test and Evaluation Methodology and Principles for Cybersecurity

U.S. Air Force. Digital Engineering Applications to Developmental Test & Evaluation. Dr. Ed Kraft. October 24, 2016

2016 NCCA Standards Revisions Recap and Takeaways: What You Need to Know

Workshop IT Star IT Security Professional Positioning and Monitoring: e-cfplus support

Continuous Monitoring & Security Authorization XACTA IA MANAGER: COST SAVINGS AND RETURN ON INVESTMENT IA MANAGER

FPM-IT-420B: FAC-P/PM-IT Planning & Acquiring Operations of IT Systems Course Details

DoDD DoDI

Reference Framework for the FERMA Certification Programme

Dell helps you simplify IT

Association for International PMOs. Expert. Practitioner. Foundation PMO. Learning.

Workshop 71: Is Your Financial System Ready? An Overview of Effective Federal Information System Controls Audit Manual (FISCAM) Assessments

Certified CMMI Professional Renewal Policy & Required Activities

Engineering Practices for System Assurance

US Air Force Initiative to Enhance Hypersonic Test Capabilities

Dr. Steven J. Hutchison Principal Deputy Developmental Test and Evaluation

OFFICE OF THE UNDER SECRETARY OF DEFENSE 3000DEFENSEPENTAGON WASHINGTON, DC

ESCO Training Dynamic Investment Grade Calculation

MANAGING PROJECTS USING PMI S STANDARDS. Facilitated by Mr. Andreas Solomou. 12, 19, 26 November and 3, 10 December :30 17:00

The Smart Campaign: Introducing Certification

Audit and Compliance Committee - Agenda

Practical Design of Experiments: Considerations for Iterative Developmental Testing

State of Security Operations

Click to edit Master title style

SMC/RN Compatible Satellite C2 (Sat C2) GSAW Vinay Swaminathan SMC/RN

Security Metrics Establishing unambiguous and logically defensible security metrics. Steven Piliero CSO The Center for Internet Security

Graduate Systems Engineering Programs: Report on Outcomes and Objectives

Welcome. Chris Sortzi, VP of Public Sector RightNow Technologies. March 19, RightNow Technologies, Inc.

IT Risk Management and Cybersecurity Summit

Data Governance Central to Data Management Success

An Accelerated Approach to Business Capability Acquisition for the Montgomery IT Summit. Presented by: Mr. Paul Ketrick May 19, 2009

Larry Clinton President & CEO (703)

Model-Based Systems Engineering Backbone of the Thales Engineering Manifesto

CMMI Institute Policy 0032 Publication Date 06 January 2016 CMMI V1.3 Renewal Process for the Certified CMMI

Master the Audit of Information Security Management Systems (ISMS) based on ISO/IEC 27001

29 th Annual ITEA Symposium Testing at the Speed of Need

ISO Lead Auditor Training

ISO9001:2015 LEAD IMPLEMENTER & LEAD AUDITOR

The Widening Talent Gap: The greatest security challenge of our time

Enhancing the Cybersecurity of Federal Information and Assets through CSIP

International Atomic Energy Agency Meeting the Challenge of the Safety- Security Interface

Transcription:

Software Test & Evaluation Summit/Workshop Review The Summit/Workshop was facilitated by the NDIA Systems Engineering Division s Software Industry Experts Panel and the Developmental Test and Evaluation Committee October 26-29, 2009 12 th Annual NDIA SE Conference 1

Basis for SW T&E Summit/Workshop NDIA SE Division s SW Committee report completed in September 2006 Top Software Engineering Issues in the Defense Industry Key Theme of the Report Current approaches for acquiring, developing, verifying and sustaining software enabled systems are inadequate to deal with the complexities of a dynamic and changing acquisition environment. Requested to identify top five issues Actually came up with seven October 26-29, 2009 12 th Annual NDIA SE Conference 2

Top Seven SW Engineering Issues 1. The impact of requirements upon software is not consistently quantified and managed in development or sustainment. 2. Fundamental system engineering decisions are made without full participation of software engineering. 3. Software life-cycle planning and management by acquirers and suppliers is ineffective. 4. The quantity and quality of domain-knowledgeable software engineering expertise is insufficient to meet the demands of government and the defense industry. 5. Traditional software verification techniques are costly and ineffective for dealing with the scale and complexity of modern systems. 6. There is a failure to assure correct, predictable, safe, secure execution of complex software in distributed environments. 7. Inadequate attention is given to total lifecycle issues for COTS/NDI impacts on lifecycle cost and risk. October 26-29, 2009 12 th Annual NDIA SE Conference 3

Issue 5 Description Traditional software verification techniques are costly and ineffective for dealing with the scale and complexity of modern systems discussion points: Over-reliance on testing alone rather than robust SW verification techniques. Manual testing techniques are labor-intensive, scale poorly, and are unproductive relative to the large investment of resources. Compliance-based tests do not adequately cover risks or failure conditions. Tests are over-documented with disproportionate effort on detailed procedures. Education, training, certifications are inadequate to develop effective test skills. October 26-29, 2009 12 th Annual NDIA SE Conference 4

Issue 5 Recommendation Study current software verification practices in industry, and develop guidance and training to improve effectiveness in assuring product quality across the life cycle. Sponsor a study of state-of-the-practice verification and testing approaches. Review/update testing policies and guidance to emphasize robust, productive approaches that maximize ROI. Review adequacy of verification plans/approaches early in the acq. life cycle. Emphasize skilled investigation throughout the life cycle, based on coverage, risk mitigation, high volume automation. Strengthen curricula, training, certifications, career incentives for testing roles. October 26-29, 2009 12 th Annual NDIA SE Conference 5

Summit/Workshop Objective To recommend policy and guidance changes to the Defense enterprise to emphasize robust and productive software Testing and Evaluation (T&E) approaches in Defense acquisition. October 26-29, 2009 12 th Annual NDIA SE Conference 6

Location & Attendance Hotel: Hyatt in Reston Town Center, VA Dates: September 15-17, 2009 110 Registered Attendee 9 no-shows Approx. 80 stayed to the end of last day! Better than expected participation! October 26-29, 2009 12 th Annual NDIA SE Conference 7

Day 1 Agenda 8:00 Introduction Why this Summit/Workshop 8:10 Government Presentations 9:50 Break 10:15 DoD Industry Panel 11:45 Lunch & Speaker 12:45 SW Test Industry Experts 2:25 Break 2:50 SW Test Industry Experts 4:30 Adjourn October 26-29, 2009 12 th Annual NDIA SE Conference 8

Day 2 Agenda 8:00 Re-Cap Day 1 8:10 DoD Services Panel 9:45 Introduction of Workshops 10:00 Break 10:30 Workshops 12:00 Lunch & Speaker 1:00 Workshops 2:30 Break 3:00 Workshops 4:30 Adjourn October 26-29, 2009 12 th Annual NDIA SE Conference 9

Day 3 Agenda 8:00Re-Cap Day 2 8:10 Introduction of Workshop Leaders 8:15 Presentation of Issues and Recommendation by Workshop Leaders 9:45 Break 10:00 Way Forward Discussion & Final Q&A s Final Summit/Workshop Product defined 11:00 Adjourn October 26-29, 2009 12 th Annual NDIA SE Conference 10

Speakers Morning Day 1 Framing the DoD Software T&E Issues Dr. Ernest A. Seglie, Chief Science Advisor, DOT&E Mr. Chris DiPetto, Acting Director, DT&E Ms. Kristen Baldwin, Director for System Analysis, OD, DR&E October 26-29, 2009 12 th Annual NDIA SE Conference 11

Speakers Morning Day 1 Panel: Framing the Industry Software T&E Issues Mr. Edgar Doleman, CSC Mr. Bruce Casias, Raytheon Mr. Tom Wissink, Lockheed Martin October 26-29, 2009 12 th Annual NDIA SE Conference 12

Speakers Afternoon Day 1 Lunch: Mr. Paco Hope, Cigital Software Security in Defense T&E Dr. Cem Kaner, Florida Institute of Technology Challenges in the Evolution of Software Testing Practices in Mission-Critical Environments Dr. Adam Kolawa, Parasoft Software Development Management Mr. Rex Black, RBCS Risk-Based Testing Mr. Hung Nguyen, Logigear Software Testing & Test Automation October 26-29, 2009 12 th Annual NDIA SE Conference 13

Speakers Morning Day 2 Panel: Framing the Services Software T&E Issues Dr. James Steilein, US Army Test and Evaluation Command Dr. Steve Hutchison, Defense Information Systems Agency (DISA) Mr. Mike Nicol, Aeronautical Systems Center, Wright-Patterson AFB Lunch: Mr. Richard Kuhn, NIST Combinatorial Testing October 26-29, 2009 12 th Annual NDIA SE Conference 14

Remainder of Day 2 Workshops Three Key Challenge Areas (KCA): 1. How Much T&E is Enough Risk considerations, Installed System T&E, Instrumentation, Reliability, Completion Criteria, Coverage and C&A 2. Lifecycle and End-to-End Software Testing How does SW T&E get involved in early development (i.e. left-hand side of the V-model and I&T deliverables 3. Changing Paradigms Open Architecture, COTS, SOA, SoS, SaaS, Legacy plus New, Security October 26-29, 2009 12 th Annual NDIA SE Conference 15

Remainder of Day 2 Workshops Four Focus Areas for each KCA: 1. Review, revise, improve RFP Language (Including T&E activities/deliverables in Competitive Prototyping) 2. Training, Competency Model, Human Capital 3. Policy, Guidance & Standards 4. Tools/Automation, Methodologies & Processes October 26-29, 2009 12 th Annual NDIA SE Conference 16

Results of Workshop Raw Data Issues 1. Workshop #1 108 2. Workshop #2 51 3. Workshop #3 20 Total 179 Recommendations 1. Workshop #1 44 2. Workshop #2 29 3. Workshop #3 13 Total 86 Participants 1. Workshop #1 30 2. Workshop #2 31 3. Workshop #3 25 Total 86 October 26-29, 2009 12 th Annual NDIA SE Conference 17

Results of Workshop Raw Data Recommendations by Focus Area 17 for FA #1 Revise/Improve RFPs & T&E Deliverables 23 for FA #2 Training, Human Capital, Competency Models 22 for FA #3 Policies, Guidance & Standards 17 for FA #4 Tools/Automation, Methodologies & Processes 7 for FA #5 Costs, Software, Studies, Organization October 26-29, 2009 12 th Annual NDIA SE Conference 18

Way Forward This is a Joint effort of the NDIA s SE Division DT&E Committee and the Software Industry Experts Panel 1.Workshop #1 Team to complete Recommendation Generation by October 9 (Done) 2.In parallel with the Item 1 generate draft outline for the SW T&E Summit/Workshop White Paper (Done) 3.Review and correlate Workshops 1, 2 and 3 issues and recommendations Update White Paper outline if needed 4. Generate Initial White Paper Completion goal December 4, 2009 October 26-29, 2009 12 th Annual NDIA SE Conference 19

Q & A SW T&E Summit/Workshop Presentations: www.ndia.org/divisions/divisions/systemsengineering/pages/test_and_evaluation_committee.aspx October 26-29, 2009 12 th Annual NDIA SE Conference 20