The Standish Group

Reliable Software Technologies

Computer Risks to the Public

SofRel Inc

Adelard

Carnegie Mellon

HISSA

A falha de software do Ariane

Safeware Engineering corporation

DLSF Systems Inc

IEEE Technical Committee on Software Reliability Engineering

NASA - Software Assurance Technology Center

Using COTS Software in Systems Development

Centers for Software Reliability (UK)

DoD-System Safety Program Requirements

 

 

The Standish Group

Estrelas: *****

O que é:

 standish group realiza investigações e sondagens de mercado/tecnologia para utilizadores e fornecedores de aplicações críticas na área de OLTP (On-Line Transaction Processing) e ambientes cliente/servidor. Entre os seus clientes encontram-se várias companhias Fortune 500, agências governamentais e Universidades.

Informação interessante: Há alguns relatórios do grupo "online", mas o mais interessante é o já famoso "Chaos" ( http://www.standishgroup.com/chaos.html ) que se debruça sobre o actual caos no desenvolvimento de software nas empresas. Dados estatísticos mostram que nos EUA 37% dos projectos de software chegam a um beco sem saída e são cancelados!. Fique a saber porquê! O "Chaos" identifica as características principais dos projectos que falham, os principais factores que levam a esse falhanço e os ingredientes necessários para minorar as possibilidades de falhanço. O Standish Group oferece um serviço (COMPASS), mediante uma subscrição anual, que se destina a assistir os gestores de TI na avaliação e aquisição de tecnologia crítica para o negócio.

Mais informações em http://www.standishgroup.com


Reliable Software Technologies
Estrelas: ****

O que é:

 RST é uma empresa (EUA-Virginia) que fornece ferramentas e serviços de suporte ao desenvolvimento e teste de sistemas críticos de software tendo em vista a sua qualidade (reliability, safety, and security). Clientes importantes da RST são a NASA, Microsoft e Hughes.

Informação interessante: Há bastantes artigos online em http://www.rstcorp.com/paper_subject.html , e descrição detalhada das ferramentas comerciais da RST de suporte à fiabilidade de software.A WhiteBox inclui ferramentas para a automatização da geração de casos de teste, testes de mutação, identificação de módulos críticos a serem testados intensivamente, etc...A WhiteBox vai em breve ser utilizada internamente pela Microsoft no seu processo de desenvolvimento de software.

Mais informações em http://www.rtscorp.com


Computer Risks to the Public
Estrelas: ***

O que é:

 Um forum de discussão moderado sobre os riscos da utilização de computadores mantido pelo ACM Committee on Computers and Public Policy. É o acesso web ao grupo de discussão comp.risks.

Informação interessante: Nos arquivos do forum há dados interessantes sobre desastres e problemas causados pelo mau funcionamento de computadores e software.

Mais informações em http://catless.ncl.ac.uk/Risks


SofRel Inc
Estrelas:***

O que é:

 SoftRel é uma empresa (EUA) que presta serviços na área de fiabilidade de software: avaliação de processos de desenvolvimento de software, fault tree analysis, testes de módulos e sistemas, suporte à formulação de propostas nos aspectos em que a fiabilidade do projecto é determinante, inspecções de código, etc...

Informação interessante: Informação sobre cursos em fiabilidade de software, publicações e um livro online: System Software Reliability Assurance Notebook.

Mais informações em http://www.softrel.com


Adelard
Estrelas: **

O que é:

 Adelard é uma empresa de consultadoria (UK) na área de assurance e safety de sistemas computacionais que produziu vários standards e guias para a produção de software fiável.

Informação interessante: Cursos sobre análise de riscos, métodos formais e técnicas para desenvolvimento de software. Algumas publicações teóricas na área de fiabilidade de software.

Mais informações em http://www.adelard.co.uk


Carnegie Mellon Software Engineering Institute
Estrelas: *****

O que é:

 SEI é um núcleo de excelência em engenharia de software, talvez o mais famoso em todo o mundo. Modelos como o CMM - Capability Maturity Model e CERT , entre outros, foram registados pelo SEI.

Informação interessante: Publicações, guias, livros, FAQs e um repositório com casos práticos dos programas do SEI sobre Gestão de Risco e confiabilidade. Há um arquivo de informação relevante para software confiável em ( ftp://ftp.sei.cmu.edu/pub/depend-sw ) e uma mailing list ( para subscrever envie um mail para weinstoc@sei.cmu.edu, para enviar uma mensagem para a lista use depend-sw@sei.cmu.edu).

Mais informações em http://www.sei.cmu.edu


HISSA - High Integrity Software System Assurance
Estrelas: ****

O que é:

 HISSA faz parte do National Institute of Standards and Technology.- NIST ( http://www.nist.gov/). Este projecto do NIST destina-se ao fornecimento de tecnologia que proporcione o desenvolvimento de software de alta integridade com custos razoáveis. O trabalho incide sobre as linhas de orientação para processos de desenvolvimento e manutanção de software de qualidade.

Informação interessante: Algumas publicações interessantes online, embora menos do que desejado. Exemplos são um artigo/guia sobre a utilização de C++ em safety critical systems.

Mais informações em http://hissa.nist.gov


A falha de software do Ariane que custou 500 milhões de USD!

Estrelas: *****

O que é:

 O Relatório de 19 Julho de 1996 que explica em detalhe o que falhou no lançamento do ARIANE 5 - voo 501 da Agência Espacial Europeia ( http://www.esrin.esa.it ).

Mais informações em http://www.esrin.esa.it/htdocs/tidc/Press/Press96/ariane5rep.html


Safeware Engineering Corporation
Estrelas: **

O que é:

 Safeware é uma companhia spin-off do grupo de software safety ( http://www.cs.washington.edu/research/projects/safety/www ) da Universidade de Washington que fornece serviços e ferramentas na área de real-time safety critical software systems.

Informação interessante: Informação sobre cursos ministrados pela safeware e técnicas utilizadas na sua actividade.

Mais informações em http://www.safeware-eng.com


DLSF Systems Inc
Estrelas: ***

O que é:

 DLSF é uma companhia Canadiana que se dedica a consultadoria em software safety. Esta companhia tornou-se conhecida por ter dado assistência na sequência dos problemas com o equipamento médico Therac-25 (http://tor-pw1.netcom.ca/~dlsf/therac25.html ).

Informação interessante: Informação sobre cursos e seminários organizados pela DLSF, auditorias de software, análise pos-design e pos-acidente do género "equipa de salvamento2" quando as coisas falham mesmo a sério.

Mais informações em http://tor-pw1.netcom.ca/~dlsf/intro.html


NASA - Software Assurance Technology Center
Estrelas: ****

 O que é:

 Standards e guias online relacionados com a qualidade de software, inspecções e gestão (http://satc.gsfc.nasa.gov/Info/wstdgdb.html) assim como descrição de ferramentas e metodologias utilizadas pela NASA.

Mais informações em http://satc.gsfc.nasa.gov


Using COTS Software in Systems Development
Estrelas: ****

 O que é:

 Página do Institute for Information Technology, Software Engineering Group do Canadá.

Informação interessante: Relatórios e outros documentos produzidos no âmbito de um projecto que pretende compreender as implicações do uso de componentes de software COTS (common off-the-shelf) na construção de sistemas mais complexos. Critérios para a avaliação de componentes COTS, vantagens/desvantagens do uso de COTS.

Mais informações em http://wwwsel.iit.nrc.ca/projects/cots/COTSpg.html


Centers for Software Reliability (UK)
Estrelas: ****

 O que é:

 CSR é um centro de investigação da Universidade de Newcastle e da também da City (UK).

Informação interessante: Resumos do conteúdo de algumas dezenas de livros sobre Fiabilidade de software publicados pelos membros do CSR. Embora estejam disponíveis as referências bibliográficas de muitos artigos, estes não estão dísponiveis online (uma pena!). O CSR também oferece cursos de formação/actualização vocacionados para a Indústria.

Mais informações em http://www.csr.ncl.ac.uk (Newcastle) e em http://www.csr.city.ac.uk(City)


DoD - System Safety Program Requirements
Estrelas: ***

O que é:

 DoD é o "Department of Defense" dos EUA.

Informação interessante: Saiba as regras pelas quais se rege o DoD para o desenvolvimento e integração de software em sistemas militares. O Military Standard MIL-STD-882C de 19 Janeiro de 1993 é uma referencia fundamental nesta área e está disponível para consulta externa sem restrições.

Mais informações em http://www.acq.osd.mil/ens/sh/882C


Reliability Books Index
Estrelas: ****

O que é:

 Lista de livros na área de fiabilidade, alguns com comentário crítico. Essencial para quem procura bibliografia.

Mais informações em http://www.enre.umd.edu/rbooks.htm


IEEE Technical Committee on Software Reliability Engineering
Estrelas: **

O que é:

 SRE é o comité do IEEE para a fiabilidade de software e é o patrocinador da conferência anual ISSRE (International Symposium on Software Reliability Engineering).

Informação interessante: Nada de interessante a não ser que se queira inscrever na mailing list do TCSRE, que pode fazer enviando um mail para (vishwa@hac2arpa.hac.com). Para enviar mensagens para a lista use (sw-rel@gate1.hac.com).

Para mais informações http://www.tcse.org/tcsesre.html


 

Software Metrics: A Rigorous Approach

Software Metrics:A Rigorous and Practical Approach

Systems Construction and Analysis: A Mathematical and Logical Approach

Software Reliability Handbook

 Software Quality Assurance and Metrics:A Worldwide Perspective

Software Requirements, Specification and Testing

Software Reliability: Achievement and Assessment

Safe & Secure Computing Systems

Safety-critical Systems

Directions in Safety-critical Systems

Safety-Critical Computer Systems

Safeware: System Safety and Computers

Safety Aspects of Computer Control

A guide to risk assessment

Review Guidelines on Software Languages for Use in Nuclear Power Plant Safety Systems 

Software metrics, estimação de custos / effort em projectos de software

   

 

Software Metrics: A Rigorous Approach - Chapman & Hall Ltd., 1991. N. Fenton, Centre for Software Reliability, City University, London, UK.

 Software metrics is normally considered to be a collection of diverse, unrelated and often informal activities concerned with controlling, managing and predicting various aspects of software development processes. This book provides a coherent and rigorous framework for these diverse activities providing a unifying basis for the entire subject area. This framework is based on two simple concepts, namely a rigorous approach to measurement extracted from basic ideas in measurement theory and a classification of the entities of interest in software development in terms of products, processes and resources. The author explains the pitfalls associated with software measurement and indicates how these may be avoided. He shows how to develop and implement data collection and metrics strategies and how to set up experiments to validate metrics and models. Using the framework described above, the book demonstrates and analyses a range of software metrics and models. Numerous exercises and examples are included throughout the text. 

ISBN: 0 412 40440 0 ISBN: 0 442 31355 1 (USA)


Software Metrics: A Rigorous and Practical Approach - International Thomson Computer Press, 1996. N.E. Fenton and S.L. Pfleeger 

 As one of the first texts on software metrics, the first edition broke new ground by introducing software engineers to measurement theory, graph-theoretic concepts, and new approaches to software reliability. This second edition brings the coverage of software metrics fully up-to-date. The book has been comprehensively re-written and re-designed to reflect changing developments in software metrics, most notably their widespread acceptance in industrial practice. This edition stresses the original framework for software metrics, but emphasises its practical applications. Based on measurement theory and a classification of entities as products, processes and resources, the framework has been expanded to include notions of process visibility and goal-directed measurement. The theory is liberally illustrated with case studies and examples to illustrate the application of each idea and technique. The new edition also reflects classroom and industrial feedback about the first edition. Thus, the text now includes extensive case studies, and more worked examples and exercises. Every section of the book has been improved and updated, including new sections on process maturity and measurement, the Goal-Question-Metric paradigm, metrics planning, experimentation, empirical studies, object-oriented metrics, and metrics tools. The book continues to provide an accessible and comprehensive introduction to software metrics, now an essential facet of the software engineering process. The book is arranged in three parts. Part I offers the reader a basic understanding of why and how we measure. It examines and explains the fundamentals of measurement, experimentation, and data collection and analysis. Next, Part II explores software engineering measurement in greater detail, with comprehensive information about a range of specific metrics and their uses, illustrated by a wealth of examples and case studies. Finally, Part III provides a management perspective on software measurement, explaining how to plan a measurement program, what has been successful in other organisations, and how measurement can be used to evaluate the effectiveness of techniques and tools. The book also includes an annotated bibliography, a glossary, and answers to selected exercises from the main chapters.

ISBN: 1-85032-275-9. Price £21.95.


Systems Construction and Analysis: A Mathematical and Logical Approach - McGraw Hill, 1992 N. Fenton and G. Hill, City University, London, UK.

 Text book that provides a comprehensive coverage of the discrete mathematics basis for computer science. Topics covered: models, systems, sets, relations, functions, graph theory, linear algebra, combinatorics, propositional calculus, predicate calculus, proof, formal languages, lambda calculus, formal specification, Z, VDM, formal verification, models of computations, graph models for structured programming, Petri nets, probability theory, algorithmic and computational complexity, coding theory, measurement theory. 

ISBN 0-07-707431-9


Software Reliability Handbook - Elsevier, 1990 edited by P. Rook, Centre for Software Reliability, City University, London, UK. 

 This book provided a major reference work for the increasingly important area of quality assurance and reliability of computer systems.

ISBN 1-85166-400-9 (Available from Chapman and Hall Limited)


Software Quality Assurance and Metrics: A Worldwide Perspective - International Thomson Computer Press, 1995 edited by N.E. Fenton, Y. Iizuka, and R.W. Whitty.

 This book provides a comprehensive review of current leading edge industrial activities in software quality assurance and measurement. The carefully edited work contains contributions from many of the world's leading experts in the subject. The book is unique in its international coverage, and its insight into Japanese practice is possibly the most extensive ever published in the West. 

ISBN 1-85032-174-4


Software Requirements, Specification and Testing - Blackwell Scientific Publications, 1985 edited by T. Anderson, Centre for Software Reliability, University of Newcastle upon Tyne, UK.

 This book provides a record of the first CSR workshop, held at the University of East Anglia in April 1984, on requirements definition, system specification and testing of computer software. 

ISBN 0-632-01309-5 (Out of print)


Software Reliability: Achievement and Assessment - Blackwell Scientific, 1987 edited by B. Littlewood, Centre for Software Reliability, City University, London, UK.

 This book stems from the second CSR workshop which was held at the University of Keele in April 1985. The theme of the workshop was the achievement and measurement of software reliability.

ISBN 0-632-01573-X


Safe & Secure Computing Systems - Blackwell Scientific Publications, 1989 edited by T. Anderson, Centre for Software Reliability, University of Newcastle upon Tyne, UK.

 Proceedings of the third CSR workshop held at the Scottish Exhibition and Conference Centre Glasgow in September 1986. This book explores the similarities between problems and techniques for safety and security in computing systems, and shows how they have much in common which has not been fully recognised.

ISBN 0-632-01819-4 (Out of print)


Safety-critical Systems - Current issues, techniques and standards - Chapman & Hall Ltd., 1993 edited by F. Redmill and T. Anderson.

 The 22 chapters in this book were invited from experts who gave presentations at Safety-critical Systems Club seminars. The book is broad in scope and suitable for academics, experienced practitioners, and newcomers to the field. It is divided into 5 parts: Current Issues, Requirements and Specification, Education and Training, Lessons from the Medical Sector, and Current Development of Standards.

ISBN 0-412-54820-8 


Directions in Safety-critical Systems - Springer Verlag, 1993 edited by F. Redmill and T. Anderson. 

 This is the proceedings of the Club's Safety-critical Systems Symposium '93 held in Bristol. The first day's papers covered experience from around Europe and included a sociological view. The second day's proceedings focused on collaborative research projects in the UK. The third day opened out to cover the achievement and evaluation of safety, and included papers on the relationship between safety and such other attributes as security and quality.

ISBN 3-540-19817-2


Neil Storey, "Safety-Critical Computer Systems", Addison Wesley,1996.ISBN 0-201-42787-7

Mais informações em (http://www.awl-he.com/computing/titles/0-201-42787-7.html)


Nancy G. Leveson, "Safeware: System Safety and Computers", Addison Wesley, 1995 ISBN 0-201-11972-2

 Mais informações em (http://www.awl-he.com/computing/titles/0-201-11972-2.html)


Bennett, P.A. (editor), "Safety Aspects of Computer Control", Butterworth-Heinemann, 1993


The HSE Guide, "A guide to risk assessment", HSE BookISBN: 071761212


"Review Guidelines on Software Languages for Use in Nuclear Power Plant Safety Systems"

 

 Stars: ****

 This report provides guidelines which can be used to prohibit or limit the use of programming practices which are considered unsafe in high-integrity digital sytems (E.G., MALLOC).The guidelines were developed for the following  languages: C, C++, PLC Ladder Logic, PLC Structured Text, Function Block Diagrams, Pascal, PLM, Ada 83, Ada 95 and Sequential Function Charts.

 

Estrelas: ****

Trata-se de um conjunto de requesitos a que devem obedecer linguagens a utilizar em aplicações extremas das centrais nucleares.Este relatório apresenta critérios que podem ser utilizados para prevenir (ou limitar) o uso de práticas de software que são considerados pouco seguras no desenvolvimento de sistemas digitais de alta integridade (high-integrity), tais como MALLOC. O estudo considera as seguintes linguagens:C, C++, PLC Ladder Logic, PLC Structured Text, Function Block Diagrams, Pascal, PLM, Ada 83, Ada 95, e Tabelas de Funções Sequenciais (Sequential Function Charts).

 Mais informações em (http://www.nrc.gov/NRC/NUREGS/CR6463/index.htm)


"Software metrics, estimação de custos / effort em projectos de software"

 O modelo de nome COCOMO e' o melhor aceite,

Mais informações em ( http://sunset.usc.edu/COCOMOII/Cocomo.html), em

(http://www.construx.com/estimate/resource.htm) estão alguns links comentados interessantes para

ferramentas public-domain e comerciais para avaliação.

 


 

ISTec (Institute for Safety Technology, Garching, Alemanha) DELTA (Danish Electronics, Light & Acoustics, Horsholm, Dinamarca) Objectif Technologie (Paris, França)
CSR (Centre for Software Reliability, Newcastle, Grã-Bretanha) Universidade de Aegean (Atenas / Samos, Grécia) TUE (Eindhoven University of Technology, Eindhoven, Holanda)
ENEA (Ente per le Nuove Tecnologie, l'Energia e l'Ambiente, Roma, Itália) DNV (Det Norske Veritas, Hovik, Noruega) DEI (Departamento de Engenharia de Informática da Universidade de Coimbra, Coimbra, Portugal)
SP (Swedish National Testing and Research Institute, Boras, Suécia) ARCS (Austrian Research Center Seibersdorf, Seibersdorf, Áustria)