SPRG Logs
A requirement is (1) a condition or capability a user needs to solve a problem, (2) a condition or capability a system must possess to satisfy a contract or standard, or (3) a documented representation of (1) or (2).
The three-part definition is deliberately layered, because the...
Q When choosing how to represent a requirement, what are the four "degrees of freedom" you can dial?
You can choose the instrument (natural language → structured models → interaction models → formal model), the structure, the precision, and the depth (deepness) of the representation.
* Four dials you set independently; turning any of them up costs more effort, so each is scaled...
Q How does the cost of fixing a defect change depending on when in the software lifecycle it is discov...
The later you find it, the more it costs — from x1 in requirements to a mean of about x250 once the system is in operations, which is why rework and bug-fixing can swallow up to half a project's effort.
* The multipliers on a log scale: the range per phase, with the mean joining...
Q What is the difference between a functional requirement and a quality (non-functional) requirement?
A functional requirement says what the system does — a result or behaviour a function must provide; a quality requirement says how well it does it (performance, availability, security…) and is defined as everything not covered by the functional ones.
This is the most fundamental...
Q If nobody can be 100% secure, what is a realistic security target for a development project, and whi...
Not "zero vulnerabilities" but "no well-known vulnerabilities in the code" — reached by knowing the common vulnerability types, avoiding the well-known mistakes, and reusing proven countermeasures and patterns instead of inventing your own.
Perfect security is not an achievable g...
Q What is Software Assurance (SwA) and what are its two key properties?
Software Assurance is the level of confidence that software is free of vulnerabilities and behaves as intended — its two pillars are Trustworthiness and Predictable Execution.
* The two pillars as independent axes — three of the four quadrants are assurance failures. *
Software...
Q What are the four core activities of requirements engineering, and over what span are they carried o...
Elicit the stakeholders' requirements, document them suitably, validate and verify them, and manage them — and you do all four across the entire life cycle of the system, not just once at the start.
* Management is drawn as the band around the other three, not as a fourth step i...
Q What is the difference between business analysis and requirements engineering?
Business analysis identifies business needs and determines solutions to business problems — the solution may not be software at all; requirements engineering is the narrower process of formulating, documenting and maintaining a system's software requirements.
* Requirements engi...
Q What is the difference between System Boundary and Context Boundary in requirements engineering?
The system boundary draws the line between the system and its environment; the context boundary draws a second, outer line between the environment that matters and the environment you can ignore.
* The system boundary separates the system from its environment; the context bounda...
Q What is the goal of requirements engineering, and why does it put so much weight on achieving consen...
The goal is to know the relevant requirements, reach a consensus among stakeholders about them, document them to standards, and manage them systematically — all to minimise the risk of delivering a system that does not meet the stakeholders' real needs.
Requirements engineering i...