When eliciting requirements, what are the three sources you draw from, and the three types of requirement you gather?
Sources: stakeholders, documents, and existing systems. Types: functional (e.g. "login"), quality / non-functional (e.g. "secure storage of log data"), and general conditions or regulations (e.g. "must be live by summer", "PCI-DSS compliant").
* Any source can yield any of the three types — which is why mining documents and systems is where the quality requirements turn up. *
Eliciting requirements starts with a stakeholder analysis — getting to know all the involved parties — because people are the richest source. But requirements do not only come from people:
Three sources:
- Stakeholders — what the involved parties say they need, drawn out through interviews and workshops.
- Documents — existing specifications, policies, regulations and contracts, which often already impose requirements nobody will think to mention.
- Systems — existing or neighbouring systems whose actual behaviour constrains the new one, regardless of what anybody wishes were true.
Three types you collect:
- Functional — a behaviour the system provides, e.g. login.
- Quality / non-functional — how well it behaves, e.g. secure storage of log data.
- General regulations or conditions — constraints framing the whole project, e.g. the system should be live in summer, or it must be PCI-DSS compliant (the card-industry security standard for handling payment-card data).
Tip: Beginners only interview stakeholders and only capture features. Mature elicitation also mines documents and systems, and deliberately hunts for the quality requirements and general conditions nobody volunteers — security almost always hides in those last two buckets, because it is written in a policy or implied by a neighbouring system rather than requested by a user.
Go deeper:
Requirements elicitation (Wikipedia) — the techniques that suit each source, and why elicitation is harder than asking.
Stakeholder analysis (Wikipedia) — how to find everyone who counts as a stakeholder before you start interviewing.
PCI DSS (Wikipedia) — a worked example of a general condition: a standard that imposes requirements nobody in the room asked for.