<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">IASC</journal-id>
<journal-id journal-id-type="nlm-ta">IASC</journal-id>
<journal-id journal-id-type="publisher-id">IASC</journal-id>
<journal-title-group>
<journal-title>Intelligent Automation &#x0026; Soft Computing</journal-title>
</journal-title-group>
<issn pub-type="epub">2326-005X</issn>
<issn pub-type="ppub">1079-8587</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">14639</article-id>
<article-id pub-id-type="doi">10.32604/iasc.2021.014639</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>CMMI Compliant Workflow Models to Establish Configuration Management Integrity in Software SMEs</article-title><alt-title alt-title-type="left-running-head">CMMI Compliant Workflow Models to Establish Configuration Management Integrity in Software SMEs</alt-title><alt-title alt-title-type="right-running-head">CMMI Compliant Workflow Models to Establish Configuration Management Integrity in Software SMEs</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author">
<name name-style="western">
<surname>Ali</surname>
<given-names>Islam</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western">
<surname>Khan</surname>
<given-names>Musawwer</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western">
<surname>Mehmood</surname>
<given-names>Waqar</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western">
<surname>Nisar</surname>
<given-names>Wasif</given-names>
</name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western">
<surname>Aslam</surname>
<given-names>Waqar</given-names>
</name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western">
<surname>Saleem</surname>
<given-names>Muhammad Qaiser</given-names>
</name>
<xref ref-type="aff" rid="aff-3">3</xref>
</contrib>
<contrib id="author-7" contrib-type="author">
<name name-style="western">
<surname>Omer</surname>
<given-names>Majzoob K.</given-names>
</name>
<xref ref-type="aff" rid="aff-3">3</xref>
</contrib>
<contrib id="author-8" contrib-type="author" corresp="yes">
<name name-style="western">
<surname>Shafiq</surname>
<given-names>Muhammad</given-names>
</name>
<xref ref-type="aff" rid="aff-4">4</xref>
<email>shafiq@ynu.ac.kr</email>
</contrib>
<aff id="aff-1">
<label>1</label><institution>Department of Computer Science, COMSATS University Islamabad</institution>, <addr-line>Wah Campus, Wah Cantt, </addr-line><country>Pakistan</country></aff>
<aff id="aff-2">
<label>2</label><institution>Department of Computer Science &#x0026; IT, The Islamia University of Bahawalpur</institution>, <addr-line>Bahawalpur</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-3">
<label>3</label><institution>College of Computer Science and Information Technology, Al Baha University</institution>, <addr-line>Al Bahah</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-4">
<label>4</label><institution>Department of Information and Communication Engineering, Yeungnam University</institution>, <addr-line>Gyeongsan, 38541, Korea</addr-line></aff>
</contrib-group><author-notes><corresp id="cor1">&#x002A;Corresponding author: Muhammad Shafiq. Email: <email>shafiq@ynu.ac.kr</email></corresp></author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2021-01-01">
<day>01</day>
<month>01</month>
<year iso-8601-date="2021">2021</year>
</pub-date>
<volume>27</volume>
<issue>3</issue>
<fpage>605</fpage>
<lpage>623</lpage>
<history>
<date date-type="received">
<day>05</day>
<month>10</month>
<year iso-8601-date="2020">2020</year>
</date>
<date date-type="accepted">
<day>30</day>
<month>11</month>
<year iso-8601-date="2020">2020</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2021 Ali et al.</copyright-statement>
<copyright-year>2021</copyright-year>
<copyright-holder>Ali et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_IASC_14639.pdf"></self-uri>
<abstract>
<p>Capability Maturity Model Integration (CMMI) is a world-renowned framework for software process improvement, which specifies &#x201C;What-To-Do&#x201D; in terms of requirements. However, it leaves the &#x201C;How-To-Do&#x201D; part regarding implementation to implementers. The software industry especially software SMEs (SSMEs) faces difficulties in implementing the Specific Practices (SPs) of Various Process Areas (PAs). Configuration Management Process Area (CM-PA) is usually ignored despite its acknowledged importance in the software development process. Establishing integrity is one of the three Specific Goals (SGs) that CMMI ver. 1.3 requires for successful implementation of CM-PA. This goal is achieved through the implementation of two SPs (i.e., 3.1 and 3.2). In order to enable aforesaid SSMEs, pertinent research work regarding the implementation of PAs at CMMI Level-II was studied and Workflow Models (WFMs) were devised after sifting through all the relevant material. The models were assessed through Expert Panel Review (EPR) and further confirmed by conducting case studies. This work also contributes to the implementation of CM-PA. The results from EPR and case studies are promising since they not only testifies the clarity, learnability, usability, usefulness of the models but also proves its applicability to SSMEs. The proposed WFMs have a strong theoretical basis and practically proven. More industrial case studies are suggested to evaluate models for the upcoming versions of CMMI frameworks.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Software configuration management</kwd>
<kwd>capability maturity model integration</kwd>
<kwd>software process improvement</kwd>
<kwd>software SMEs</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The success or failure of an organization largely hinges on quality of products or services it provides. Everyone desires to have software product(s) that operate reliably without errors or being crashed. One way to enhance software quality is to improve software development processes. That&#x2019;s why many SSMEs take interest in SPI. Improving the software process continually and appraising it regularly for effectiveness helps in meeting the customer&#x2019;s expectations and is bound to pave a way towards a high-quality software.</p>
<p>There is no doubt that CMMI enables software development industry to take quality of software process to a next higher level. However, no significant number of SSMEs are opting for adoption. Like many other researcher, Gang Xu et al. [<xref ref-type="bibr" rid="ref-1">1</xref>] pointed out that CMMI offers software companies only guidelines, not the clear workflow models resulting in increased budget.</p>
<p>CMMI Level-II [<xref ref-type="bibr" rid="ref-2">2</xref>] consists of seven PAs including CM-PA. As elaborated in the next section, variety of research work has been carried out for implementation of PAs at CMMI Level-II, However, presently, no workflow model was found for SPs wise implementation of CM-PA particularly to help SSMEs as shown in <xref ref-type="table" rid="table-1">Tab. 1</xref>. Therefore there is an intense need to devise the tailorable workflow models for SPs of CM-PA.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Summary of workflow models devised earlier for various SPs of PAs at CMMI Level-II</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>No</th>
<th>PAs at CMMI Level-II</th>
<th>Work</th>
<th>Reference</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>Configuration Management (CM)</td>
<td>X</td>
<td>X</td>
</tr>
<tr>
<td>2</td>
<td>Measurement &#x0026; Analysis (M&#x0026;A-PA)</td>
<td>X</td>
<td>X</td>
</tr>
<tr>
<td>3</td>
<td>Project Monitoring &#x0026; Control (PM&#x0026;C)</td>
<td>X</td>
<td>X</td>
</tr>
<tr>
<td>4</td>
<td>Requirements Management (REQM)</td>
<td>RCM, WFM for SP 1.3 &#x0026; 1.4, REQM</td>
<td>[<xref ref-type="bibr" rid="ref-3">3</xref>&#x2013;<xref ref-type="bibr" rid="ref-6">6</xref>]</td>
</tr>
<tr>
<td>5</td>
<td>Project Planning (PP)</td>
<td>WFM for SP 1.3</td>
<td>[<xref ref-type="bibr" rid="ref-7">7</xref>]</td>
</tr>
<tr>
<td>6</td>
<td>Process and Product Quality Assurance (PPQA)</td>
<td>WFM for All SPs</td>
<td>[<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td>7</td>
<td>Supplier Agreement Management (SAM)</td>
<td>WFM</td>
<td>[<xref ref-type="bibr" rid="ref-9">9</xref>]</td>
</tr>
</tbody>
</table></table-wrap>
<p>As per CMMI for Dev Ver. 1.3, CM-PA has three SGs and are achieved through implementation of seven SPs collectively. The focus of this study is to achieve the third goal (SG-3) of CM-PA by devising WFMs for implementation of two associated SPs (i.e., 3.1 and 3.2). As a vehicle to achieve the research objective, research questions are formulated as given in <xref ref-type="table" rid="table-2">Tab. 2</xref>.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Research questions</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>ID</th>
<th>Research Question</th>
<th>Motivation</th>
</tr>
</thead>
<tbody>
<tr>
<td>RQ-A</td>
<td>How to implement the associated SPs to achieve &#x201C;Establish Integrity&#x201D; goal of CM-PA at CMMI Level-II in SSMEs?</td>
<td>To devise WFMs for implementation of SPs contributing to SG-3 of CM-PA and</td>
</tr>
<tr>
<td>RQ-B</td>
<td>What is the expert&#x2019;s perception about &#x201C;Practice Coverage&#x201D; of the proposed WFMs specifically w.r.t SSMEs?</td>
<td>assess the coverage of sub-practices,</td>
</tr>
<tr>
<td>RQ-C</td>
<td>What is the expert&#x2019;s perception about &#x201C;Usefulness&#x201D; of the proposed WFMs taking SSMEs into account?</td>
<td>evaluate its utility</td>
</tr>
<tr>
<td>RQ-D</td>
<td>What is the expert&#x2019;s perception about &#x201C;Ease of Learning &#x0026; Usage&#x201D; of the proposed WFMs in the context of SSMEs?</td>
<td>appraise its ease of learning, usability &#x0026;</td>
</tr>
<tr>
<td>RQ-E</td>
<td>What is the expert&#x2019;s perception about &#x201C;Applicability&#x201D; of the proposed WFMs to SSMEs?</td>
<td>Judge its implement-ability in SSMEs.</td>
</tr>
</tbody>
</table></table-wrap>
<p>Organization of the paper is as follows. Sec 2 traverses through the earlier work and its limitations. Sec 3 throw light on methodology adopted and criteria for validation of the workflow model. Proposed models are elaborated in sec 4. Validation of models, threats to validity and their mitigation is given in sec 5, Sec 6 concludes the study and finally sec 7 highlights potential future work.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>In order to help software development firms in implementing the best practices of REQM-PA, Niazi et al. [<xref ref-type="bibr" rid="ref-3">3</xref>] devised the CMMI compliant Requirements Change Management (RCM) Model. The model has five stages &#x201C;Request&#x201D;, &#x201C;Validate&#x201D;, &#x201C;Implement&#x201D;, &#x201C;Verify&#x201D; &#x0026; &#x201C;Update&#x201D; and was evaluated through EPR process. Keshta [<xref ref-type="bibr" rid="ref-4">4</xref>] devised WFMs for SPs 1.3 &#x0026; 1.4 of the REQM-PA having six stages &#x201C;Initiate&#x201D;, &#x201C;Validate&#x201D;, &#x201C;Implement&#x201D;, &#x201C;Verify&#x201D;, &#x201C;Update&#x201D; and &#x201C;Release&#x201D;. EPR was used to validate the models against the specified criteria. Applicability of models to small &#x0026; medium sized software development organizations (SMSDOs) was evaluated in Saudi Arabian software industry. Tariq [<xref ref-type="bibr" rid="ref-5">5</xref>] has suggested to include an additional SP in REQM-PA for Software as a Services (SAAS) and carried out validation through a case study &#x201C;Allwebid&#x201D;. Batti [<xref ref-type="bibr" rid="ref-6">6</xref>] proposed a six-phased methodology to deal with changing requirements i.e., &#x201C;Initiate&#x201D;, &#x201D;Receipt&#x201D;, &#x201D;Approve/Disapprove&#x201D;, &#x201D;Evaluate&#x201D;, &#x201D;Implement&#x201D; and &#x201D;Configure&#x201D; with CCB to act as central player and as a process owner. Keshta [<xref ref-type="bibr" rid="ref-7">7</xref>] also devised a WFM for implementation of SP 1.3 of PP-PA and defined phases for a project life cycle keeping in view the SMSDOs. The model comprises of four stages &#x201C;Plan&#x201D;, &#x201C;Design&#x201D;, &#x201C;Review&#x201D; and &#x201D;Update/Rework&#x201D;. Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>] further developed a WFMs for all SPs of PPQA-PA in perspective of SMSDOs. Both SP-1.1 &#x0026; SP-1.2 of PPQA comprise of four stages i.e., &#x201C;Plan&#x201D;, &#x201C;Prepare&#x201D;, &#x201C;Audit&#x201D; &#x0026; &#x201C;Report&#x201D;. The models were validated making use of EPR. Vivatanavorasin et al. [<xref ref-type="bibr" rid="ref-9">9</xref>] presented a three layered WFM for SAM-PA having &#x201C;Contextual layer&#x201D;, &#x201C;Elaboration layer&#x201D;, and &#x201C;Definition layer&#x201D;. As a proof of concept prototype, Supplier Agreement Management Tool was developed. In order to adopt CM process in DevOps environment, Erik Hochbergs and Laroy Nilsson Sj&#x00F6;dahl [<xref ref-type="bibr" rid="ref-10">10</xref>] prepared guidelines after exploring literature and interviewing key professionals of software companies. Syahrul Fahmy et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] highlighted the evolution of SCM since its beginning and appreciated that SCM techniques are also being applied to other areas.</p>
<p>Resources are meagre in small software companies (SSCs) as compared to medium and large companies. Tuape and Ayalew [<xref ref-type="bibr" rid="ref-12">12</xref>] underscored that SPI frameworks are usually framed keeping big companies in view and thus software quality is usually compromised in SSCs. The authors identified three factors that tend to affect development process in SSC&#x2019;s generally and African SSCs particularly. Victor Jos&#x00E9; et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] worked on how to implement the measurement process in line with the CMMI in companies whose primary business is maintenance instead of development. Tadele [<xref ref-type="bibr" rid="ref-14">14</xref>] devised a simple and easy to use framework amalgamating the CMMI ver 2.0 and DevOps to assist small companies. This framework is claimed to be comparatively cheaper &#x0026; easily implementable and was validated through case study in few companies where substantial improvement was seen after implementation. Definition of SMEs varies w.r.t countries and time span. Few, collected from various studies, are given in <xref ref-type="table" rid="table-3">Tab. 3</xref>.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Categorization of SMEs</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr><th rowspan="2">Country</th>
<th>Small Company</th>
<th>Medium Company</th><th rowspan="2">Reference</th>
</tr>
<tr>
<th>Number of employee</th>
<th>Number of employee</th>
</tr>
</thead>
<tbody>
<tr>
<td>Pakistan</td>
<td>10&#x007E;35</td>
<td>36&#x007E;99</td>
<td>Dasanayaka [<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
</tr>
<tr>
<td>Korea</td>
<td>11&#x007E;49</td>
<td>50&#x007E;199</td>
<td>Sanath Divakara [<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
</tr>
<tr>
<td>Turkey</td>
<td>03&#x007E;49</td>
<td>50&#x007E;250</td>
<td>Hande Karadag [<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
</tr>
<tr>
<td>Saudi Arabia</td>
<td>06&#x007E;49</td>
<td>50&#x007E;249</td>
<td>Abhishek Tripathii [<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
</tr>
</tbody>
</table></table-wrap>
</sec>
<sec id="s3">
<label>3</label>
<title>Methodology Adopted and Criteria for Validation of Workflow Model</title>
<p>Research methodology need to be devised very carefully as it has profound impact on the validity and reliability of study results. The research methodology used for this research has six major stages and is illustrated in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Methodology adopted</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-1.png"/>
</fig>
<p>Success of a study largely depends on formulating of a sound evaluation criteria. Criteria for validation of the models in this study, because of the similar nature, has been derived from work of Niaz [<xref ref-type="bibr" rid="ref-3">3</xref>], Keshta [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-8">8</xref>] and Vivatanavorasin [<xref ref-type="bibr" rid="ref-9">9</xref>] respectively and is elaborated in <xref ref-type="table" rid="table-4">Tab. 4</xref>.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Validation criteria</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Criteria</th>
<th>Elaboration</th>
</tr>
</thead>
<tbody>
<tr>
<td><italic>Satisfaction of SPs</italic></td>
<td>The proposed WFMs should address the practices where necessary to ensure achieving the goals set by CMMI v1.3 specifications.</td>
</tr>
<tr>
<td><italic>Satisfaction of Users</italic></td>
<td>Models&#x2019; should satisfy users and help them to achieve their needs and objectives.</td>
</tr>
<tr>
<td><italic>Ease of Learning &#x0026; Use</italic></td>
<td>Models shall be simple, easy to understand and comfortable to follow.</td>
</tr>
<tr>
<td><italic>Applicability of the models in SSMEs</italic>.</td>
<td>The WFMs shall be implementable in SSMEs i.e., it shall enable them to achieve the integrity goal of CM-PA.</td>
</tr>
</tbody>
</table></table-wrap>
</sec>
<sec id="s4">
<label>4</label>
<title>Proposed Workflow Models for Establishing Integrity</title>
<p>As per CMMI Framework 1.3, the SG-1 &#x201C;Establish Baselines&#x201D; of CM-PA serve to establish baselines, the SG-2 &#x201C;Track and Control Changes&#x201D; assist in maintaining the baselines whereas the SG-3 &#x201C;Establish Integrity&#x201D; basically establish records and appraise the integrity of the baselines. The later goal is achieved through implementation of two SPs. The proposed WFMs for the aforesaid SPs, in this work, are composed of core stages. In fact, the activities involved in a particular SP have been logically grouped with logical sequence into stages. The proposed WFMs are constructed using well known Entry-Task-Verification-eXit (ETVX) model. Each activity is accompanied with the actor having generic title who has to perform it and the potential artifacts to be created. These actors are taken from a sample SSMEs. The implementers may tailor it as per their working environment. Further, inputs and outputs of the workflow along with the associated processes/stages are also indicated.</p>
<sec id="s4_1">
<label>4.1</label>
<title>WFM for SP 3.1 &#x2013; &#x201C;Establish Configuration Management Records&#x201D;</title>
<p>First SP of the said goal is to &#x201C;Establish and maintain records describing the CIs&#x201D;. In order to keep brevity, only three among many of the findings from literature are given in <xref ref-type="table" rid="table-5">Tab. 5</xref> supporting each stage i.e., &#x201C;Planning&#x201D;, &#x201C;Recording&#x201D;, &#x201C;Revision&#x201D;, and &#x201C;Sharing Reports&#x201D; of the proposed WFM for SP 3.1 of CM-PA and is depicted in <xref ref-type="fig" rid="fig-2">Fig. 2</xref> followed by the associated process guide in <xref ref-type="table" rid="table-6">Tab. 6</xref>. Rationale for provision of process guide in tabular format is to achieve brevity and to provide structured information to implementers.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Evidences from literature supporting each stage of WFM for SP 3.1</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>No.</th>
<th>Evidence from Literature</th>
<th>Author&#x2019;s Point of View</th>
<th>Author &#x0026; reference</th>
</tr>
</thead>
<tbody>
<tr>
<td colspan="4"><bold>A - Planning Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>CMMI for Development</td>
<td>It&#x2019;s an organizational prerogative, due to supportive nature of the PA, to select CIs and its control level. In fact, understanding CIs status is quite time-taking without adequate description of CIs.</td>
<td>Chrissis et al. [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>Introduction to Software Process Improvement</td>
<td>G. Oregan emphasized to include the activity of establishing records in the process, make part of checklists as well as template.</td>
<td>G. O&#x2019;Regan [<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>Guide to Software Engineering Body of Knowledge V 3.0</td>
<td>SCM Planning shall be consistent with the organizational context and project plan. It terms SCM Plan as living document serving as a reference for the SCM process.</td>
<td>SWEBOK V 3.0 [<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
</tr>
<tr>
<td colspan="4"><bold>B &#x2013; Recording Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>Introduction to Software Quality</td>
<td>G. O&#x2019;Regan suggested a role of librarian to establish a library (filing structure) for to record CM activities. Configuration manager may act as librarian.</td>
<td>G. O&#x2019;Regan [<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>CMMI for Development</td>
<td>Chrisis emphasized that ample information be recorded to be able to maintain the CIs differentiation between baselines easily.</td>
<td>Chrissis et al. [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>WFM for SP 2.2 of PPQA.</td>
<td>The author included the &#x201C;Record&#x201D; stage in WFM for SP &#x201C;Establish Records&#x201D; of PPQA-PA with evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td colspan="4"><bold>C - Revision Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>CMMI for Development</td>
<td>The author considers the version control as critical and suggested &#x201C;Sequential&#x201D; as standard way for identification of versions.</td>
<td>Chrissis et al. [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>Introduction to Software Quality</td>
<td>G. O&#x2019;Regan stressed that on each change in document, next version shall be assigned and history shall be updated.</td>
<td>G. O&#x2019;Regan [<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>WFM for SP 2.2 of PPQA</td>
<td>The author included the &#x201C;Revise&#x201D; stage in WFMs for SP &#x201C;Establish Records&#x201D; of PPQA-PA with evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td colspan="4"><bold>D - Sharing Reports Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>Workflow Model for PPQA-PA</td>
<td>The author included the &#x201C;Report&#x201D; stage in both WFMs for SP 1.1 and SP 1.2 of PPQA-PA with evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>Introduction to Software Quality</td>
<td>The Status Accounting Reports shall include Baseline Status, Baseline Differences, Problems reports, Change Request etc.</td>
<td>O&#x2019;Regan [<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>Workflow Model for PPQA-PA</td>
<td>The author included the &#x201C;Share&#x201D; stage in workflow models for SP &#x201C;Establish Records&#x201D; of PPQA-PA with evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
</tbody>
</table></table-wrap>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Workflow model for SP-3.1</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-2.png"/>
</fig>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Process guide for SP 3.1</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<tbody>
<tr>
<td><bold>Purpose</bold></td>
<td colspan="6">In order to maintain control over the configuration of project CIs and provide management status of the project, CM records of the CIs needs to be recorded throughout the SDLC.</td>
</tr>
</tbody>
<tbody>
<tr>
<td><bold>Scope</bold></td>
<td colspan="6">This process applies to all activities that are performed throughout the project life cycle.</td>
</tr>
<tr>
<td><bold>Abbreviations</bold></td>
<td colspan="2">
<list list-type="bullet">
<list-item>
<p>SAR</p></list-item>
<list-item>
<p>BDR</p></list-item></list></td>
<td colspan="4">Status Accounting Reports<break/>Baselines Difference Report</td>
</tr>
<tr>
<td><bold>Entry criteria</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>A Baseline has been released to the client.</p></list-item>
<list-item>
<p>A request for the status has been received from PM through email</p></list-item></list></td>
</tr>
<tr>
<td rowspan="2"><bold>Inputs to the workflow and associated SPs</bold></td>
<td colspan="3"><bold>Input Work-Products</bold></td>
<td colspan="3"><bold>Associated PA/SP</bold></td>
</tr>
<tr>
<td colspan="3">
<list list-type="bullet">
<list-item>
<p>SCM Plan</p></list-item>
<list-item>
<p>Organizational/Project Measures/Metrics</p></list-item>
<list-item>
<p>Configuration Management System (CMS)</p></list-item></list></td>
<td colspan="3">
<list list-type="bullet">
<list-item>
<p>PP-PA</p></list-item>
<list-item>
<p>Status Accounting Information Requirements</p></list-item>
<list-item>
<p>Establish CMS</p></list-item></list></td>
</tr>
<tr>
<td><bold>Stage</bold></td>
<td colspan="4"><bold>Process Activities</bold></td>
<td><bold>Activity Roles</bold></td>
<td><bold>Potential Records</bold></td>
</tr>
<tr>
<td rowspan="3"><bold><italic>A. Planning</italic></bold></td>
<td>A.1</td>
<td colspan="3">Status accounting information are identified/selected.</td>
<td>PM</td>
<td>Status Accounting Information</td>
</tr>
<tr>
<td>A.2</td>
<td colspan="3">The version of CIs that constitute the baselines</td>
<td>SCM TM</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>A.3</td>
<td colspan="3">The latest version of the baselines shall be specified.</td>
<td>SCM TM</td>
<td>&#x2013;</td>
</tr>
<tr>
<td rowspan="4"><bold><italic>B. Recording</italic></bold></td>
<td>B.1</td>
<td colspan="3">The Status accounting information shall be incorporated into SCM repository.</td>
<td>SCM TL, SCM TM</td>
<td>Rev. Repository Structure</td>
</tr>
<tr>
<td>B.2</td>
<td colspan="3">Authorized users shall have access to the repository.</td>
<td>SCM TM</td>
<td>Roles/privileges</td>
</tr>
<tr>
<td>B.3</td>
<td colspan="3">The SCM repository shall be configured to auto-inform authorized users about change of any CI.</td>
<td>SCM TM</td>
<td>Roles/privileges</td>
</tr>
<tr>
<td>B.4</td>
<td colspan="3">In order to know the content and status of CIs and render the older versions recoverable, all SCM activities shall be recorded with sufficient details.</td>
<td>SCM TM</td>
<td>Logs</td>
</tr>
<tr>
<td rowspan="3"><bold><italic>C. Revision</italic></bold></td>
<td>C.1</td>
<td colspan="3">The changes shall be identified based on updates.</td>
<td>SCM TM</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>C.2</td>
<td colspan="3">Following shall be confirmed prior to revision of status and preparing history of CIs.
<list list-type="bullet">
<list-item>
<p>The old version be recoverable.</p></list-item>
<list-item>
<p>Status accounting info are incorporated into SCM Repository and access provided to users</p></list-item>
<list-item>
<p>The repository be configured to send the alerts automatically on change of CIs.</p></list-item>
<list-item>
<p>No errors are there in any CIs/records.</p></list-item></list></td>
<td>SCM TMs</td>
<td>Corrective Actions</td>
</tr>
<tr>
<td>C.3</td>
<td colspan="3">Status of CIs shall be revised and revision history shall be prepared accordingly.</td>
<td>SCM TMs</td>
<td>Revision History of CIs</td>
</tr>
<tr>
<td rowspan="2"><bold><italic>E. Sharing Reports</italic></bold></td>
<td>D.1</td>
<td colspan="3">SCM Reports shall be generated periodically or on demand including structure reports, add-hoc reports and difference b/w successive baselines reports.</td>
<td>SCM TMs, SCM TL</td>
<td>SCM Report</td>
</tr>
<tr>
<td>D.2</td>
<td colspan="3">SCA reports shall be distributed to stakeholders.</td>
<td>SCM TL</td>
<td>Dissemination log</td>
</tr>
<tr>
<td><bold>Interfaces</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Artifacts generated from PP, PPQA, PMC, REQM, MA, and SCM Process Areas are referred to SCM process area to be stored and maintained in the CMS.</p></list-item>
<list-item>
<p>QC department performs the testing according the defined process and notifies SCM about the resolution of all bugs or the completion of functionality.</p></list-item>
<list-item>
<p>The schedule of configuration audit is received from the Project Planning Process Area</p></list-item></list></td>
</tr>
<tr>
<td rowspan="2"><bold>Outputs of WFM and associated PAs/SPs</bold></td>
<td colspan="4"><bold>Output Work-Products</bold></td>
<td colspan="2"><bold>Associated PA/SP</bold></td>
</tr>
<tr>
<td colspan="4">
<list list-type="bullet">
<list-item>
<p>SCM Reports</p></list-item>
<list-item>
<p>Corrective Actions</p></list-item>
<list-item>
<p>Internal Configuration Checklist, NCs, Audit Reports</p></list-item></list></td>
<td colspan="2">Perform Configuration Audits<break/>PPQA-PA<break/>Establish CM Records, PPQA</td>
</tr>
<tr>
<td><bold>Exit criteria</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>SA Reports and Baselines Difference Reports are generated/viewed/evaluated.</p></list-item>
<list-item>
<p>Product has been released to the client and acceptance from client has been received.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Measures</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Number of releases.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Verification points</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>PM in coordination with Dev TL and SCM TL reviews the Configuration Status Accounting process and work products at points identified by the Project Plan and Project Schedule.</p></list-item>
<list-item>
<p>QA evaluates the Configuration Status Accounting process and designated work products.</p></list-item>
<list-item>
<p>Top Management periodically reviews the Status Accounting activities. Refer PMC Process.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Training</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Training on Configuration Status Accounting process/Templates</p></list-item></list></td>
</tr>
<tr>
<td><bold>Tools</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>MS Word, MS Excel, VSS/TFS/Any CM Tool</p></list-item></list></td>
</tr>
<tr>
<td><bold>Assumptions</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>PM may request the project status/baseline difference report any time throughout the SDLC.</p></list-item>
<list-item>
<p>Frequency of reports generation can be defined as per the project&#x2019;s needs.</p></list-item>
<list-item>
<p>SCM TL verifies the updates in the status report on weekly basis.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Exemptions</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Tailoring Guidelines</p></list-item></list></td>
</tr>
<tr>
<td><bold>Applicable standards &#x0026; documents</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Documentation Standards Manual,</p></list-item>
<list-item>
<p>PMC Process Guide/MA Process Guide</p></list-item>
<list-item>
<p>SCM Report template</p></list-item></list></td>
</tr>
</tbody>
</table></table-wrap>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>WFM for SP-3.2 of CM-PA &#x201C;Perform Configuration Audits&#x201D;</title>
<p>The purpose of SP-3.2 is to appraise the integrity of the baselines. As per CMMI, CM Audit is defined as &#x201C;Audit is to verify that a CIs or a collection of CIs that make up a baseline conforms to a specified standard or requirement&#x201D;. Only three among the findings from literature are given in <xref ref-type="table" rid="table-7">Tab. 7</xref> supporting each stage of the aforementioned WFM i.e., &#x201C;Planning&#x201D;, &#x201C;Preparation&#x201D;, &#x201C;Conduction&#x201D; and &#x201C;Closure&#x201D; and is depicted in <xref ref-type="fig" rid="fig-3">Fig. 3</xref> followed by the Process Guide in <xref ref-type="table" rid="table-8">Tab. 8</xref>.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Evidences from literature supporting each stage of WFM for SP 3.2</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>No.</th>
<th>Evidence from Literature</th>
<th>Author&#x2019;s Point of View</th>
<th>Author &#x0026; reference</th>
</tr>
</thead>
<tbody>
<tr>
<td colspan="4"><bold>A - Planning Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>International Journal of Government Auditing, International Standard of Supreme Audit Institutions (ISSAIs).</td>
<td>Performance audit guides published by various member countries e.g., <bold>Bangladesh</bold>, Kosovo, India, Pakistan etc. all follow the same standard that has four main stages namely &#x201C;Planning&#x201D;, &#x201C;Execution&#x201D;, &#x201C;Reporting&#x201D;, and &#x201C;Follow-up&#x201D;.</td>
<td>INTOSAI [<xref ref-type="bibr" rid="ref-23">23</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>Workflow model for Audit</td>
<td>Planning is essential for any activity and audit is not an exception. Planning is included as a stage in this workflow.</td>
<td>SASQAG [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>WFMs for SP-1.1 and SP-1.2 of PPQA-PA</td>
<td>The &#x201C;Plan&#x201D; stage was included in WFMs for auditing the said SPs with evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td colspan="4"><bold>B &#x2013; Preparation Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>Workflow model for Audit</td>
<td>An audit is as much successful as how much &#x201C;Preparation&#x201D; has been carried out prior to the conduction of audit and hence necessary to include this step in the said workflow.</td>
<td>SASQAG [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>Introduction to Software Process Improvement.</td>
<td>Prepared an audit 15 points checklist to help CM Auditor.</td>
<td>O&#x2019;Regan [<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>WFMs for SP-1.1 and SP-1.2 of PPQA-PA</td>
<td>The &#x201C;Prepare&#x201D; stage in WFMs for auditing both the SPs was included with adequate evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td colspan="4"><bold>C &#x2013; Conduction Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>Audit Guide</td>
<td>The &#x201C;Execution&#x201D; in ISSAI is similar to &#x201C;Conduction&#x201D; stage.</td>
<td>Audit Guide [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>Workflow model for Audit</td>
<td>The SASQAG Audit Workflow includes the &#x201C;Conduct Audit&#x201D; as a major step.</td>
<td>SASQAG [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>WFMs for SP-1.2 of PPQA-PA</td>
<td>&#x201C;Audit&#x201D; stage is included in WFMs for both with adequate evidences from literature.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
<tr>
<td colspan="4"><bold>D &#x2013; Closure Stage</bold></td>
</tr>
<tr>
<td>1</td>
<td>Workflow model for Audit</td>
<td>The SASQAG Audit Workflow includes the &#x201C;Close Out Audit&#x201D; as a major step and is similar to closure stage.</td>
<td>SASQAG [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
</tr>
<tr>
<td>2</td>
<td>ISSAIs</td>
<td>The activities carried out in this stage of proposed WFM are addressed in &#x201C;Reporting&#x201D; &#x0026; &#x201C;Follow-up&#x201D; stages of ISSAI.</td>
<td>Audit-Guide [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
</tr>
<tr>
<td>3</td>
<td>WFMs for SP-1.2 of PPQA-PA</td>
<td>&#x201C;Report&#x201D; stage is included with evidences from literature. Basically reporting is covered in this stage in our WFM.</td>
<td>Keshta [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
</tr>
</tbody>
</table></table-wrap>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Workflow model for SP-3.2</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="fig-3.png"/>
</fig>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Process guide for SP 3.2</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<tbody>
<tr>
<td>Purpose</td>
<td colspan="6">Configuration audits confirm that the resulting baselines/documentation conform to a specified standard and to ensure accuracy, consistency, and completeness of CIs.</td>
</tr>
<tr>
<td><bold>Scope</bold></td>
<td colspan="6">Scope of this process is to audit the CM department where integrity of all the project artifacts is evaluated. Audit scope is specified in the audit plan by the management.</td>
</tr>
<tr>
<td><bold>Abbreviations</bold></td>
<td colspan="2">
<list list-type="bullet">
<list-item>
<p>NCs</p></list-item>
<list-item>
<p>SCML</p></list-item>
<list-item>
<p>CMA</p></list-item></list></td>
<td colspan="4">Non-conformances<break/>Software Configuration Management Library<break/>Configuration Management Audit</td>
</tr>
<tr>
<td><bold>Entry criteria</bold></td>
<td colspan="6">Once notification for conducting audit is received as per the Configuration Management Plan</td>
</tr>
<tr>
<td rowspan="2"><bold>Inputs to the workflow and associated PAs/SPs</bold></td>
<td colspan="3"><bold>Input Work-Products</bold></td>
<td colspan="3"><bold>Associated PA/SP</bold></td>
</tr>
<tr>
<td colspan="3">
<list list-type="bullet">
<list-item>
<p>Project Plan/SCM Plan</p></list-item>
<list-item>
<p>CIs and Baselines</p></list-item>
<list-item>
<p>Change Requests</p></list-item>
<list-item>
<p>Configuration Management System (CMS)</p></list-item></list></td>
<td colspan="3">PP-PA<break/>Create Baselines<break/>Track Change Requests<break/>Establish CMS</td>
</tr>
<tr>
<td><bold>Stage</bold></td>
<td colspan="4"><bold>Process Activities</bold></td>
<td><bold>Activity Roles</bold></td>
<td><bold>Potential Records</bold></td>
</tr>
<tr>
<td rowspan="4"><bold><italic>A. Planning</italic></bold></td>
<td>A.1</td>
<td colspan="3">Organizational level quality standards, processes, plans are established.</td>
<td>PM, SCM TL, Dev TL</td>
<td>Processes, Standards, Plans</td>
</tr>
<tr>
<td>A.2</td>
<td colspan="3">An independent auditor is identified and audit criteria for SCM Audit is specified.</td>
<td>PM, SCM TL, SQTL</td>
<td>Audit Criteria</td>
</tr>
<tr>
<td>A.3</td>
<td colspan="3">Employees shall be encouraged to participation in identifying &#x0026; reporting CM Issues.</td>
<td>PM, SCM TL</td>
<td>SCM Issues</td>
</tr>
<tr>
<td>A.4</td>
<td colspan="3">The SCM Audit Plan shall be finalized.</td>
<td>PM, SCM TL, SQA TL</td>
<td>Correspondence with Auditor</td>
</tr>
<tr>
<td rowspan="4"><bold><italic>B. Preparation</italic></bold></td>
<td>B.1</td>
<td colspan="3">Checklist is prepared/reviewed for SCM Audit.</td>
<td>SQA/Auditor</td>
<td>SCM Audit Checklist</td>
</tr>
<tr>
<td>B.2</td>
<td colspan="3">Internal Audit shall be carried out prior to as a preparation to external audit.</td>
<td>SQA TL/PPQA</td>
<td>Internal Audit Report</td>
</tr>
<tr>
<td>B.3</td>
<td colspan="3">SCM shall be facilitated in obtaining requisite info/work products.</td>
<td>PM</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>B.4</td>
<td colspan="3">Schedule is confirmed and communicated to stakeholders.</td>
<td>PM, SQA TL, SCM TL</td>
<td>Corresp. with stakeholders</td>
</tr>
<tr>
<td rowspan="9"><bold><italic>C. Conduction</italic></bold></td>
<td>C.1</td>
<td colspan="3">SQA TL shall act a facilitator to the Auditor.</td>
<td>SQA TL</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>C.2</td>
<td colspan="3">The integrity of baselines are assessed as per defined audit criteria</td>
<td>SCM Auditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.3</td>
<td colspan="3">CMS records and CIs shall be tallied for connect identification.</td>
<td>SCM Auditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.4</td>
<td colspan="3">Structure and integrity of CIS in CMS shall be reviewed</td>
<td>SCM Auditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.5</td>
<td colspan="3">Disposition of change requests shall be checked.</td>
<td>SCM Auditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.6</td>
<td colspan="3">The completeness, correctness and consistency of CIs shall be confirmed.</td>
<td>SCM Auditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.7</td>
<td colspan="3">Compliance of CIs is evaluated against standards.</td>
<td>SCMAuditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.8</td>
<td colspan="3">Non-compliance, observation and improvement opportunities are collected and noted down.</td>
<td>SCM Auditor</td>
<td>Audit Notes</td>
</tr>
<tr>
<td>C.9</td>
<td colspan="3">The agreed upon audit findings shall be documented and shared.</td>
<td>Auditor, PM, SCM TL</td>
<td>Audit Notes</td>
</tr>
<tr>
<td rowspan="7"><bold><italic>D. Closure</italic></bold></td>
<td>D.1</td>
<td colspan="3">Audit findings/NCs shall be analysed for root causes and potential impact.</td>
<td>SCM TL, SQA TL</td>
<td>Root Causes/Impacts</td>
</tr>
<tr>
<td>D.2</td>
<td colspan="3">Audit findings are compared across the projects and/or organization to figure out trends, best practices and lessons learned.</td>
<td>SCM TL, SQA TL</td>
<td>Trends, best practices, lessons learned.</td>
</tr>
<tr>
<td>D.3</td>
<td colspan="3">Audit findings (NCs, observation, issues etc.) shall be discussed with relevant stakeholders.</td>
<td>SCM TL, SQA TL</td>
<td>Suggested CAs</td>
</tr>
<tr>
<td>D.4</td>
<td colspan="3">The issues shall be escalated to higher management for which the CAs are not feasible and approval is taken for organization-wide implementation of improvement opportunities.</td>
<td>SCM TL, PM</td>
<td>Management Directives/Decisions/Approvals</td>
</tr>
<tr>
<td>D.5</td>
<td colspan="3">Corrective actions shall be taken to close findings/NCs and improvements shall be incorporated for all instances of NCs.</td>
<td>SCM TL, SQA TL</td>
<td>CA reports</td>
</tr>
<tr>
<td>D.6</td>
<td colspan="3">Corrective actions shall be tracked to closure for all instances of NCs.</td>
<td>SCM TL</td>
<td>Follow-up Status</td>
</tr>
<tr>
<td>D.7</td>
<td colspan="3">Audit Status Report shall be prepared for publishing/sharing with stakeholders.</td>
<td>PM, SQA TL, SCM</td>
<td>Corrective Actions Reports</td>
</tr>
<tr>
<td><bold>Interfaces</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Artifacts generated from all PAs are referred to SCM-PA to be maintained in the CMS.</p></list-item>
<list-item>
<p>QC department performs testing and notifies SCM about the resolution of all bugs.</p></list-item>
<list-item>
<p>The schedule of configuration audit is received from the PP-PA.</p></list-item></list></td>
</tr>
<tr>
<td rowspan="2"><bold>Outputs of the workflow and associated PAs/SPs</bold></td>
<td colspan="4"><bold>Output Work-Products</bold></td>
<td colspan="2"><bold>Associated PA/SP</bold></td>
</tr>
<tr>
<td colspan="4">
<list list-type="bullet">
<list-item>
<p>Updated project plans</p></list-item>
<list-item>
<p>Corrective Actions</p></list-item>
<list-item>
<p>Internal Configuration Checklist, NCs, Audit Reports</p></list-item></list></td>
<td colspan="2">
<list list-type="bullet">
<list-item>
<p>PP-PA</p></list-item>
<list-item>
<p>Track Change Requests</p></list-item>
<list-item>
<p>Establish CM Records</p></list-item></list></td>
</tr>
<tr>
<td><bold>Exit criteria</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>The CM Audits have been conducted and corrective actions have been tracked to closure.</p></list-item>
<list-item>
<p>Audit report published.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Measures</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Ratio of (No of NCs closed/No of NCs identified)</p></list-item></list></td>
</tr>
<tr>
<td><bold>Verification points</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>PM shall verify the conduction of CM Audits as per PM&#x0026;C process guide.</p></list-item>
<list-item>
<p>QC shall perform testing activity to ensure fulfillment of specified requirements.</p></list-item>
<list-item>
<p>Management shall periodically review the activities, status and configuration audit findings.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Training</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Training on Perform Configuration Audit process and CM standards shall be conducted.</p></list-item>
<list-item>
<p>Templates/checklist usage training.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Tools</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>MS Word, MS Excel</p></list-item></list></td>
</tr>
<tr>
<td><bold>Assumptions</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Trained Human Resource, Hardware, Software, tools and Facilities are available.</p></list-item></list></td>
</tr>
<tr>
<td><bold>Exemptions</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Tailoring Guidelines</p></list-item></list></td>
</tr>
<tr>
<td><bold>Applicable standards &#x0026; related documents</bold></td>
<td colspan="6">
<list list-type="bullet">
<list-item>
<p>Availability of Documentation Standards Manual, CM Standards etc.</p></list-item>
<list-item>
<p>Tailoring Guidelines</p></list-item>
<list-item>
<p>PMC Process Guide</p></list-item>
<list-item>
<p>PPQA Process Guide</p></list-item></list></td>
</tr>
</tbody>
</table></table-wrap>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Validation of Proposed Models, Threats to Validity and Their Mitigation</title>
<sec id="s5_1">
<label>5.1</label>
<title>Validation Through EPR</title>
<p>In order to perform initial evaluation of the proposed models, an expert panel review was carried out where opinions on the models, based on the specified criteria, were taken from 10 experts. The experts having expertise in various domains (SPI, Project Management, Configuration Management and Software Development) were selected required for the study from Pakistani software industry and are enlisted along with the experience in <xref ref-type="table" rid="table-9">Tab. 9</xref>.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Profiles of the panel members</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Domain</th>
<th>No of Experts</th>
<th>Overall Knowledge/Experience</th>
<th>CMMI/SPI Knowledge &#x0026; Experience</th>
</tr>
</thead>
<tbody>
<tr>
<td>SPI Experts/CMMI Auditors</td>
<td>2</td>
<td>20, 17</td>
<td>20, 16</td>
</tr>
<tr>
<td>QA Managers</td>
<td>2</td>
<td>19, 17</td>
<td>19, 15</td>
</tr>
<tr>
<td>Project Managers</td>
<td>2</td>
<td>20, 15</td>
<td>15, 15</td>
</tr>
<tr>
<td>Configuration Managers/CM Auditors</td>
<td>2</td>
<td>20, 14</td>
<td>18, 13</td>
</tr>
<tr>
<td>Senior Software Engineers</td>
<td>2</td>
<td>16, 13</td>
<td>15, 12</td>
</tr>
</tbody>
</table></table-wrap>
<p>As in [<xref ref-type="bibr" rid="ref-26">26</xref>&#x2013;<xref ref-type="bibr" rid="ref-30">30</xref>] the researchers are free to frame their own criteria. In this study, the experts were classified into 3 groups based on their experience and knowledge. Experts having experience less than 15 years were classified as Junior, the experts having experience greater than 17 years as Senior and the remaining were classified as In-between. As per this criteria, the panel comprised of 10 experts with 4 seniors, 2 juniors and 4 In-between.</p>
<p>The questionnaire was formulated specifically to obtain the panel opinion on the proposed WFMs after studying the questionnaire designed for a similar work by Niazi [<xref ref-type="bibr" rid="ref-3">3</xref>] and Keshta [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-8">8</xref>]. The questionnaire comprised of three parts including a cover letter elucidating the purpose; demographics; and expert&#x2019;s opinion. The later part addresses the validation criteria specified in <xref ref-type="table" rid="table-4">Tab. 4</xref>. The questionnaire was reviewed by an academician to make it more legible and refined. The questionnaire comprised seven questions, as shown in <xref ref-type="table" rid="table-11">Tabs. 11</xref> and <xref ref-type="table" rid="table-12">12</xref>. Question 8 not shown in questionnaire was used to collect feedback to improve the models. Five point Likert measure with relative weight is given in <xref ref-type="table" rid="table-10">Tab. 10</xref>.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Relative weight of five-point liker measure</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>-</th>
<th>Strongly Disagree</th>
<th>Disagree</th>
<th>Neutral</th>
<th>Agree</th>
<th>Strongly Agree</th>
</tr>
</thead>
<tbody>
<tr>
<td>Weight</td>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>5</td>
</tr>
<tr>
<td>Mean</td>
<td>1.00&#x2013;1.80</td>
<td>1.81&#x2013;2.60</td>
<td>2.61&#x2013;3.40</td>
<td>3.41&#x2013;4.20</td>
<td>4.21&#x2013;5.00</td>
</tr>
</tbody>
</table></table-wrap>
<p>Summary of responses to questions about SP-3.1 and SP-3.2 of CM-PA are shown in <xref ref-type="table" rid="table-11">Tabs. 11</xref> and <xref ref-type="table" rid="table-12">12</xref>.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>Summary of the responses to the proposed model for Sp-3.1</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th></th>
<th></th>
<th><italic>Question</italic></th>
<th><italic>Measure</italic></th>
<th><italic>SD/&#x201C;1&#x201D;</italic></th>
<th><italic>D/&#x201C;2&#x201D;</italic></th>
<th><italic>N/&#x201C;3&#x201D;</italic></th>
<th><italic>A/&#x201C;4&#x201D;</italic></th>
<th><italic>SA/&#x201C;5&#x201D;</italic></th>
<th><italic>Mean</italic></th>
<th><italic>Rlt</italic></th>
</tr>
</thead>
<tbody>
<tr>
<td rowspan="4">Practice Satisfaction<break/>(Answer to RQ-A,B)</td>
<td rowspan="2">Q-1</td>
<td rowspan="2">As per CMMI Ver. 1.3, the proposed model would help to satisfy the practice and contribute towards the achievement of relevant goal.<break/>(Strongly Agree &#x2013; Strongly Disagree)</td>
<td>Freq</td>
<td>0</td>
<td>3</td>
<td>0</td>
<td>4</td>
<td>3</td>
<td rowspan="2">3.7</td>
<td rowspan="2"><bold>Agree</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>30</td>
<td>0</td>
<td>40</td>
<td>30</td>
</tr>
<tr>
<td rowspan="2">Q-2</td>
<td rowspan="2">How much our proposed WFM covers the SPs and Sub-SPs of the CM-PA?<break/>(Fully Covered 5 &#x2013; 1 Not Yet)</td>
<td>Freq</td>
<td>0</td>
<td>0</td>
<td>2</td>
<td>2</td>
<td>6</td>
<td rowspan="2">4.4</td>
<td rowspan="2"><bold>Fully Covered</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>0</td>
<td>20</td>
<td>20</td>
<td>60</td>
</tr>
<tr>
<td rowspan="4">User Satisfaction<break/>(Answer to RQ-C)</td>
<td rowspan="2">Q-3</td>
<td rowspan="2">The proposed WFMs would prove useful for SSMEs.<break/>(Very Useful 5 &#x2013; 1 Not at all)</td>
<td>Freq</td>
<td>0</td>
<td>2</td>
<td>1</td>
<td>3</td>
<td>4</td>
<td rowspan="2">3.9</td>
<td rowspan="2"><bold>Useful</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>20</td>
<td>10</td>
<td>30</td>
<td>40</td>
</tr>
<tr>
<td rowspan="2">Q-4</td>
<td rowspan="2">The use of the proposed WFM shall prove instrumental to improve software development process and contribute to quality of the products produced through it in SSMEs. (Strongly Agree &#x2013; Strongly Disagree)</td>
<td>Freq</td>
<td>0</td>
<td>4</td>
<td>0</td>
<td>3</td>
<td>3</td>
<td rowspan="2">3.5</td>
<td rowspan="2"><bold>Agree</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>40</td>
<td>0</td>
<td>30</td>
<td>30</td>
</tr>
<tr>
<td rowspan="4">Ease of Learning &#x0026; Use (Answer to RQ-D)</td>
<td rowspan="2">Q-5</td>
<td rowspan="2">How clearly the said WFMs represents the relevant SP.<break/>(Very Clear 5 &#x2013; 1 Not at all)</td>
<td>Freq</td>
<td>0</td>
<td>2</td>
<td>0</td>
<td>5</td>
<td>3</td>
<td rowspan="2">3.9</td>
<td rowspan="2"><bold>Clear</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>20</td>
<td>0</td>
<td>50</td>
<td>30</td>
</tr>
<tr>
<td rowspan="2">Q-6</td>
<td rowspan="2">In order to use the WFMs, how much CMMI knowledge would be required?<break/>(Not at all 5 &#x2013; 1 Too Much)</td>
<td>Freq</td>
<td>0</td>
<td>3</td>
<td>0</td>
<td>3</td>
<td>4</td>
<td rowspan="2">3.8</td>
<td rowspan="2"><bold>Little</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>30</td>
<td>0</td>
<td>30</td>
<td>40</td>
</tr>
<tr>
<td rowspan="2">Implement-ability<break/>(Answer to RQ-E)</td>
<td rowspan="2">Q-7</td>
<td rowspan="2">Our proposed WFMs can be implemented in SSMEs with little tailoring/tweaking.<break/>(Strongly Agree &#x2013; Strongly Disagree)</td>
<td>Freq</td>
<td>0</td>
<td>4</td>
<td>0</td>
<td>3</td>
<td>3</td>
<td rowspan="2">3.5</td>
<td rowspan="2"><bold>Agree</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>40</td>
<td>0</td>
<td>30</td>
<td>30</td>
</tr>
</tbody>
</table></table-wrap>
<table-wrap id="table-12">
<label>Table 12</label>
<caption>
<title>Summary of the responses to the proposed model for SP- 3.2</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th></th>
<th></th>
<th><italic>Question</italic></th>
<th><italic>Measure</italic></th>
<th><italic>SD/&#x201C;1&#x201D;</italic></th>
<th><italic>D/&#x201C;2&#x201D;</italic></th>
<th><italic>N/&#x201C;3&#x201D;</italic></th>
<th><italic>A/&#x201C;4&#x201D;</italic></th>
<th><italic>SA/&#x201C;5&#x201D;</italic></th>
<th><italic>Mean</italic></th>
<th><italic>Rlt</italic></th>
</tr>
</thead>
<tbody>
<tr>
<td rowspan="4">Practice Satisfaction<break/>(Answer to RQ-A,B)</td>
<td rowspan="2">Q-1</td>
<td rowspan="2">As per CMMI Ver. 1.3, the proposed model would help to satisfy the practice and contribute towards the achievement of relevant goal. (Strongly Agree &#x2013; Strongly Disagree)</td>
<td>Freq</td>
<td>0</td>
<td>3</td>
<td>0</td>
<td>3</td>
<td>4</td>
<td rowspan="2">3.8</td>
<td rowspan="2"><bold>Agree</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>30</td>
<td>0</td>
<td>30</td>
<td>40</td>
</tr>
<tr>
<td rowspan="2">Q-2</td>
<td rowspan="2">How much our proposed WFM covers the SPs and Sub-SPs of the CM-PA?<break/>(Fully Covered 5 &#x2013; 1 Not Yet)</td>
<td>Freq</td>
<td>0</td>
<td>0</td>
<td>2</td>
<td>3</td>
<td>5</td>
<td rowspan="2">4.3</td>
<td rowspan="2"><bold>Fully Covered</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>0</td>
<td>20</td>
<td>30</td>
<td>50</td>
</tr>
<tr>
<td rowspan="4">User Satisfaction<break/>(Answer to RQ-C)<break/></td>
<td rowspan="2">Q-3</td>
<td rowspan="2">The proposed WFMs would prove useful for SSMEs.<break/>(Very Useful 5 &#x2013; 1 Not at all)</td>
<td>Freq</td>
<td>0</td>
<td>3</td>
<td>0</td>
<td>4</td>
<td>3</td>
<td rowspan="2">3.7</td>
<td rowspan="2"><bold>Useful</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>30</td>
<td>0</td>
<td>40</td>
<td>30</td>
</tr>
<tr>
<td rowspan="2">Q-4</td>
<td rowspan="2">The use of the proposed WFM shall prove instrumental to improve software development process and contribute to quality of the products produced through it in SSMEs. (Strongly Agree &#x2013; Strongly Disagree)</td>
<td>Freq</td>
<td>0</td>
<td>3</td>
<td>0</td>
<td>5</td>
<td>2</td>
<td rowspan="2">3.6</td>
<td rowspan="2"><bold>Agree</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>30</td>
<td>0</td>
<td>50</td>
<td>20</td>
</tr>
<tr>
<td rowspan="4">Ease of Learning &#x0026; Use (Answer to RQ-D)</td>
<td rowspan="2">Q-5</td>
<td rowspan="2">How clearly the said WFMs represents the relevant SP.<break/>(Very Clear 5 &#x2013; 1 Not at all)</td>
<td>Freq</td>
<td>0</td>
<td>2</td>
<td>0</td>
<td>4</td>
<td>4</td>
<td rowspan="2">4.0</td>
<td rowspan="2"><bold>Clear</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>20</td>
<td>0</td>
<td>40</td>
<td>40</td>
</tr>
<tr>
<td rowspan="2">Q-6</td>
<td rowspan="2">In order to use the WFMs, how much CMMI knowledge would be required?<break/>(Not at all 5 &#x2013; 1 Too Much)</td>
<td>Freq</td>
<td>0</td>
<td>3</td>
<td>0</td>
<td>3</td>
<td>4</td>
<td rowspan="2">3.8</td>
<td rowspan="2"><bold>Little</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>30</td>
<td>0</td>
<td>30</td>
<td>40</td>
</tr>
<tr>
<td rowspan="2">Implement-ability<break/>(Answer to RQ-E)</td>
<td rowspan="2">Q-7</td>
<td rowspan="2">Our proposed WFMs can be implemented in SSMEs with little tailoring/tweaking.<break/>(Strongly Agree &#x2013; Strongly Disagree)</td>
<td>Freq</td>
<td>0</td>
<td>2</td>
<td>0</td>
<td>5</td>
<td>3</td>
<td rowspan="2">3.9</td>
<td rowspan="2"><bold>Agree</bold></td>
</tr>
<tr>
<td>%age</td>
<td>0</td>
<td>40</td>
<td>0</td>
<td>30</td>
<td>30</td>
</tr>
</tbody>
</table></table-wrap>
<p>As obvious from the results of EPR, the expert are strongly agree or agree that the models are instrumental in facilitating the implementation of the SPs, supportive in achieving SG-3, provide coverage to the sub-practices, are easy to learn, believed to be very useful to the software industry, perceived to improve process and contribute to the quality of the software produced. Further, it shall particularly support SSMEs in implementing the said SPs. However, it transpired from the EPR that a little knowledge about CM-PA of CMMI and CM domain is required. Results also suggest that there is a room for improvement in the WFMs.</p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Validation Through Case Studies</title>
<p>As a confidence measure, two Pakistani software SMEs were selected for carrying out case studies. The SSMEs were willing to publish the outcome of the study, however asked for non-disclosure of the SMEs names and project&#x2019;s info. As a confidentiality measure, the companies in this study are referred as Small Software Enterprise (SSE) and Medium Software Enterprise (MSE). Brief introduction of the companies are tabulated as under in <xref ref-type="table" rid="table-13">Tab. 13</xref>.</p>
<table-wrap id="table-13">
<label>Table 13</label>
<caption>
<title>Software setups participated in study</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Type of Setup</th>
<th>Emp(s) Strength</th>
<th>Core Business Activities</th>
</tr>
</thead>
<tbody>
<tr>
<td>SSE</td>
<td>32</td>
<td>Software development and provision of support to Pakistani Sugar Mills.</td>
</tr>
<tr>
<td>MSE</td>
<td>83</td>
<td>Development of ERP for SMEs and provision of maintenance support.</td>
</tr>
</tbody>
</table></table-wrap>
<p>After necessary coordination at management level, an opening sessions were arranged in both the SSMEs for participating employees including project manager, quality manager, configuration manager and relevant desirous system analysts, developers and testing professionals. The two companies&#x2019; collaborated and about 30 professionals participated. A brief presentation was given over the objectives of the study in these sessions. Soft copies of the models, templates, forms, guides were provided as well as an envelope full of hard copies was handed over for implementation in their environment within one month duration. After implementation in both the SSMEs, SCAMPI Type-&#x201C;C&#x201D; &#x0026; Type-&#x201C;B&#x201D; appraisals were conducted against the said SPs to evaluate its effectiveness by the lead auditor with appraisal team members (ATM). Finally, a closing session was conducted to get feedback from participating professionals. The appraisal results were encouraging and appreciated by the lead auditor. Confidence of the lead auditor reflected from his statement that both the SSMEs fulfill the requirements of the said SPs and will certainly result in &#x201C;Fully-Implemented&#x201D; if SCAMPI type &#x201C;A&#x201D; is conducted. In closing session, feedback was collected through the questionnaire that was originally designed for EPR.</p>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>The Proposed WFMs in Comparison with Earlier Models Developed for Various PAs of CMMI</title>
<p>A detailed comparison of the proposed models with the existing models are inscribed in <xref ref-type="table" rid="table-14">Tab. 14</xref>. The comparison criteria was taken from the work of Niazi [<xref ref-type="bibr" rid="ref-3">3</xref>], Keshta [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-8">8</xref>] and further refined.</p>
<table-wrap id="table-14">
<label>Table 14</label>
<caption>
<title>The proposed model in comparison with the earlier models found in literature</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr><th rowspan="2">Comparison Criteria</th><th rowspan="2">The Proposed Models</th><th colspan="7">References to Earlier Models</th>
</tr>
<tr>
<th>[<xref ref-type="bibr" rid="ref-3">3</xref>]<break/>Niazi</th>
<th>[<xref ref-type="bibr" rid="ref-4">4</xref>]<break/>Keshta</th>
<th>[<xref ref-type="bibr" rid="ref-5">5</xref>]<break/>Anum</th>
<th>[<xref ref-type="bibr" rid="ref-6">6</xref>]<break/>Bhatti</th>
<th>[<xref ref-type="bibr" rid="ref-7">7</xref>]<break/>Keshta</th>
<th>[<xref ref-type="bibr" rid="ref-8">8</xref>]<break/>Keshta</th>
<th>[<xref ref-type="bibr" rid="ref-9">9</xref>]<break/>Viva</th>
</tr>
</thead>
<tbody>
<tr>
<td>Is WFMs compliant to CMMI representation-(staged/phased)?</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
</tr>
<tr>
<td>Do WFMs achieve objectives of SG-2 of CM-PA?</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
</tr>
<tr>
<td>Are the WFMs devised SP-wise?</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
</tr>
<tr>
<td>Do it satisfy the relevant SPs (SP-2.1 &#x0026; SP-2.2)?</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
</tr>
<tr>
<td>Do the WFM cover the Sub-SPs?</td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>Do it satisfy user?</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
</tr>
<tr>
<td>Are the WFMs easy to learn/easy to use?</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
</tr>
<tr>
<td>Do the WFMs applicable to Software SMEs?</td>
<td>&#x263C;</td>
<td></td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td></td>
</tr>
<tr>
<td>Do the WFMs follow the ETVX Model?</td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>Have the associated templates, forms, checklists developed?</td>
<td>&#x263C;</td>
<td></td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td>&#x263C;</td>
<td>&#x263C;</td>
<td>&#x263C;</td>
</tr>
<tr>
<td>Is the Process Guide prepared?</td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>Does the model address the overall CM-PA?</td>
<td>&#x263C;</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table></table-wrap>
</sec>
<sec id="s5_4">
<label>5.4</label>
<title>Limitation of the Study/Threats to Validity and Their Mitigation Strategies</title>
<p>The limitations of the study, threats to its validity are explained in <xref ref-type="table" rid="table-15">Tab. 15</xref> along with mitigation strategies.</p>
<table-wrap id="table-15">
<label>Table 15</label>
<caption>
<title>Limitations of the study/threats to validity and mitigation strategies.</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Limitation/Threats to Validity</th>
<th>Mitigation Strategy</th>
</tr>
</thead>
<tbody>
<tr>
<td>Presence of the closed-ended questions in the questionnaire may not have captured the true respondent&#x2019;s feelings.</td>
<td>The impact was reduced by adding the open-ended questions as well. This added to the veracity of the response.</td>
</tr>
<tr>
<td>The panel members may have varying interpretation of the questions/WFMs and responded accordingly.</td>
<td>The questionnaire, due to close relevancy, was taken from Keshta&#x2019;s work. This was more refined by adding coverage of the framework at sub-practices level and reviewed by another academician.</td>
</tr>
<tr>
<td>The responses may have been limited to the knowledge and experiences of the respondents.</td>
<td>As a confidence building measure, experts with rich industry experience were selected. Presence of the world-renowned experts in the panel added to the effectiveness of the review process.</td>
</tr>
<tr>
<td>There might be a difference between responses received from Junior, In-between and Senior experts.</td>
<td>Fortunately, the number of senior and In-between experts exceeded the Junior experts. Further, the <italic>p</italic> &#x003E; 0.05 of Chi-Square (X<sup>2</sup>) test when &#x221E; is 0.05 &#x0026; degree of freedom is 2 against the responses which is indicative of insignificant variation among the responses provided by Senior, In-between and Junior experts.</td>
</tr>
<tr>
<td>The possibility that ordinary literature review process may have failed to see the relevant research work.</td>
<td>As per Hossain et al. [<xref ref-type="bibr" rid="ref-31">31</xref>], this cannot be taken as systematic omission.</td>
</tr>
<tr>
<td>Results and conclusions may not be valid for diversified or a typical environments.</td>
<td>In addition to the EPR, case studies were conducted in Pakistani Software Industry. Though results may be generalized for Pakistani SSMEs, however more case studies be carried out for other countries.</td>
</tr>
</tbody>
</table></table-wrap>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusion</title>
<p>Designing a workflow model to achieve SG-3 &#x201C;Establish Integrity&#x201D; of CM-PA at CMMI maturity level-II and its validation was the main objective of this study. Five research questions (RQ-A&#x007E;RQ-E) were formulated for the purpose. Further WFMs were devised for two SPs contributing to the aforesaid goal. It is clearly indicated in the <xref ref-type="table" rid="table-11">Tabs. 11</xref> and <xref ref-type="table" rid="table-12">12</xref> that which question of questionnaire addresses which research question making use of which validation criteria. Responses from the experts satisfied the said criteria. The results were further affirmed through conducting case studies. It is worth-mentioning that case studies demonstrated the ability of Pakistani SSMEs to adopt the proposed models with little tailoring to adjust their contexts. Satisfactory comments from participating organizations and experts speaks well of the WFMs and add to the confidence in the evaluation results. In face-to-face discussion with the participating professionals, it transpired that they had no problem in understanding/usage of the models with associated templates, forms, checklists and process guides as helping tools. The WFMs were refined after several rounds of improvements by incorporating suggestions from academicians, professionals and finally feedback from case studies. This work shall be continued to develop WFMs for other SPs of this PA, other PAs of Level-II as well as higher levels for which the workflow models are not developed yet. The models also need to be revised/validated for future versions of the CMMI.</p>
</sec>
</body>
<back><fn-group>
<fn fn-type="other">
<p><bold>Funding Statement:</bold> The author(s) received no specific funding for this study.</p>
</fn>
<fn fn-type="conflict">
<p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1">
<label>[1]</label><mixed-citation publication-type="conf-proc">
<person-group person-group-type="author"><string-name>
<given-names>G.</given-names> 
<surname>Xu</surname></string-name>, <string-name>
<given-names>H.</given-names> 
<surname>Hu</surname></string-name>, <string-name>
<given-names>P.</given-names> 
<surname>Yu</surname></string-name>, <string-name>
<given-names>J.</given-names> 
<surname>Lv</surname></string-name>, <string-name>
<given-names>P.</given-names> 
<surname>Qu</surname></string-name> <etal>et al.</etal>
</person-group><italic>,</italic> &#x201C;
<article-title>Supporting flexibility of the CMMI process framework with a multi-layered process model</article-title>,&#x201D; in <conf-name>Web Information System and Application Conference (WISA 2013)</conf-name>, Yangzhou, China, pp. 
<fpage>409</fpage>&#x2013;
<lpage>414</lpage>, 
<year iso-8601-date="2013">2013</year>. </mixed-citation>
</ref>
<ref id="ref-2">
<label>[2]</label><mixed-citation publication-type="other">
<person-group person-group-type="author">
<collab>CMMI Product Team</collab>
</person-group>, &#x201C;
<article-title>CMMI for Development</article-title>, 
<comment>Version 1.3</comment>,&#x201D; 
<year iso-8601-date="2010">2010</year>.</mixed-citation>
</ref>
<ref id="ref-3">
<label>[3]</label><mixed-citation publication-type="book">
<person-group person-group-type="author"><string-name>
<given-names>M.</given-names> 
<surname>Niazi</surname></string-name>, <string-name>
<given-names>C.</given-names> 
<surname>Hickman</surname></string-name>, <string-name>
<given-names>R.</given-names> 
<surname>Ahmad</surname></string-name> and <string-name>
<given-names>M.</given-names> 
<surname>Ali Babar</surname></string-name>
</person-group>, &#x201C;<chapter-title>A model for requirements change management: Implementation of CMMI level 2 specific practice</chapter-title>,&#x201D; in 
<source>9th International Conference on Product-Focused Software Process Improvement (PROFES 2008)</source>, Springer Berlin Heidelberg, Monte Porzio Catone, Italy, vol. 
<volume>5089</volume>, pp. 
<fpage>143</fpage>&#x2013;
<lpage>157</lpage>, 
<year iso-8601-date="2008">2008</year>.</mixed-citation>
</ref>
<ref id="ref-4">
<label>[4]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>I.</given-names> 
<surname>Keshta</surname></string-name>, <string-name>
<given-names>M.</given-names> 
<surname>Niazi</surname></string-name> and <string-name>
<given-names>M.</given-names> 
<surname>Alshayeb</surname></string-name>
</person-group>, &#x201C;
<article-title>Towards implementation of requirements management specific practices (SP1.3 and SP1.4) for Saudi Arabian small and medium sized software development organizations</article-title>,&#x201D; 
<source>IEEE Access</source>, vol. 
<volume>5</volume>, pp. 
<fpage>24162</fpage>&#x2013;
<lpage>24183</lpage>, 
<year iso-8601-date="2017">2017</year>.</mixed-citation>
</ref>
<ref id="ref-5">
<label>[5]</label><mixed-citation publication-type="conf-proc">
<person-group person-group-type="author"><string-name>
<given-names>A.</given-names> 
<surname>Tariq</surname></string-name>, <string-name>
<given-names>S. A.</given-names> 
<surname>Khan</surname></string-name> and <string-name>
<given-names>S.</given-names> 
<surname>Iftikhar</surname></string-name>
</person-group>, &#x201C;
<article-title>Remapping of CMMI level-2 KPA&#x2019;s for development process improvement of software-as-a-service (SaaS) cloud environment</article-title>,&#x201D; in <conf-name>Int. Conf. on Open Source Systems and Technologies (ICOSST)</conf-name>, Lahore, Pakistan, pp. 
<fpage>43</fpage>&#x2013;
<lpage>51</lpage>, 
<year iso-8601-date="2014">2014</year>. </mixed-citation>
</ref>
<ref id="ref-6">
<label>[6]</label><mixed-citation publication-type="conf-proc">
<person-group person-group-type="author"><string-name>
<given-names>M. W.</given-names> 
<surname>Bhatti</surname></string-name>, <string-name>
<given-names>F.</given-names> 
<surname>Hayat</surname></string-name>, <string-name>
<given-names>N.</given-names> 
<surname>Ehsan</surname></string-name>, <string-name>
<given-names>A.</given-names> 
<surname>Ishaque</surname></string-name>, <string-name>
<given-names>S.</given-names> 
<surname>Ahmed</surname></string-name> <etal>et al.</etal>
</person-group><italic>,</italic> &#x201C;
<article-title>A methodology to manage the changing requirements of a software project</article-title>,&#x201D; in <conf-name>Int. Conf. on Computer Information Systems and Industrial Management Applications (CISIM)</conf-name>, Krackow, Poland, pp. 
<fpage>319</fpage>&#x2013;
<lpage>322</lpage>, 
<year iso-8601-date="2010">2010</year>. </mixed-citation>
</ref>
<ref id="ref-7">
<label>[7]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>I.</given-names> 
<surname>Keshta</surname></string-name>
</person-group>, &#x201C;
<article-title>A model for defining project lifecycle phases: Implementation of CMMI level 2 specific practice</article-title>,&#x201D; 
<source>Journal of King Saud University - Computer and Information Sciences</source>, pp. 1&#x2013;10, 
<year iso-8601-date="2019">2019</year>.</mixed-citation>
</ref>
<ref id="ref-8">
<label>[8]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>I.</given-names> 
<surname>Keshta</surname></string-name>, <string-name>
<given-names>M.</given-names> 
<surname>Niazi</surname></string-name> and <string-name>
<given-names>M.</given-names> 
<surname>Alshayeb</surname></string-name>
</person-group>, &#x201C;
<article-title>Towards implementation of process and product quality assurance process area for Saudi Arabian small and medium sized software development organizations</article-title>,&#x201D; 
<source>IEEE Access</source>, vol. 
<volume>6</volume>, pp. 
<fpage>41643</fpage>&#x2013;
<lpage>41675</lpage>, 
<year iso-8601-date="2018">2018</year>.</mixed-citation>
</ref>
<ref id="ref-9">
<label>[9]</label><mixed-citation publication-type="conf-proc">
<person-group person-group-type="author"><string-name>
<given-names>C.</given-names> 
<surname>Vivatanavorasin</surname></string-name>, <string-name>
<given-names>N.</given-names> 
<surname>Prompoon</surname></string-name> and <string-name>
<given-names>A.</given-names> 
<surname>Surarerks</surname></string-name>
</person-group>, &#x201C;
<article-title>A process model design and tool development for supplier agreement management of CMMI: Capability level 2</article-title>,&#x201D; in <conf-name>XIII ASIA PACIFIC Software Engineering Conf. (APSEC&#x2019;06)</conf-name>, Kanpur, India, pp. 
<fpage>385</fpage>&#x2013;
<lpage>392</lpage>, 
<year iso-8601-date="2006">2006</year>. </mixed-citation>
</ref>
<ref id="ref-10">
<label>[10]</label><mixed-citation publication-type="book">
<person-group person-group-type="author"><string-name>
<given-names>E.</given-names> 
<surname>Hochbergs</surname></string-name>
</person-group>, 
<source>MS Thesis by Erik Hochbergs and Laroy Nilsson Sj&#x00F6;dahl from Department of Computer Science LTH</source>, 
<publisher-name>Lund University</publisher-name>, Lund Sweden, 
<year iso-8601-date="2020">2020</year>.</mixed-citation>
</ref>
<ref id="ref-11">
<label>[11]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>S.</given-names> 
<surname>Fahmy</surname></string-name>, <string-name>
<given-names>A.</given-names> 
<surname>Deraman</surname></string-name>, <string-name>
<given-names>J.</given-names> 
<surname>Yahaya</surname></string-name>, <string-name>
<given-names>A.</given-names> 
<surname>Nasir</surname></string-name> and <string-name>
<given-names>N.</given-names> 
<surname>Shamsudin</surname></string-name>
</person-group>, &#x201C;
<article-title>The evolution of software configuration management</article-title>,&#x201D; 
<source>International Journal of Advanced Trends in Computer Science and Engineering</source>, vol. 
<volume>9</volume>, no. 
<issue>1.3</issue>, pp. 
<fpage>50</fpage>&#x2013;
<lpage>63</lpage>, 
<year iso-8601-date="2020">2020</year>.</mixed-citation>
</ref>
<ref id="ref-12">
<label>[12]</label><mixed-citation publication-type="conf-proc">
<person-group person-group-type="author"><string-name>
<given-names>M.</given-names> 
<surname>Tuape</surname></string-name>
</person-group>, &#x201C;
<article-title>Factors affecting development process in small software companies</article-title>,&#x201D; in <conf-name>IEEE/ACM Symposium on Software Engineering in Africa (SEiA)</conf-name>, Montr&#x00E9;al, Qu&#x00E9;bec, Canada, pp. 
<fpage>16</fpage>&#x2013;
<lpage>23</lpage>, 
<year iso-8601-date="2019">2019</year>. </mixed-citation>
</ref>
<ref id="ref-13">
<label>[13]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>V.</given-names> 
<surname>Jos&#x00E9;</surname></string-name>, <string-name>
<given-names>G.</given-names> 
<surname>Camila</surname></string-name>, <string-name>
<given-names>R.</given-names> 
<surname>Balancieri</surname></string-name> and <string-name>
<given-names>A. C.</given-names> 
<surname>Rouiller</surname></string-name>
</person-group>, &#x201C;
<article-title>The measurement process in micro and small software maintenance companies: Empirical study</article-title>,&#x201D; 
<source>Independent Journal of Management &#x0026; Production (IJM&#x0026;P)</source>, vol. 
<volume>11</volume>, pp. 
<fpage>519</fpage>&#x2013;
<lpage>538</lpage>, 
<year iso-8601-date="2020">2020</year>.</mixed-citation>
</ref>
<ref id="ref-14">
<label>[14]</label><mixed-citation publication-type="book">
<person-group person-group-type="author"><string-name>
<given-names>T. M.</given-names> 
<surname>Eshete</surname></string-name>
</person-group>, 
<source>Thesis of MS in Software Engineering by Tadele Mengiste Eshete A</source>, School of Research and Postgraduate Studies Faculty F Computing, Bahir Dar University Bahir Dar Institute of Technology, DSpace Institution, DSpace Repository, 
<year iso-8601-date="2020">2020</year>. <uri>http://dspace.org</uri>.</mixed-citation>
</ref>
<ref id="ref-15">
<label>[15]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>S.</given-names> 
<surname>Dasanayaka</surname></string-name>
</person-group>, &#x201C;
<article-title>SMEs in globalized world: A brief note on basic profiles of Pakistan&#x2019;s small and medium scale enterprises and possible research directions</article-title>,&#x201D; 
<source>Research Journal of the Institute of Business Administration Karachi &#x2013; Pakistan</source>, vol. 
<volume>3</volume>, no. 
<issue>1</issue>, pp. 
<fpage>69</fpage>&#x2013;
<lpage>90</lpage>, 
<year iso-8601-date="2008">2008</year>.</mixed-citation>
</ref>
<ref id="ref-16">
<label>[16]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>S.</given-names> 
<surname>Divakara</surname></string-name> and <string-name>
<given-names>H. N. S. K.</given-names> 
<surname>Surangi</surname></string-name>
</person-group>, &#x201C;
<article-title>A literature review on small &#x0026; medium size enterprises</article-title>,&#x201D; 
<source>Journal of Business and Technology</source>, vol. 
<volume>2</volume>, no. 
<issue>3</issue>, pp. 
<fpage>23</fpage>, 
<year iso-8601-date="2018">2018</year>.</mixed-citation>
</ref>
<ref id="ref-17">
<label>[17]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>H.</given-names> 
<surname>Karadag</surname></string-name>
</person-group>, &#x201C;
<article-title>The role and challenges of small and medium-sized enterprises (SMEs) in emerging economies: An analysis from Turkey</article-title>,&#x201D; 
<source>Business and Management Studies</source>, vol. 
<volume>1</volume>, no. 
<issue>2</issue>, pp. 
<fpage>179</fpage>&#x2013;
<lpage>188</lpage>, 
<year iso-8601-date="2015">2015</year>.</mixed-citation>
</ref>
<ref id="ref-18">
<label>[18]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>A.</given-names> 
<surname>Tripathi</surname></string-name>
</person-group>, &#x201C;
<article-title>SMEs in Saudi Arabia - an innovative tool for country&#x2019;s economic growth</article-title>,&#x201D; 
<source>Science International (Lahore)</source>, vol. 
<volume>31</volume>, no. 
<issue>2</issue>, pp. 
<fpage>261</fpage>&#x2013;
<lpage>267</lpage>, 
<year iso-8601-date="2019">2019</year>.</mixed-citation>
</ref>
<ref id="ref-19">
<label>[19]</label><mixed-citation publication-type="book">
<person-group person-group-type="author"><string-name>
<given-names>C.</given-names> 
<surname>Mary Beth</surname></string-name>, <string-name>
<given-names>M.</given-names> 
<surname>Konrad</surname></string-name> and <string-name>
<given-names>S.</given-names> 
<surname>Shrum</surname></string-name>
</person-group>, 
<source>CMMI for Development</source>. 
<edition>Third</edition> Edition, 
<publisher-name>Addison Wesley, Pearson Education, Boston, USA</publisher-name>, 
<year iso-8601-date="2017">2017</year>.</mixed-citation>
</ref>
<ref id="ref-20">
<label>[20]</label><mixed-citation publication-type="book">
<person-group person-group-type="author"><string-name>
<given-names>G.</given-names> 
<surname>O&#x2019;Regan</surname></string-name>
</person-group>, 
<source>Introduction to Software Process Improvement</source>. 
<publisher-loc>London Dordrecht Heidelberg New York</publisher-loc>: 
<publisher-name>Springer</publisher-name>, 
<year iso-8601-date="2011">2011</year>.</mixed-citation>
</ref>
<ref id="ref-21">
<label>[21]</label><mixed-citation publication-type="other">
<person-group person-group-type="author"><string-name>
<given-names>A.</given-names> 
<surname>Abran</surname></string-name>, <string-name>
<given-names>J. W.</given-names> 
<surname>Moore</surname></string-name>, <string-name>
<given-names>R.</given-names> 
<surname>Dupuis</surname></string-name>, <string-name>
<given-names>R.</given-names> 
<surname>Dupuis</surname></string-name> and <string-name>
<given-names>L. L.</given-names> 
<surname>Tripp</surname></string-name>
</person-group>, &#x201C;
<source>Guide to the Software Engineering Body of Knowledge (SWEBOK)</source>, 
<publisher-name>A Project of the IEEE Computer Society</publisher-name>, 
<comment>Version 3.0</comment>, 
<year iso-8601-date="2014">2014</year>.</mixed-citation>
</ref>
<ref id="ref-22">
<label>[22]</label><mixed-citation publication-type="book">
<person-group person-group-type="author"><string-name>
<given-names>G.</given-names> 
<surname>O&#x2019;Regan</surname></string-name>
</person-group>, 
<source>Introduction To Software Quality Assurance</source>. 
<publisher-loc>Ireland, Cham Heidelberg New York Dordrecht London</publisher-loc>: 
<publisher-name>Springer</publisher-name>, 
<year iso-8601-date="2014">2014</year>.</mixed-citation>
</ref>
<ref id="ref-23">
<label>[23]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>J. C.</given-names> 
<surname>Blockwood</surname></string-name>,
</person-group> &#x201C;
<article-title>Editor, Professional skepticism: A model for public sector auditing</article-title>,&#x201D; 
<source>International Journal of Governemnt Auditing</source>, vol. 
<volume>47</volume>, no. 
<issue>3</issue>, pp. 
<fpage>45</fpage>, 
<year iso-8601-date="2020">2020</year>, [Online]. Available: <uri>www.intosaijournal.org</uri>.</mixed-citation>
</ref>
<ref id="ref-24">
<label>[24]</label><mixed-citation publication-type="other">
<person-group person-group-type="author"><string-name>
<given-names>I.</given-names> 
<surname>Guidelines</surname></string-name>
</person-group>, &#x201C;
<source>ISSAI Guidelines on Performance Audit</source>,&#x201D; 
<year iso-8601-date="2010">2010</year>.</mixed-citation>
</ref>
<ref id="ref-25">
<label>[25]</label><mixed-citation publication-type="other">
<person-group person-group-type="author"><string-name>
<given-names>T.</given-names> 
<surname>Gilchrist</surname></string-name>
</person-group>, &#x201C;
<article-title>Software Process Reviews/Audits Process Overview - SASQAG</article-title>,&#x201D; 
<year iso-8601-date="2010">2010</year>.</mixed-citation>
</ref>
<ref id="ref-26">
<label>[26]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>S. U.</given-names> 
<surname>Khan</surname></string-name>, <string-name>
<given-names>M.</given-names> 
<surname>Niazi</surname></string-name> and <string-name>
<given-names>R.</given-names> 
<surname>Ahmad</surname></string-name>
</person-group>, &#x201C;
<article-title>Empirical investigation of success factors for offshore software development outsourcing vendors</article-title>,&#x201D; 
<source>Institute of Engineering and Technology Software</source>, vol. 
<volume>6</volume>, no. 
<issue>1</issue>, pp. 
<fpage>1</fpage>&#x2013;
<lpage>15</lpage>, 
<year iso-8601-date="2012">2012</year>.</mixed-citation>
</ref>
<ref id="ref-27">
<label>[27]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>M. I. U.</given-names> 
<surname>Lali</surname></string-name>, <string-name>
<given-names>R. U.</given-names> 
<surname>Mustafa</surname></string-name>, <string-name>
<given-names>K.</given-names> 
<surname>Saleem</surname></string-name>, <string-name>
<given-names>M. S.</given-names> 
<surname>Nawaz</surname></string-name>, <string-name>
<given-names>T.</given-names> 
<surname>Zia</surname></string-name> <etal>et al.</etal>
</person-group><italic>,</italic> &#x201C;
<article-title>Finding healthcare issues with search engine queries and social network data</article-title>,&#x201D; 
<source>International Journal on Semantic Web and Information Systems</source>, vol. 
<volume>13</volume>, no. 
<issue>1</issue>, pp. 
<fpage>48</fpage>&#x2013;
<lpage>62</lpage>, 
<year iso-8601-date="2017">2017</year>.</mixed-citation>
</ref>
<ref id="ref-28">
<label>[28]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>B.</given-names> 
<surname>Shahzad</surname></string-name>, <string-name>
<given-names>Y.</given-names> 
<surname>Al-Ohali</surname></string-name> and <string-name>
<given-names>A.</given-names> 
<surname>Abdullah</surname></string-name>
</person-group>, &#x201C;
<article-title>Trivial model for mitigation of risks in software development life cycle</article-title>,&#x201D; 
<source>International Journal of the Physical Sciences</source>, vol. 
<volume>6</volume>, no. 
<issue>8</issue>, pp. 
<fpage>2072</fpage>&#x2013;
<lpage>2082</lpage>, 
<year iso-8601-date="2011">2011</year>.</mixed-citation>
</ref>
<ref id="ref-29">
<label>[29]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>B.</given-names> 
<surname>Shahzad</surname></string-name> and <string-name>
<given-names>S.</given-names> 
<surname>Afzal Safvi</surname></string-name>
</person-group>, &#x201C;
<article-title>Effective risk mitigation: A user prospective</article-title>,&#x201D; 
<source>International Journal of Mathematics and Computers in Simulation</source>, vol. 
<volume>2</volume>, no. 
<issue>1</issue>, pp. 
<fpage>70</fpage>&#x2013;
<lpage>80</lpage>, 
<year iso-8601-date="2008">2008</year>.</mixed-citation>
</ref>
<ref id="ref-30">
<label>[30]</label><mixed-citation publication-type="journal">
<person-group person-group-type="author"><string-name>
<given-names>M.</given-names> 
<surname>Shafiq</surname></string-name>, <string-name>
<given-names>M.</given-names> 
<surname>Ahmad</surname></string-name> and <string-name>
<given-names>J. G.</given-names> 
<surname>Choi</surname></string-name>
</person-group>, &#x201C;
<article-title>Public system usability analysis for the valuation of cognitive burden and interface standardization: A case study of cross-ATM design</article-title>,&#x201D; 
<source>Journal of Organizational Computing and Electronic Commerce</source>, vol. 
<volume>27</volume>, no. 
<issue>2</issue>, pp. 
<fpage>162</fpage>&#x2013;
<lpage>196</lpage>, 
<year iso-8601-date="2017">2017</year>.</mixed-citation>
</ref>
<ref id="ref-31">
<label>[31]</label><mixed-citation publication-type="conf-proc">
<person-group person-group-type="author"><string-name>
<given-names>E.</given-names> 
<surname>Hossain</surname></string-name>, <string-name>
<given-names>M.</given-names> 
<surname>Ali Babar</surname></string-name> and <string-name>
<given-names>H. Y.</given-names> 
<surname>Paik</surname></string-name>
</person-group>, &#x201C;
<article-title>Using scrum in global software development: A systematic literature review</article-title>,&#x201D; in <conf-name>Fourth IEEE Int. Conf. on Global Software Engineering (ICGSE 2009)</conf-name>, Limerick, Ireland, pp. 
<fpage>175</fpage>&#x2013;
<lpage>184</lpage>, 
<year iso-8601-date="2009">2009</year>. </mixed-citation>
</ref>
</ref-list>
</back>
</article>