The stakeholders of security system should be trained on security data collection methods and:
An objective baseline relies on judgment being applied in making the measure.
Subjective baseline studies are commonly conducted studies in measuring quality and productivity. Define what is meant by "subjective", give three examples of products / services / processes that can be measured subjectively, and for each example given, explain how that subjective measure might be used to improve quality.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Your manager has ask you to help develop a well defined continuous improvement process that can be used by the various teams in the IT department. Use the PDCA concept to provide a detailed outline of your continuous improvement process.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Deming's quality principles include the elimination of fear. Explain three specific ways that the software quality assurance function might help to eliminate fear.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Quality Control is the check component of Dr. Deming’s Plan-Do-Check-Act quality concept. List what you believe are the three most important quality control practices in an IT organization, briefly describe those practices, and explain why you believe each practice is one of the MOST important quality control practices.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Define what “force-field analysis” is, and describe the steps a team would use to employ force-field analysis.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
What is independent monitoring and who can perform it?
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Two of the best accepted industry models are the SEI Capability Maturity Model Integration for Software and ISO 9000 standards. Describe the two models, and explain the differences between the two models.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
There are three types of enforcement actions; automated enforcement, self-enforcement, and supervisory enforcement. Which of these is the best enforcement action and why? Give an example that illustrates why it is the best.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
As more of an organization’s business goes online the need for security increases. As a quality assurance manager, your IT Director knows that security is comprised of technical controls and management controls. The technical controls such as virus protecting software are very complex and its effectiveness would be difficult to evaluate by the average quality assurance professional. However, quality assurance professionals should be able to evaluate the management controls over security. To accomplish this, your IT Director has asked you to develop a ten question checklist that could be used to determine whether or not adequate management security controls exist over online software systems.
List below the ten questions you would put on that checklist.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Provide an explanation of the software testing process for an audience that likes to think in terms of the Plan-Do-Check-Act cycle.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
One of the means to describe a work task or activity is a workbench; a workbench is a graphical representation of a work task. As a Quality Assurance Manager, one of your work tasks is to provide quality training for the IT staff. Describe the components on the workbench that you would use to train a single individual in the quality principles and indicate the entrance and exit criteria as well as the activity that you would perform for each component of the workbench.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
A model (like CMMI or ISO 9001) is an idealized concept to be accomplished. Organizations choose to adopt a model for a variety of reasons. Describe two reasons you believe an organization might adopt a model.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Defect data has been collected for two software projects. When analyzed quantitatively, one project seems to be under statistical control with all defect rates within the calculated control limits, while the other project shows several data points outside the calculated control limits. Explain how each team should approach improving their processes given this data analysis.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.