2 cissp ® Official Study Guide Eighth Edition


Maintenance and Change Management



Download 19,3 Mb.
Pdf ko'rish
bet818/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   814   815   816   817   818   819   820   821   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Maintenance and Change Management
Once a system is operational, a variety of maintenance tasks are necessary to ensure con-
tinued operation in the face of changing operational, data processing, storage, and environ-
mental requirements. It’s essential that you have a skilled support team in place to handle 
any routine or unexpected maintenance. It’s also important that any changes to the code 
be handled through a formalized change management process, as described in Chapter 1, 
“Security Governance Through Principles and Policies.”
Lifecycle Models
One of the major complaints you’ll hear from practitioners of the more established engineer-
ing disciplines (such as civil, mechanical, and electrical engineering) is that software engineer-
ing is not an engineering discipline at all. In fact, they contend, it’s simply a combination of 
chaotic processes that somehow manage to scrape out workable solutions from time to time. 
Indeed, some of the “software engineering” that takes place in today’s development environ-
ments is nothing but bootstrap coding held together by “duct tape and chicken wire.”


882
Chapter 20 

Software Development Security
However, the adoption of more formalized lifecycle management processes is seen in 
mainstream software engineering as the industry matures. After all, it’s hardly fair to com-
pare the processes of an age-old discipline such as civil engineering to those of an industry 
that’s only a few decades old. In the 1970s and 1980s, pioneers like Winston Royce and 
Barry Boehm proposed several software development lifecycle (SDLC) models to help guide 
the practice toward formalized processes. In 1991, the Software Engineering Institute 
introduced the Capability Maturity Model, which described the process that organizations 
undertake as they move toward incorporating solid engineering principles into their soft-
ware development processes. In the following sections, we’ll take a look at the work pro-
duced by these studies. Having a management model in place should improve the resultant 
products. However, if the SDLC methodology is inadequate, the project may fail to meet 
business and user needs. Thus, it is important to verify that the SDLC model is properly 
implemented and is appropriate for your environment. Furthermore, one of the initial steps 
of implementing an SDLC should include management approval.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   814   815   816   817   818   819   820   821   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish