Wednesday, 13 April 2016

Planning for ISO 27001 - Part 1

web application development companies

Introduction

ISO/IEC 27001:2005 Information Technology— Security techniques—Information security management systems—Requirements is an information security management system (ISMS) standard published in October 2005 by the InternationalOrganization for Standardization (ISO) and International Electro technical Commission (IEC).The potential benefits of implementing ISO 27001 and obtaining certification are numerous also implementing ISO 27001 enables enterprises to benchmark against competitors and to provide relevant information about IT security to vendors and customers, it enables management to demonstrate due diligence. And it also can foster efficient security cost management, and compliance with laws & regulations, a comfortable level of interoperability due to a common set of guidelines followed by the partner organization. It also helps in improving IT information security system quality assurance (QA) and increase security awareness among the employees, customers and the vendors, etc., and it can also increase IT and business alignment. And it also provides a process framework for IT security implementation and can also assist in determining the status of information security and the degree of compliance with the security policies, the directives and standards. Many software development companies, custom application development companies, web application development companies etc are leveraging benefits of implementing ISO 27001.

Costs of Implementation

Before implementing ISO 27001, one needs to consider the costs and project length all of which are further influenced by the detailed understanding of the implementation phases. Also in today’s cloud computing environment, the organizations that want to reduce costs without compromising information security are looking at ISO 27001 certification as a promising means to provide knowledge about their IT security. Implementation costs are driven by the perception of risk and how much risk an organization is prepared to accept. Companies such as software development companies incur various costs while implementation. In total four costs need to be considered when implementing this type of project:

1. Internal resources—The system covers a wide range of business functions which include management, human resources (HR), IT, facilities and security. All these resources will be required during the implementation of the ISMS.

2. External resources—Experienced consultants will save a huge amount of time and cost. Also they will prove useful during internal audits and ensure a smooth transition toward certification.

3. Certification—Only a few approved certification agencies currently assess companies against ISO 27001, although fees are not much more than against other standards.

4. Implementation—These costs depend largely on the health of IT within the organization. Thus if, as a result of a risk assessment or audit, a gap appears, then the implementation costs are bound to go up based on the solution implemented.


Author Signature: Shreyans Agrawal (ifour.shreyans.agrawal@gmail.com)

Tuesday, 12 April 2016

Legal Infrastructure on Industrial Safety - Part 3

EMERGING ISSUES

General Legislation on Occupational Safety and Health

At present, separate statutes are enacted covering safety and health aspects of workers employed in some sectors such as factories, mines, ports and docks and construction. Many branches of economic activities are out of coverage of OSH Legislation. There is a need for enactment of a general legislation to secure safety and health of persons at work as well as other persons, against the risks arising out of or in connection with the activities at all places of work(software development firm in ahmedabad).

National Board for Accreditation in Occupational Safety and Health

The existing statutes on safety and health require regulation, recognition, certification, approvals etc. in respect of many of the requirements. Since there are multiple agencies namely, CIFs of various States/UTs, it is felt that there should be a single agency.

Self-Certification and Third Party Certification

In order to reduce the burden of inspection, a system of self-certification regarding compliance with OSH standards can be introduced. The factories employing less than 50 workers could be required to furnish the Annual Return on the compliance with the certain provisions of the Factories Act, 1948. These Returns can be accepted as a self-certification and no inspection may be undertaken in respect of such factories. However, inspections can be carried out in case of complaints, accidents, etc. Any non-compliance detected during such inspection should be taken very seriously and the occupier and manager of such factories can be severely punished. A system of self-certification in respect of compliance with labour laws has been introduced by certain States such as Gujarat, Punjab, Uttar Pradesh, etc.

Protection of Women Workers vis-à-vis Equal Opportunities

In the era of globalization and liberalization, equal opportunities to male and female workers have become essential feature of any business enterprise. At international level also women employees are contributing significantly in the growth of business. Therefore, the restrictive provisions under the statutes seem to be discriminating and many women organizations(Empowring Woman worker in Software development company in india) have taken up the issue at social, political and judicial levels.

Conclusion

In India, a national system on Occupational Safety and Health in the form of policy, statutes and regulatory mechanism exists in respect of certain branches of economic activities namely, factories, mines, ports and docks and construction. However, there is a need to extend the OSH coverage to all other sectors, through appropriate means. Further, with the phenomenal growth in the industrial sector, a system of self-certification and third party certification in the field of OSH is essential in order to reduce the burden of inspection.


References

1. Constitution of India
2. The Factories Act, 1948
3. The Model Rules under the Factories Act, 1948;
DGFASLI 1998
4. Annual Report 2007-2008; Ministry of Labour &
Employment
5. DGFASLI Standard Reference Note 2006; DGFASLI
April 2007


Legal Infrastructure on Industrial Safety - Part 2

LEGAL FRAMEWORK

As per the allocation of business rules under the Constitution, labour is in the concurrent list of subjects. It is dealt with by the MOLE at the Central and Departments of Labour under State Governments in respective States / UTs. The MOLE has enacted workplace safety and health statutes concerning workers in the manufacturing sector, mines, ports and docks and in construction sectors. Many software development companies have also adopted the legal framework. Further, other Ministries of the Government of India have also enacted certain statutes relating to safety aspects of substances, equipment, operations etc. Some of the statutes applicable in the manufacturing sector are discussed below :-

The Static and Mobile Pressure Vessels (Unfired) Rules, 1981

These (SMPV) Rules are notified under the Explosives Act, 1884. These rules regulate storage, handling and transport of compressed gases. These rules stipulate requirements regarding construction and fitments, periodic testing, location, fire protection, loading and unloading facilities, transfer operations etc. in respect of pressure vessels whose water capacity exceeds one thousand liters.

The Manufacture, Storage and Import of Hazardous Chemicals Rules (MSIHC), 1989

These MSIHC Rules are notified under the Environment (Protection) Act, 1986. These rules are aimed at regulating and handling of certain specified hazardous chemicals. The rules stipulate requirements regarding notification of site, identification of major hazards, taking necessary steps to control major accident, notification of major accident, preparation of safety report and on-site emergency plan; prevention and control of major accident, dissemination of information etc by the custom software development company in india. These rules are notified by the Ministry of Environment and Forests (MOEF) but enforced by the Inspectorates of Factories of respective States / UTs in the manufacturing sector.

REGULATION OF SAFETY AND HEALTH IN FACTORIES

The Factories Act, 1948 is applicable to the premises where(i) manufacturing process is carried on with the aid of power employing 10 or more persons; (ii) manufacturing process is carried on without the aid of power employing 20 or more persons;(iii) notified under Section 85 of the Factories Act, 1948. The State Governments are empowered to make rules under the enabling provisions as well as general provision. The State Governments are also empowered to appoint inspectors and the Chief Inspector. Thus, the State Inspectorates of Factories enforce the provisions under the Act and Rules. The uniformity in States Rules notified by different States / UTs is sought through framing of Model.


References

1. Constitution of India
2. The Factories Act, 1948
3. The Model Rules under the Factories Act, 1948;
DGFASLI 1998
4. Annual Report 2007-2008; Ministry of Labour &
Employment
5. DGFASLI Standard Reference Note 2006; DGFASLI
April 2007


Legal Infrastructure on Industrial Safety - Part 1

INTRODUCTION

At the global level, industrial safety has been drawing attention of international agencies such as ILO, WHO, UNDP, UNEP, etc. In fact, efforts are being made to consider and recognize occupational safety and health as one of the human rights.


POLICY FRAMEWORK

Constitutional Provisions

The Constitution of India under the Directive Principles of State Policy provides for certain safeguards to workers. The State policies should be directed to ensure that health and strengths of workers are not abused and just and humane conditions of work and maternity relief that are provided. The Constitution prohibits employment of child below 14 years of age for work in any factory, or mine or any hazardous occupation. The constitution also provides for the State to make any special provision for women and children.

ILO Conventions

The International Labour Organization (ILO) is the standard making body in the area of labor and social issues. The ILO was established in the year 1919. Since then, they have formulated 188 Conventions relating to conditions of labor. In addition, they have also formulated several recommendations, codes of practices and guidelines for the benefit of member countries. As one of the founder members, India has so far ratified 41 Conventions.

As a step towards facilitating the ratification, a national policy on occupational safety, health and environment at workplace is already prepared by the Ministry of Labour and Employment (MOLE). The policy is under advanced stage of declaration.

National Policy On Occupational Safety, Health And Environment At Work

The national policy aims at improvement in the safety, health and environment at workplace (especially at Manufacturing sites, Chemical industries, software development companies) through:- (i) statutory framework on OSH in respect of all sectors of economic activities (ii) facilitation of technical support services (iii) providing incentives to employees and employers (iv) establishment and maintaining of R & D capabilities in the area of risk management (v) focusing on prevention strategies; and (vi) competence enhancement of technical manpower.

The policy sets its objective to achieve continuous reduction in work related injuries, diseases and associated costs; and continuous enhancement of awareness regarding safety, health and environment. The policy also outlines an Action Programme for achieving these objectives and goals. It identifies 9 key strategies :-
1. Enforcement
2. Development of national standards
3. Compliance
4. Awareness
5. Research and development
6. Skills development
7. Data collection
8. Practical guidance
9. Incentives

National Policies On Other Subjects

The Government of India have also formulated National Environment Policy, National Policy on Petroleum, Chemicals and Petro-chemical Investment Regions (PCPIR), Policy on Information Technology Investment Regions, National Fertilizer Policy, etc. These policies also contain reference to the occupational safety and health aspects of working population. Apart from these, at the instance of National Human Rights Commission (NHRC), a national programme on ‘Elimination of Silicosis’ is being formulated.

Further, a separate legislation concerning safety, health, social security and welfare of workers employed in unorganized sectors is also being contemplated by software development company in india.


Tripartite Consultations

The MOLE has put in place a tripartite consultative mechanism in the form of Indian Labour Conference (ILC), to discuss the issues relating to labour including occupational safety and health. The ILC is assisted by another tripartite forum, Standing Labour Committee (SLC) which frames the agenda for the ILC. Further, MOLE has also constituted Tripartite Committee on ILO Conventions which addresses the issue of ratification of ILO Conventions. In addition, Tripartite Committees are also constituted as per the enabling provisions under various statutes concerning safety and health.


References

1. Constitution of India
2. The Factories Act, 1948
3. The Model Rules under the Factories Act, 1948;
DGFASLI 1998
4. Annual Report 2007-2008; Ministry of Labour &
Employment
5. DGFASLI Standard Reference Note 2006; DGFASLI
April 2007
6. www.ilo.org
7. www.labour.nic.in
8. www.dgfasli.nic.in

Sunday, 10 April 2016

Types of Software Quality Models

software development companies

1. McCall Model 

McCall’s model was developed by the Rome air development center (RADC), the US air-force electronic system decision (ESD), general electric, in order to improve the quality of software products at software development companies. The model was developed to assess the relationships between external factors and product quality criteria. The quality characteristics were classified in three major types, eleven such factors which describe the external view of the software (user view), 23 quality criteria which describe the internal view of the software (developer view), and the metrics which define and are used to provide a scale and method for measurement. The total number of factors was reduced to eleven in order to simplify it. Those factors are Correctness, Integrity, Reliability, Efficiency, Usability, Flexibility, Maintainability, Reusability, Testability, Portability, and Interoperability. The major contribution of this model is the relationship between the quality characteristics and metrics. But, this model does not consider directly on the functionality of software products.

2. Boehm Model

Boehm added new factors to McCall’s model with emphasis on the maintainability of software product at software development companies. The main aim of this model is to address the contemporary shortcomings of models that automatically and quantitatively evaluate the quality of software. Thus, Boehm model represents the characteristics of the software product hierarchically in order to get contribute in the total quality. Also, the software product evaluation considered with respect to the utility of the program. But, this model contains only a diagram without any suggestion about measuring the quality characteristics.

3. FURPS Model

FURPS model was proposed by and Hewlett-Packard Co and Robert Grady. The attributes were classified into two main categories according to the user’s requirements, the functional and non-functional requirements. Functional requirements (F): Defined by input and expected output. Non-functional requirements (URPS):

Usability, reliability, performance, supportability. Also, this model was extended by IBM Rational Software – into FURPS+. Thus, this model considered only the user’s requirements and disregards the developer consideration. But, this model fails to take into account the software some of the product characteristics, like maintainability and portability.

4. Dromey Model

Dromey (1995) states that the evaluation is different for each product, thus a dynamic idea for process modeling is required. Thus, the main idea of the proposed model was to obtain a model broad enough to work for different systems. Also the model seeks to increase understanding of the relationship between the attributes (characteristics) and the sub-attributes (sub-characteristics) of quality. Also this model defined two layers, the high-level attributes and subordinate attributes. Therefore, this model suffers from lack of criteria for measurement of software quality.

5. ISO IEC 9126 Model

As, many software quality models were proposed, the confusion happened and new standard model was required. Thus, ISO/IEC JTC1 began to develop the required consensus and encourage standardization world-wide. The ISO 9126 is part of the ISO 9000 standard, and it is the most important standard for quality assurance. The first considerations originated in 1978, and in the year 1985 the development of ISO/IEC 9126 was started.

In this model, for software development companiesthe totality of software product quality attributes was classified in a hierarchical tree structure of characteristics and sub characteristics. And the highest level of this structure consists of the quality characteristics and the lowest level consists of the software quality criteria. This model specified six characteristics including Functionality, the Reliability, Usability, Efficiency, Maintainability and the Portability; all of which are further divided into 21 sub characteristics. All these sub characteristics are manifested externally when the software is used as part of a computer system, and thus are the result of internal software attributes. All the defined characteristics are applicable to every kind of software, including computer programs and data contained in firmware and provide consistent terminology for software product quality. And they also provide a framework for making trade-offs between software product capabilities.


Author Signature: Shreyans Agrawal (ifour.shreyans.agrawal@gmail.com)

Users’ perspective in Software Quality - Part 2

software development companies

4. User’s Perspective Quality Factors

Here, different characteristics of software product developed at software development companies are considered and checked; a number of such characteristics are taken into consideration by the end users. In it, the list of the software characteristics, considered by the end users and which affect their emotions are taken into consideration.

4.1 Functionality

The main idea of any software product is to perform specific business functionality. Thus, the performance of the software product is considered as crucial factor in the software quality, which identifies whether the software is really usable or not, by not considering the values of other software quality factors and functions. The critical role of the software presents whether the software product is apt, the result is correct, and whether some standard is followed in order to perform the required functions. The adaptability of the software presents how the system fit the developer’s requirements. Therefore, the suitability evaluates the ability of the software product to produce desired result and appropriate for a specified environment.

Software accuracy is defined as the ability of the software products to achieve its requirements, by bringing accurate output as per requirement of the system core developer. The software accuracy also affects the process continuity, system safety, total cost and maintainability. The compliance represents whether the system has followed any standard or certificates to achieve the user requirements.

4.2 Reliability

The reliability of the software represents the ability to perform the intended function properly without any failures. That is maintaining a level of services under specific condition within specific period of time during systems operation. Thus, the reliability measures the failures occurred in the software product within defined period of time.

Moreover, the reliability considered in the information and the system function safety harms that may be caused by the unauthorized people. Therefore, the reliability of the software product consists of several characteristics: the integrity, the maturity and the fault recovery.

4.3 Performance

Software performance is the most affected software characteristic, which gets affected by everything in the system product, from software characteristics to the system environment such as the operating system, the middleware, the hardware and the communication networks. System performance is a make-or break quality for software, which is an important nonfunctional attribute of software systems for producing quality software, that considers the run time property.

System performance is characterized by the amount of useful work accomplished by a system compared to the time and resources used. The performance factor is thus destined to evaluate whether the software application is running efficiently on the computing resources available or not.
The performance factor represents the degree of the system efficiency to produce desired result during system operation time. This degree is thus represented by combination of software and hardware attributes which influence on the time of answer and the range of the software services coverage.

4.4 Usability

As per the ACM the usability engineering (called human-computer interaction engineering) is defined as “a discipline concerned with the design, evaluation and implementation of interactive computing systems for human use and the study of major phenomena surrounding them”.
As per the software life cycle phases, usability characteristics were classified into three main categories: Interface characteristics, training, and operation supportability.

4.5 Transferability/Portability



Software transferability expresses the ability of the software to work properly in different type of platforms. It deals with the effort required to transfer a program from one hardware configuration and/or software system environment to another with slight modification. Thus this characteristic refers to how the software can be adopted to change its environment or with its requirements in software development companies.


Author: Shreyans Agrawal (ifour.shreyans.agrawal@gmail.com)

Friday, 8 April 2016

Users’ perspective in Software Quality - Part 1

software application development companies in India

1. Introduction

In the last decade, the cost of software products has reduced, which leads to growth in the software application development companies in India and software products are being used by individuals in addition to the corporations. Thus, research in software engineering increasingly grows and focuses on software quality evaluation and growth, yet most of all these research focuses on the internal/ development perspective.

Since the market of software development companies interest is on the user’s satisfaction with more attention to the perspective of users in software quality is needed, the software users from different education background and culture are considered in developing software products and services. Therefore, by not considering these factors, the software will be less used, which means the software product failed in the market.

According to ISO9126, the main consideration of the users is the software usability, its effects and its performance without knowing what is inside it, how it works, or how was it developed. 
Since, the software users do not care about all of software characteristics that are required to identify the quality of the software product, but it seems to be not accurate to show them the quality that they are searching for. Thus, the quality of the software as users need is very important in the market.

2. Software Quality Models

Since 1978, when McCall proposed first software quality model and also several other models were proposed to check the characteristics of the software products. These models combined the different point of views of the Manager, the Developer, and the user. Thus, there is no clear image of the software quality shows to the users. For e.g., if such a software product has a high maintainability and low usability might be equal to software has a high usability low maintainability.

3. User’s Emotion Quality Models

On the other side, the effect of the software products on the user were considered and several emotions models were proposed. The aim of these models is to evaluate the software product from what the users feels when they use it. It either proposed a B2C model that calculates the emotions of the end users instead of software characteristics. The cognitive emotions were adopted in this model. 



Author: Shreyans Agrawal (ifour.shreyans.agrawal@gmail.com)