The Experts below are selected from a list of 14358 Experts worldwide ranked by ideXlab platform

Sunil Wattal - One of the best experts on this subject based on the ideXlab platform.

  • Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation
    2018
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security Software as it is about secure Software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement about a Software defect is termed as ‘vulnerability disclosure’. Although research in Software economics have studied firms’ incentive to improve overall quality, there have been no studies to show that Software Vendors have an incentive to invest in building more secure Software. In this paper, we use the event study methodology to examine the role that financial markets play in determining Software Vendors’ incentives to build more secure Software. We collect data from leading national newspapers and industry sources like CERT by searching for reports on published Software vulnerabilities. We show that vulnerability disclosures lead to a negative and significant change in market value for a Software Vendor. On average, a Vendor loses around 0.6% value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Moreover, vulnerabilities which cause a confidentiality related breach cause a greater decline in the market value for a Vendor than the vulnerabilities which cause non-confidentiality related breaches. Also, more severe flaws have a significantly greater impact than flaws with low or moderate severity. Finally, we find that the markets do not punish a Software Vendor more severely if a third party discovers a flaw in its product than if the Vendor itself discovers the flaw. Our analysis provides many interesting implications for Software Vendors as well as policy makers

  • An Empirical Analysis of the Impact of Software Vulnerability Announcements on Firm Stock Price
    IEEE Transactions on Software Engineering, 2007
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Security defects in Software cost millions of dollars to firms in terms of downtime, disruptions, and confidentiality breaches. However, the economic implications of these defects for Software Vendors are not well understood. Lack of legal liability and the presence of switching costs and network externalities may protect Software Vendors from incurring significant costs in the event of a vulnerability announcement, unlike such industries as auto and pharmaceuticals, which have been known to suffer significant loss in market value in the event of a defect announcement. Although research in Software economics has studied firms' incentives to improve overall quality, there have not been any studies which show that Software Vendors have an incentive to invest in building more secure Software. The objectives of this paper are twofold. 1) We examine how a Software Vendor's market value changes when a vulnerability is announced. 2) We examine how firm and vulnerability characteristics mediate the change in the market value of a Vendor. We collect data from leading national newspapers and industry sources, such as the Computer Emergency Response Team (CERT), by searching for reports on published Software vulnerabilities. We show that vulnerability announcements lead to a negative and significant change in a Software Vendor's market value. In our sample, on average, a Vendor loses around 0.6 percent value in stock price when a vulnerability is reported. We find that a Software Vendor loses more market share if the market is competitive or if the Vendor is small. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Also, more severe flaws have a significantly greater impact. Our analysis provides many interesting implications for Software Vendors as well as policy makers.

  • impact of Software vulnerability announcements on the market value of Software Vendors an empirical investigation
    WEIS, 2005
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security Software as it is about secure Software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement makes about a Software defect is termed as 'vulnerability disclosure'. Although research in Software economics have studied firms' incentive to improve overall quality, there have been no studies to show that Software Vendors have an incentive to invest in building more secure Software. In this paper, we use the event study methodology to examine Software Vendors' incentives to build more secure Software. We collect data from leading national newspapers and industry sources like CERT by searching for reports on published Software vulnerabilities. We show that vulnerability disclosures lead to a negative and significant change in market value for a Software Vendor. On average, a Vendor loses around 0.6% value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Moreover, vulnerabilities which cause a confidentiality related breach cause a greater decline in the market value for a Vendor than the vulnerabilities which cause non-confidentiality related breaches. Also, more severe flaws have a significantly greater impact than flaws with low or moderate severity. Finally, we find that the markets do not punish a Software Vendor more severely if a third party discovers a flaw in its product than if the Vendor itself discovers the flaw. Our analysis provides many interesting implications for Software Vendors as well as policy makers.

  • do security vulnerability announcemnets impact Software Vendors an event study analysis
    Americas Conference on Information Systems, 2005
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    In this paper, we use the event study methodology to examine the role that financial markets play in determining the impact of vulnerability disclosures on Software Vendors. We collect data from leading national newspapers and industry sources by searching for reports on published Software vulnerabilities. Our main result is that vulnerability disclosures do lead to a negative and significant change in market value for a Software Vendor. On average, a Vendor loses around 0.6% value in stock price when a vulnerability is reported. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. This is the first study to measure Vendors’ incentive to develop secure Software and also provides many interesting implications for Software Vendors as well as policy makers.

  • impact of Software vulnerability announcements on the market value of Software Vendors an empirical investigation
    WEIS, 2005
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security Software as it is about secure Software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement about a Software defect is termed as ‘vulnerability disclosure’. Although research in Software economics have studied firms’ incentive to improve overall quality, there have been no studies to show that Software Vendors have an incentive to invest in building more secure Software. In this paper, we use the event study methodology to examine the role that financial markets play in determining Software Vendors’ incentives to build more secure Software. We collect data from leading national newspapers and industry sources like CERT by searching for reports on published Software vulnerabilities. We show that vulnerability disclosures lead to a negative and significant change in market value for a Software Vendor. On average, a Vendor loses around 0.6% value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Moreover, vulnerabilities which cause a confidentiality related breach cause a greater decline in the market value for a Vendor than the vulnerabilities which cause non-confidentiality related breaches. Also, more severe flaws have a significantly greater impact than flaws with low or moderate severity. Finally, we find that the markets do not punish a Software Vendor more severely if a third party discovers a flaw in its product than if the Vendor itself discovers the flaw. Our analysis provides many interesting implications for Software Vendors as well as policy makers. Keyword: information security, Software vulnerability, quality, event study, disclosure policy

Rahul Telang - One of the best experts on this subject based on the ideXlab platform.

  • Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation
    2018
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security Software as it is about secure Software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement about a Software defect is termed as ‘vulnerability disclosure’. Although research in Software economics have studied firms’ incentive to improve overall quality, there have been no studies to show that Software Vendors have an incentive to invest in building more secure Software. In this paper, we use the event study methodology to examine the role that financial markets play in determining Software Vendors’ incentives to build more secure Software. We collect data from leading national newspapers and industry sources like CERT by searching for reports on published Software vulnerabilities. We show that vulnerability disclosures lead to a negative and significant change in market value for a Software Vendor. On average, a Vendor loses around 0.6% value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Moreover, vulnerabilities which cause a confidentiality related breach cause a greater decline in the market value for a Vendor than the vulnerabilities which cause non-confidentiality related breaches. Also, more severe flaws have a significantly greater impact than flaws with low or moderate severity. Finally, we find that the markets do not punish a Software Vendor more severely if a third party discovers a flaw in its product than if the Vendor itself discovers the flaw. Our analysis provides many interesting implications for Software Vendors as well as policy makers

  • An Empirical Analysis of the Impact of Software Vulnerability Announcements on Firm Stock Price
    IEEE Transactions on Software Engineering, 2007
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Security defects in Software cost millions of dollars to firms in terms of downtime, disruptions, and confidentiality breaches. However, the economic implications of these defects for Software Vendors are not well understood. Lack of legal liability and the presence of switching costs and network externalities may protect Software Vendors from incurring significant costs in the event of a vulnerability announcement, unlike such industries as auto and pharmaceuticals, which have been known to suffer significant loss in market value in the event of a defect announcement. Although research in Software economics has studied firms' incentives to improve overall quality, there have not been any studies which show that Software Vendors have an incentive to invest in building more secure Software. The objectives of this paper are twofold. 1) We examine how a Software Vendor's market value changes when a vulnerability is announced. 2) We examine how firm and vulnerability characteristics mediate the change in the market value of a Vendor. We collect data from leading national newspapers and industry sources, such as the Computer Emergency Response Team (CERT), by searching for reports on published Software vulnerabilities. We show that vulnerability announcements lead to a negative and significant change in a Software Vendor's market value. In our sample, on average, a Vendor loses around 0.6 percent value in stock price when a vulnerability is reported. We find that a Software Vendor loses more market share if the market is competitive or if the Vendor is small. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Also, more severe flaws have a significantly greater impact. Our analysis provides many interesting implications for Software Vendors as well as policy makers.

  • an empirical analysis of Vendor response to Software vulnerability disclosure
    2005
    Co-Authors: Ashish Arora, Ramayya Krishnan, Rahul Telang, Yubao Yang
    Abstract:

    Software vulnerability disclosure refers to the publication of vulnerability information before a patch to address the vulnerability has been issued by the Software Vendor. It has generated intense interest and debate. In particular, there have been arguments made both in opposition to and in favor of alternatives such as full and instant disclosure and limited or no disclosure. An important consideration in this debate is the behavior of the Software Vendor. Does vulnerability disclosure policy have an effect on patch release behavior of Software Vendors? This paper compiles a unique data set from CERT/CC and SecurityFocus to answer this question. Our results suggest that disclosure policy has a significant positive impact on the Vendor patching speed. Vendors are 137% more likely to patch due to disclosure. In particular, instant disclosure hastens the patch delivery by almost 29 days. Open source Vendors patch more quickly than closed source Vendors and severe vulnerabilities are patched faster. We also find that Vendors respond more slowly to vulnerabilities not handled by CERT/CC. This might reflect unmeasured differences in the severity and importance of vulnerabilities. It might also reflect the stronger lines of communication between CERT/CC and Vendors, and the value of the vulnerability analysis by CERT/CC.

  • impact of Software vulnerability announcements on the market value of Software Vendors an empirical investigation
    WEIS, 2005
    Co-Authors: Rahul Telang, Sunil Wattal
    Abstract:

    Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches. However, information security is as much about security Software as it is about secure Software. Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement makes about a Software defect is termed as 'vulnerability disclosure'. Although research in Software economics have studied firms' incentive to improve overall quality, there have been no studies to show that Software Vendors have an incentive to invest in building more secure Software. In this paper, we use the event study methodology to examine Software Vendors' incentives to build more secure Software. We collect data from leading national newspapers and industry sources like CERT by searching for reports on published Software vulnerabilities. We show that vulnerability disclosures lead to a negative and significant change in market value for a Software Vendor. On average, a Vendor loses around 0.6% value in stock price when a vulnerability is reported. This is equivalent to a loss in market capitalization values of $0.86 billion per vulnerability announcement. To provide further insight, we use the information content of the disclosure announcement to classify vulnerabilities into various types. We find that the change in stock price is more negative if the Vendor fails to provide a patch at the time of disclosure. Moreover, vulnerabilities which cause a confidentiality related breach cause a greater decline in the market value for a Vendor than the vulnerabilities which cause non-confidentiality related breaches. Also, more severe flaws have a significantly greater impact than flaws with low or moderate severity. Finally, we find that the markets do not punish a Software Vendor more severely if a third party discovers a flaw in its product than if the Vendor itself discovers the flaw. Our analysis provides many interesting implications for Software Vendors as well as policy makers.

  • an empirical analysis of Vendor response to disclosure policy
    WEIS, 2005
    Co-Authors: Ashish Arora, Ramayya Krishnan, Rahul Telang, Yubao Yang
    Abstract:

    Software vulnerability disclosure has generated intense interest and debate. In particular, there have been arguments made both in opposition to and in favor of alternatives such as full and instant disclosure and limited or no disclosure. An important consideration in this debate is the behavior of the Software Vendor. Does vulnerability disclosure policy have an effect on patch release behavior of Software Vendors? This paper compiles a unique data set from CERT/CC and Security Focus databases to answer this question. Our results suggest that early disclosure has significant positive impact on the Vendor patching speed. Open source Vendors patch more quickly than closed source Vendors and severe vulnerabilities are patched faster. We also find that Vendors respond slower to vulnerabilities not disclosed by CERT/CC. This might reflect unmeasured differences in the severity and importance of vulnerabilities. It might also reflect the stronger lines of communication between CERT/CC and Vendors, and the value of the vulnerability analysis by CERT/CC. We also find that Vendors are more responsible after the 9/11 event.

Sjaak Brinkkemper - One of the best experts on this subject based on the ideXlab platform.

  • a sense of community a research agenda for Software ecosystems
    International Conference on Software Engineering, 2009
    Co-Authors: Slinger Jansen, A Finkelstein, Sjaak Brinkkemper
    Abstract:

    Software Vendors lack the perspective to develop Software within a Software ecosystem. The inability to function in a Software ecosystem has already led to the demise of many Software Vendors, leading to loss of competition, intellectual property, and eventually jobs in the Software industry. In this paper we present a research agenda on Software ecosystems to study both the technical and the business aspects of Software engineering in vibrant ecosystems. The results of such research enable Software Vendors to develop Software that is adaptable to new business models and new markets, and to make strategic choices that help a Software Vendor to thrive in a Software ecosystem.

  • ten misconceptions about product Software release management explained using update cost value functions
    2006 International Workshop on Software Product Management (IWSPM'06 - RE'06 Workshop), 2006
    Co-Authors: Slinger Jansen, Sjaak Brinkkemper
    Abstract:

    The decision for a young product Software Vendor to release a version of their product is dependent on different factors, such as development decisions (it feels right), sales decisions (the market needs it), and quality decisions (the product is stable). Customers of these products, however, are much more cost oriented when deciding whether to update their product or not, and will look mainly at the cost and value of an update. Product Software Vendors would gain tremendously if their release package planning method was supported by a similar cost/value overview. This paper presents cost/value functions for product Software Vendors to support their release package planning method. These cost/value functions are supported by ten misconceptions encountered in seven case studies of product Software Vendors that these Vendors had to adjust during their lifetime. Finally, a number of cost saving opportunities are presented to enable quicker adoption of a release and thus shorten release times and customer feedback cycles.

  • evaluating the release delivery and deployment processes of eight large product Software Vendors applying the customer configuration update model
    Proceedings of the 2006 international workshop on Workshop on interdisciplinary software engineering research, 2006
    Co-Authors: Slinger Jansen, Sjaak Brinkkemper
    Abstract:

    For Software Vendors the processes of release, delivery, and deployment to customers are inherently complex. However, Software Vendors can greatly improve their product quality and quality of service by applying a model that focuses on customer interaction if such a model were available. This paper presents a model for customer configuration updating (CCU) that can evaluate the capabilities of a Software Vendor in these processes. Eight extensive case studies of medium to large product Software Vendors are presented and evaluated using the model, thereby uncovering issues in their release, delivery, and deployment processes.

  • Definition and Validation of the Key process of Release, Delivery and Deployment for Product Software Vendors: turning the ugly duckling into a swan
    2006 22nd IEEE International Conference on Software Maintenance, 2006
    Co-Authors: Slinger Jansen, Sjaak Brinkkemper
    Abstract:

    For Software Vendors the processes of release, delivery, and deployment to customers are inherently complex. However, Software Vendors can greatly improve their product quality and quality of service by applying a model that focuses on customer interaction if such a model were available. This paper presents a model for customer configuration updating (CCU) that can evaluate the practices of a Software Vendor in these processes. Nine extensive case studies of medium to large product Software Vendors are presented and evaluated using the model, thereby uncovering issues in their release, delivery, and deployment processes. Finally, organisational and architectural changes are proposed to increase quality of service and product quality for Software Vendors

  • On the Creation of a Reference Framework for Software Product Management: Validation and Tool Support
    2006 International Workshop on Software Product Management (IWSPM'06 - RE'06 Workshop), 2006
    Co-Authors: Inge Van De Weerd, Richard Nieuwenhuis, Johan Versendaal, Sjaak Brinkkemper, Lex Bijlsma
    Abstract:

    Software product management does not get as much attention in scientific research as it should have, compared to the high value product Software companies ascribe to it. In this paper, we give a status overview of the current Software product management domain by performing a literature study and field studies with product managers. Based on these, we are able to present a reference framework for Software product management, in which the key process areas, stakeholders and their relations are modeled. To validate the reference framework, we perform a case study in which we analyze the stakeholder communication concerning the conception, development and launching of a new product at a major Software Vendor. Finally, we propose the Software Product Management Workbench for operational support for product managers in product Software companies.

Tunay I. Tunca - One of the best experts on this subject based on the ideXlab platform.

  • who should be responsible for Software security a comparative analysis of liability policies in network environments
    Management Science, 2011
    Co-Authors: Terrence August, Tunay I. Tunca
    Abstract:

    In recent years, Vendor liability for Software security vulnerabilities has been the center of an important debate in the Software community and a topic gaining government attention in legislative committees and hearings. The importance of this question surrounding Vendor security liability is amplified when one considers the increasing emergence of zero-day attacks where hackers take advantage of vulnerabilities before the Software Vendor has a chance to release protective patches. In this paper, we compare the effectiveness of three Software liability policies: Vendor liability for damages, Vendor liability for patching costs, and government imposed security standards. We find that Vendor liability for losses is not effective in improving social welfare in the short run, while liability for patching costs can be effective if either patching costs are large and the likelihood of a zero-day attack is low, or patching costs are small and zero-day likelihood is high. In the long run, when the Vendor can invest in reducing the likelihood of security vulnerabilities, loss liability is still ineffective when the zero-day attack probability is high but can increase both Vendor investment in security and social welfare when zero-day attack likelihood is sufficiently low. When the zero-day attack probability is high, patch liability is ineffective if user patching costs are large, but partial patch liability can boost Vendor investment and improve welfare when patching costs are small. In contrast, in an environment with low zero-day attack probability, full Vendor patch liability can be optimal. Finally, comparing the effectiveness of the three liability policies under study, we find that government imposed standards on Software security investment can be preferable to both patching and loss liability on the Vendor, if zero-day attack likelihood is sufficiently low. However, if zero-day attacks are a common occurrence and patching costs are not too high, partial patch liability is the most effective policy. This paper was accepted by Sandra Slaughter, information systems.

  • who should be responsible for Software security a comparative analysis of liability policies in network environments
    2010
    Co-Authors: Terrence August, Tunay I. Tunca
    Abstract:

    In recent years, Vendor liability for Software security vulnerabilities has been the center of an important debate in the Software community and a topic gaining government attention in legislative committees and hearings. The importance of this question surrounding Vendor security liability is amplified when one considers the increasing emergence of "zero-day" attacks where hackers take advantage of vulnerabilities before the Software Vendor has a chance to release protective patches. In this paper, we compare the effectiveness of three Software liability policies: Vendor liability for damages, Vendor liability for patching costs, and government imposed security standards. We find that Vendor liability for losses is not effective in improving social welfare in the short-run, while liability for patching costs can be effective if either patching costs are large and the likelihood of a zero-day attack is low, or patching costs are small and zero-day likelihood is high. In the long run, when the Vendor can invest in reducing the likelihood of security vulnerabilities, loss liability is still ineffective when the zero-day attack probability is high but canincrease both Vendor investment in security and social welfare when zero-day attack likelihood is sufficiently low. When the zero-day attack probability is high, patch liability is ineffective if user patching costs are large, but partial patch liability can boost Vendorinvestment and improve welfare when patching costs are small. In contrast, in an environment with low zero-day attack probability, full Vendor patch liability can be optimal. Finally, comparing the effectiveness of the three liability policies under study, we find that government imposed standards on Software security investment can be preferable to both patching and loss liability on the Vendor, if zero-day attack likelihood is sufficiently low. However, if zero-day attacks are a common occurrence and patching costs are not too high, partial patch liability is the most effective policy.

  • Let the Pirates Patch? An Economic Analysis of Software Security Patch Restrictions
    Information Systems Research, 2008
    Co-Authors: Terrence August, Tunay I. Tunca
    Abstract:

    We study the question of whether a Software Vendor should allow users of unlicensed (pirated) copies of a Software product to apply security patches. We present a joint model of network Software security and Software piracy and contrast two policies that a Software Vendor can enforce: (i) restriction of security patches only to legitimate users or (ii) provision of access to security patches to all users whether their copies are licensed or not. We find that when the Software security risk is high and the piracy enforcement level is low, or when tendency for piracy in the consumer population is high, it is optimal for the Vendor to restrict unlicensed users from applying security patches. When piracy tendency in the consumer population is low, applying Software security patch restrictions is optimal for the Vendor only when the piracy enforcement level is high. If patching costs are sufficiently low, however, an unrestricted patch release policy maximizes Vendor profits. We also show that the Vendor can use security patch restrictions as a substitute to investment in Software security, and this effect can significantly reduce welfare. Furthermore, in certain cases, increased piracy enforcement levels can actually hurt Vendor profits. We also show that governments can increase social surplus and intellectual property protection simultaneously by increasing piracy enforcement and utilizing the strategic interaction of piracy patch restrictions and network security. Finally, we demonstrate that, although unrestricted patching can maximize welfare when the piracy enforcement level is low, contrary to what one might expect, when the piracy enforcement level is high, restricting security patches only to licensed users can be socially optimal.

Arne Beckhaus - One of the best experts on this subject based on the ideXlab platform.

  • the impact of collaboration network structure on issue tracking s process efficiency at a large business Software Vendor
    Hawaii International Conference on System Sciences, 2010
    Co-Authors: Arne Beckhaus, Lars M Karg, Dirk Neumann
    Abstract:

    Researchers in the IS domain have addressed communication structure and its effect on performance. While early research focused on small networks and utilized sociometric surveys, recent works have concentrated on electronic data sources provided by open source Software repositories. Surprisingly, Software Vendors have less frequently been studied despite their need for continuous enhancement of organizational design. In this study, we analyze a global business Software Vendor by utilizing existing data sources. We investigate the association of both collaboration network centrality and communication with process efficiency. Despite coping with complex, interweaved processes and social networks, we find that communication, centrality in the large case-study-wide network, and communication pattern homogeneity are positively associated with process efficiency. However, centrality in small work groups slows the analyzed issue tracking process down, possibly due to increased overhead and bottleneck effects that become visible when looking at single issues qualitatively.

  • applicability of Software reliability growth modeling in the quality assurance phase of a large business Software Vendor
    Computer Software and Applications Conference, 2009
    Co-Authors: Arne Beckhaus, Lars M Karg, Gerrit Hanselmann
    Abstract:

    Software reliability growth modeling aims to use data on experienced failures for prediction of future quality levels. We analyze the applicability of this approach in the context of business Software that is still in the quality assurance phase and has not been released to the customer yet. We find that the approach is not applicable in our research setup that is characterized by an agile process organization. We identify qualitative reasons why the models' assumptions are violated in our industrial case study and conduct a quantitative analysis whether data availability challenges can be addressed by mapping issue tracking data as the only available data source to the required system under test execution time. The derived metrics support managers in their decision whether their processes are suited for Software reliability growth modeling.

  • the impact of communication structure on issue tracking efficiency at a large business Software Vendor
    2009
    Co-Authors: Arne Beckhaus, Dirk Neumann
    Abstract:

    Software development’s organizational design is often characterized by geographical dispersion and virtual team work. In this setup, communication is an essential task. We study this task by analyzing the association between communication structure and efficiency of the issue tracking process. This key process within Software development is primarily carried out digitally and thus provides a suitable data set for analysis. We find that communication structure is associated with issue tracking efficiency in a case study at a large business Software Vendor.