Planning and Monitoring Risks in Software Engineering – P&M SE Risks

Abstract


One of the main challenges in agile software development is ensuring that planning and monitoring risks and opportunities is simple and effective. It’s essential to adopt a method integrated with a planning and monitoring tool that’s easy to use and learn, flexible, and provides important information without overloading activities. This article reports on experiences with a simple, agile approach, compatible with CMMI, MPS, ISO 12207, ISO 27000, and ISO 31000 models and standards, used by five organizations at different times to meet maturity assessment, certification, and process improvement needs.

Keywords: Risk Management, Risk Monitoring, Software Engineering

References

ISO/IEC (2017). ISO/IEC/IEEE 12207:2017 Systems and software engineering — Software life cycle processes, Geneve: ISO, 2017.

[Simões and Silva 2024] Simões, C., & Silva, T. S. da C. (2024). Agile Planning and Monitoring with Kanban and Measurement. IFPUG Metric Views, June 2024. Available at: [link].

ABNT NBR ISO 31000:2018 Gestão de riscos ― Diretrizes. Risk management ― Guidelines. ICS ISBN 978-85-07-07470-0. Segunda edição 28.03.2018

CMMI Institute. CMMI Model V3.0. Available at: [link]. Accessed on: March 3, 2025.

Software Process Improvement Group (Softex). Guia Geral MPS de Software: 2024. Available at: [link]. Accessed on: March 3, 2025.

Simões, C. (2024). A Difícil Arte de Planejar e Monitorar Custo, Desempenho e Qualidade Quando da Adoção de Métodos Ágeis. Workshop Anual do MPS – WAMPS 2024.

Simões, C. (2023). Modelo de Referência de Processo para Terceirização de Força de Trabalho de TI. Tese de Doutorado, Universidade Federal do Estado do Rio de Janeiro, Programa de Pós-Graduação em Informática.

Simões, C., & Montoni, M. (2014). Applying Statistical Process Control in SmallSized Evolutionary Projects: Results and Lessons Learned in the Implementation of CMMI-DEV Maturity Level 5 in Synapsis Brazil. Journal of Software Engineering Research and Development, 2:2. Available at: [link].

ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Third edition 2022-1
Published
2025-11-03
SIMÕES, Carlos. Planning and Monitoring Risks in Software Engineering – P&M SE Risks. In: MPS ANNUAL WORKSHOP, 21. , 2025, São José dos Campos/SP. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2025 . p. 11-15.