DUDLEYKNOX LIBRARY MONTEREY CA 93943-6101 NAVAL POSTGRADUATE SCHOOL Monterey, California DISSERTATION A FORMAL MODEL FOR RISK ASSESSMENT IN SOFTWARE PROJECTS by Juan Carlos Nogueira de Leon September 2000 Dissertation Advisor: Luqi Approved for public release; distribution is unlimited. REPORT DOCUMENTATION PAGE FormApproved OMBNo. 0704-0188 Publicreportingburdenforthiscollectionofinformationisestimatedtoaverage 1 hourperresponse,includingthetimeforreviewinginstruction, searchingexistingdatasources,gatheringandmaintainingthedataneeded,andcompletingandreviewingthecollectionofinformation.Send commentsregardingthisburdenestimateoranyotheraspectofthiscollectionofinformation,includingsuggestionsforreducingthisburden,to WashingtonheadquartersServices,DirectorateforInformationOperationsandReports, 1215JeffersonDavisHighway,Suite 1204,Arlington,VA 22202-4302,andtotheOfficeofManagementandBudget,PaperworkReductionProject(0704-0188)WashingtonDC20503. 1. AGENCYUSEONLY 2. REPORTDATE 3. REPORTTYPEANDDATESCOVERED September2000 Ph.D. Dissertation 4. TITLEANDSUBTITLE : AForma]ModelforRiskAssessmentinSoftwareProjects 5. FUNDINGNUMBERS ARO-38690-MA 6. AUTHOR(S) Nogueira,JuanC. ARO-40473-MA DARPA-99-F759 PERFORMING 7. PERFORMINGORGANIZATIONNAME(S)ANDADDRESS(ES) 8O.RGANIZATION REPORT Naval Postgraduate School NUMBER Monterey, CA 93943-5000 9. SPONSORING/MONITORINGAGENCYNAME(S)ANDADDRESS(ES) 10.SPONSORING/ MONITORING N/A AGENCYREPORT NUMBER SUPPLEMENTARYNOTES 11. TheviewsexpressedinthisdissertationarethoseoftheauthoranddonotreflecttheofficialpolicyorpositionoftheDepartmentofDefenseorthe U.S.Government. 12a. DISTRIBUTION/AVAILABILITYSTATEMENT 12b.DISTRIBUTIONCODE Approved forpublic release; distribution is unlimited. ABSTRACT 13. The current state of the art techniques of risk assessment rely on checklists and human expertise. This constitutes a weak approach because different people could arrive at different conclusions from the same scenario. The difficulty of estimating the duration of projects applying evolutionarysoftwareprocessesaddsintricacytotheriskassessmentproblem.Thisdissertationintroducesaformal methodtoassesstheriskand the duration ofsoftware projects automatically, based on measurements thatcanbeobtainedearly in the developmentprocess. The method has been designedaccordingtothecharacteristicsofevolutionarysoftwareprocesses, suchasefficiency, requirement volatilityandcomplexity. The formal modelbasedonthesethreeindicatorsestimatesthedurationandriskofevolutionarysoftwareprocesses.Theapproach introduces benefits intwofields:a)automationofriskassessmentand,b)earlyestimationmethodsforevolutionarysoftwareprocesses. 14. SUBJECTTERMS NUMBER 15. RiskAssessment,FormalModels,SoftwareEstimationModels,SoftwareMetrics,ProjectManagement. OFPAGES 270 16. PRICE CODE 17. SECURITY O18F. TSHEICSUPRIATGYECLASSIFICATION 19. SECURITY 2L0I.MITATION CLASSIFICATIONOFREPORT CLASSIFICATIONOF OFABSTRACT Unclassified Unclassified ABSTRACT UL Unclassified NSN7540-01-280-5500 StandardForm298(Rev.2-89) PrescribedbyANSIStd.239-18 11 Approved for public release; distribution is unlimited A FORMAL MODEL FOR RISK ASSESSMENT IN SOFTWARE PROJECTS Juan Carlos Nogueira de Leon Captain, Navy ofUruguay B.S., Universidad de la Republica, 1985 M.S., Universidad O.R.T., 1993 Submitted in partial fulfillment ofthe requirements for the degree of DOCTOR IN PHILOSOPHY IN SOFTWARE ENGINEERING from the NAVAL POSTGRADUATE SCHOOL September 2000

