Files
wms-app/sdlc/ISO29110-audit-prep.md
T

38 lines
3.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# BRN WMS (200-WMS-26-001-00) — ISO/IEC 29110 audit preparation
## 1. Questions auditors usually ask
### Project Management (PM)
| Usual question | Where to point |
|---|---|
| What was agreed with the customer: scope, deliverables, acceptance criteria? | Statement of Work, Software Project Plan §3 |
| How did you plan: tasks, people, effort, schedule? | Work Schedule, Software Project Plan §5–8 |
| How did you track progress, and what did you do when something slipped? | Progress Status Records (15 periods), Minutes of Meeting |
| What risks did you identify, and were they reviewed? | Software Project Plan §9 (R1–R8); expect "show me a risk that changed during the project" |
| How were changes requested, assessed and approved? | Change Report |
| How were defects recorded and closed? | Correction Register ISS-001–028, each linked to a commit and a test case |
| How is the repository controlled and backed up? | Project Repository, Project Repository (Backup), Software Configuration (`main`, baseline `6c39700`) |
| Did the customer formally accept the product? | Acceptance Report, Validation Results |
### Software Implementation (SI)
| Usual question | Where to point |
|---|---|
| Were requirements reviewed and baselined before development? | Customer Requirements (CR01–CR14), SRS (SR01–SR09), requirements baseline 18 Feb 2569 |
| Pick one requirement and show its design, code, test and result | Traceability Record — most common test; rehearse 2–3 requirements end to end |
| Show the design and how it maps to the code | Software Design (units UN01–UN13 with file paths) |
| Who reviewed which documents, what was found, and how was it fixed? | Verification Results V0.1–V1.0 (4 rounds) |
| Show the test cases and test results, including a failure and its retest | Test Case and Test Procedures (45), Test Report, Correction Register |
| What exactly was delivered, and can you rebuild it? | Software, Software Components, Product Operation Guide |
| Are user, operation and maintenance documents available? | Software User Document, Product Operation Guide, Maintenance Document |
### Weak points likely to be probed
| Point | What to show | What to say |
|---|---|---|
| No change requests in 8 months | Change Report parts 1–3; Minutes of Meeting 23 May (Rack → Bin), 3 Aug and 14 Aug (Task 4.7) | "Change control was used: 3 items were judged against the criteria and none qualified." Rehearse the advisor's test: "if we removed it, could we still deliver?" |
| All 45 test cases passed in one run | Correction Register: 28 issues found and fixed during development, each linked to a commit and a test case; Test Case and Test Procedures pass rule: defects logged and retested until they pass | "The formal run came after the defects were fixed, so a clean run is the result of that work." If git history has real failing test runs, have one ready |
| Risks never re-rated | Software Project Plan R1–R8; risk table in every Progress Status Record | Pick 1–2 risks that actually occurred (R1 → Rack/Bin decision; R7 → evidence prepared before UAT) and show where they were handled. Do not change ratings in the records now |
| Interviews must match the documents | One rehearsal session with the three people | Developer: how a defect is logged (ISS-002 → commit `92d116f` → TC-UN08.002). QA: run TC-UN08.002 (rollback test). PM: trace CR13:001 → SR09:003 → UN08.002 → TC-UN08.002 → Passed in Test Report and Validation Results |