Software review
A software review is "a process or meeting during which a software product is examined by a project personnel, managers, users, customers, user representatives, or other interested parties for comment or approval".
In this context, the term "software product" means "any technical document or partial document, produced as a deliverable of a software development activity", and may include documents such as contracts, project plans and budgets, requirements documents, specifications, designs, source code, user documentation, support and maintenance documentation, test plans, test specifications, standards, and any other type of specialist work product.
Varieties of software review
Software reviews may be divided into three categories:- Software peer reviews are conducted by one or more colleagues of the author, to evaluate the technical content and/or quality of the work.
- Software management reviews are conducted by management representatives to evaluate the status of work done and to make decisions regarding downstream activities.
- Software audit reviews are conducted by personnel external to the software project, to evaluate compliance with specifications, standards, contractual agreements, or other criteria.
Different types of peer reviews
- Code review is systematic examination of computer source code.
- Pair programming is a type of code review where two persons develop code together at the same workstation.
- Inspection is a very formal type of peer review where the reviewers are following a well-defined process to find defects.
- Walkthrough is a form of peer review where the author leads members of the development team and other interested parties go through a software product and the participants ask questions and make comments about defects.
- Technical review is a form of peer review in which a team of qualified personnel examines the suitability of the software product for its intended use and identifies discrepancies from specifications and standards.
Formal versus informal reviews
Research studies tend to support the conclusion that formal reviews greatly outperform informal reviews in cost-effectiveness. Informal reviews may often be unnecessarily expensive and frequently provide a sense of security which is quite unjustified by the relatively small number of real defects found and repaired.
IEEE 1028 generic process for formal reviews
IEEE 1028 defines a common set of activities for "formal" reviews. This standard applies distinctions between management review, technical review, inspection, walk-through, audit, etc.The stipulated sequence of standard activities is largely based on the software inspection process originally developed at IBM by Michael Fagan. Differing types of review may apply this structure with varying degrees of rigour, but all activities are mandatory for inspection:
- 0. : The review leader uses a standard checklist of entry criteria to ensure that optimum conditions exist for a successful review.
- 1. Management preparation: Responsible management ensure that the review will be appropriately resourced with staff, time, materials and tools, and will be conducted according to policies, standards or other relevant criteria.
- 2. Planning the review: The review leader identifies or confirms the objectives of the review, organises a team of reviewers and ensures that the team is equipped with all necessary resources for conducting the review.
- 3. Overview of review procedures: The review leader, or some other qualified person, ensures that all reviewers understand the review goals, the review procedures, the materials available to them and the procedures for conducting the review.
- 4. Preparation: The reviewers individually prepare for group examination of the work under review, by examining it carefully for "anomalies", the nature of which will vary with the type of review and its goals.
- 5. Examination: The reviewers meet at a planned time to pool the results of their preparation activity and arrive at a consensus regarding the status of the document being reviewed.
- 6. Rework/follow-up: The author of the work product undertakes whatever actions are necessary to repair defects or otherwise satisfy the requirements agreed to at the examination meeting. The review leader verifies that all action items are closed.
- 7. : The review leader verifies that all activities necessary for successful review have been accomplished and that all outputs appropriate to the type of review have been finalized.
Value of reviews
A second, but ultimately more important, value of software reviews is that they can be used to train technical authors in the development of extremely low-defect documents, and also to identify and remove process inadequacies that encourage defects.
This is particularly the case for peer reviews if they are conducted early and often, on samples of work, rather than waiting until the work has been completed. Early and frequent reviews of small work samples can identify systematic errors in the author's work processes, which can be corrected before further faulty work is done. This improvement in author skills can dramatically reduce the time it takes to develop a high-quality technical document and dramatically decrease the error-rate in using the document in downstream processes.
As a general principle, the earlier a technical document is produced, the greater will be the impact of its defects on any downstream activities and their work products. Accordingly, greatest value will accrue from early reviews of documents such as marketing plans, contracts, project plans and schedules and requirements specifications. Researchers and practitioners have shown the effectiveness of reviewing process in finding bugs and security issues.