SlideShare a Scribd company logo
Enterprise SPICE Scope Linda Ibrahim
First Technical Decisions We need to decide Enterprise SPICE scope. This entails the following: What disciplines will Enterprise SPICE address? What standards will be integrated into Enterprise SPICE regarding those agreed disciplines?
Scope Determination Process Steps to determine Enterprise SPICE initial scope:  Develop criteria for additional disciplines and source standards Receive approval from Advisory Board on criteria Request and receive stakeholder inputs on suggested disciplines and source standards Review stakeholder inputs on suggested disciplines and source standards and provide recommendations to Advisory Board Receive approval from Advisory Board on disciplines and source standards to be included (in initial baseline model, in subsequent releases, etc according to prioritization discussions/decisions) Suggest this be accomplished within ~3 months   Upon completion of scope determination, Technical Author Team and Authors will develop plan for product development
Discipline Scope Current discipline scope  for Enterprise SPICE, based on disciplines addressed in the iCMM and its extensions, includes:  full lifecycle software engineering, full lifecycle systems engineering, acquisition, quality management, enterprise leadership and strategic processes, integrated process/product development, safety and security Examples of additional disciplines  that might be considered: service management, human resource management, financial/ investment management, supply chain management, marketing, manufacturing, or other broad enterprise processes (etc) Discipline selection  will be determined by Enterprise SPICE Advisory Board based on recommendations of collaborators and stakeholders.  Criteria  for discipline selection might include: relevance  to stakeholder enterprises, perceived  need  for assessing processes in these disciplines in stakeholder enterprises,  value  of including these disciplines in enterprise assessments, etc.  It is recommended disciplines be  broad  in focus,  not industry-specific .  It is recommended disciplines be  prioritized  in terms of criticality or need for inclusion.
Discipline Scope Discussion Questions What criteria should be used to decide Enterprise SPICE discipline scope?  What disciplines might be included in Enterprise SPICE?
Source Material Sources:  Once discipline scope is decided, source documents and reference documents need to be selected for agreed discipline scope Source  documents are documents from which Enterprise SPICE practices are derived.  Mapping  of Enterprise SPICE practices to source practices is required and  coverage  of source documents, at an appropriate level of detail, will be demonstrated.  Reference  documents are documents identified as useful in developing best practice in certain areas, but full coverage and detailed mapping is not required. Source material  will be determined by Enterprise SPICE Advisory Board based on recommendations of Enterprise SPICE collaborators and stakeholders.  Criteria  recommended for source material selection:  only major, essential, widely-recognized standards/models be selected as source documents number of sources for a discipline limited to 3 to 5 for a given area.
Current Source Material   Current Source Material,  based on disciplines in iCMM and its extensions, includes  18 sources : Four ISO Standards: ISO 9001:2000  Quality Management Systems  ISO/IEC 12207*  Software life cycle processes  (ISO/IEC 15504-5) ISO/IEC 15288 ** System Life Cycle Processes  (ISO/IEC 15504-6) ISO/IEC 15504 **  Process assessment  Performance Excellence Criteria: Malcolm Baldrige National Quality Award/President’s Quality Award Criteria **  Five Capability Models: EIA 731  Systems Engineering Capability CMMI  CMM Integrated  SW-CMM  CMM for Software SA-CMM  Software Acquisition CMM SE-CMM  Systems Engineering CMM * Need to address 12207 amendments  ** selected aspects of human resource management not currently in iCMM scope
Current Source Material   (continued) Four Safety Sources:   MIL-STD-882C:  System Safety Program Requirements MIL-STD-882D:  Standard Practice for System Safety IEC 61508:  Functional Safety of Electrical/ Electronic/ Programmable Electronic Systems DEF STAN 00-56:  Safety Mgmt Requirements for Defence Systems Four Security Sources: ISO 17799:  Information Technology - Code of practice for information security management  ISO 15408:  The Common Criteria - Mapping of Assurance Levels and Families ISO/IEC 21827: SSE-CMM:  Systems Security Engineering CMM  NIST 800-30:  Risk Mgmt Guide for Information Technology Systems
Source Material Discussion Questions What criteria should be used to decide Enterprise SPICE source standards?  What source standards might be included in Enterprise SPICE?
Scope Prioritization Phases:   Enterprise SPICE may evolve through phases to address broadening scope or evolving needs over time, and based on experience in enterprise assessments, e.g., Phase 1:  Enterprise SPICE scope initially includes the baseline disciplines and standards/models (latest versions) addressed in the iCMM and extensions. Phase 2:  Enterprise SPICE scope additionally includes service management plus any other high priority discipline.  Phase 3:  Enterprise SPICE scope addresses next highest priority set of disciplines.

More Related Content

PDF
Identify Applicable EHS Regulatory Documents
PPTX
Safety system life cycle
PPTX
Hipaa hitech requirements
PPTX
Compliance Framework
PPTX
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
PPTX
ISO 27001:2013 IS audit plan - by software outsourcing company in india
PPT
Process
PPTX
D1 security and risk management v1.62
Identify Applicable EHS Regulatory Documents
Safety system life cycle
Hipaa hitech requirements
Compliance Framework
Vendor Management - PCI DSS, ISO 27001, E13PA,HIPPA & FFIEC
ISO 27001:2013 IS audit plan - by software outsourcing company in india
Process
D1 security and risk management v1.62

What's hot (17)

PPT
Ais Romney 2006 Slides 19 Ais Development Strategies
PPTX
ISO 27001 management clause 7 support - by software development company in india
PDF
How to Effectively Audit your IT Infrastructure
PDF
Iso 27001 metrics and implementation guide
PPTX
Iso 27001 transition to 2013 03202014
PDF
NQA ISO 22301 Transition Gap Guide
PDF
Swetana A Purohit
PPTX
IS audit checklist
PPTX
Is audit plan
PPT
The best way to use ISO 27001
PDF
Defining Segregation of Duties
PPTX
Planning for security and security audit process
PPTX
IT Audit For Non-IT Auditors
PPT
IT Audit methodologies
PDF
CISA Domain 3 - Information Systems Acquisition, Development and Implementation
PDF
Transitioning to iso 27001 2013
PDF
Iso 27001 audits_guide
Ais Romney 2006 Slides 19 Ais Development Strategies
ISO 27001 management clause 7 support - by software development company in india
How to Effectively Audit your IT Infrastructure
Iso 27001 metrics and implementation guide
Iso 27001 transition to 2013 03202014
NQA ISO 22301 Transition Gap Guide
Swetana A Purohit
IS audit checklist
Is audit plan
The best way to use ISO 27001
Defining Segregation of Duties
Planning for security and security audit process
IT Audit For Non-IT Auditors
IT Audit methodologies
CISA Domain 3 - Information Systems Acquisition, Development and Implementation
Transitioning to iso 27001 2013
Iso 27001 audits_guide
Ad

Viewers also liked (7)

PDF
Touchpoints and security
PPTX
Security Vulnerabilities in Third Party Code - Fix All the Things!
PPTX
Security in the Development Lifecycle - lessons learned
PDF
Security Maturity Models.
PPT
How to Avoid the Top Ten Software Security Flaws
PPTX
Secure Design: Threat Modeling
Touchpoints and security
Security Vulnerabilities in Third Party Code - Fix All the Things!
Security in the Development Lifecycle - lessons learned
Security Maturity Models.
How to Avoid the Top Ten Software Security Flaws
Secure Design: Threat Modeling
Ad

Similar to Enterprise Spice Scope (20)

PPT
Enterprise Spice Kickoff Overview
PDF
Internal Audits and Assessments with help of Enterprise SPiCE
PDF
Strategies and Process Improvement with Enterprise SPICE®
PPT
Spice
PDF
Internal Audits and Assessments with help of Enterprise SPiCE
PPT
What Is Iso/iec 15504
PPT
ISO/IEC 15504
PPT
ISO/IEC 15504
PPT
Spice
PPTX
software process improvement
PDF
Enterprise Spice Agenda Draft18 October
PDF
Looking for my fittest process' model
PDF
1. bussiness process diagonistic tool for cpm
PPT
How Does IT Provide A Consistently Effective Service
PPT
Spice
PPSX
Spice a resource for leadership and innovation
DOC
Optimize Workloads with IBM Solutions and Services
PPTX
Software Process Improvement - RKREDDY
PDF
Adopt Adapt and Apply IT Best Practices - David Ratcliffe
DOCX
Managing and Using Information Systems A Strategic Approach –.docx
Enterprise Spice Kickoff Overview
Internal Audits and Assessments with help of Enterprise SPiCE
Strategies and Process Improvement with Enterprise SPICE®
Spice
Internal Audits and Assessments with help of Enterprise SPiCE
What Is Iso/iec 15504
ISO/IEC 15504
ISO/IEC 15504
Spice
software process improvement
Enterprise Spice Agenda Draft18 October
Looking for my fittest process' model
1. bussiness process diagonistic tool for cpm
How Does IT Provide A Consistently Effective Service
Spice
Spice a resource for leadership and innovation
Optimize Workloads with IBM Solutions and Services
Software Process Improvement - RKREDDY
Adopt Adapt and Apply IT Best Practices - David Ratcliffe
Managing and Using Information Systems A Strategic Approach –.docx

Recently uploaded (20)

PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Getting Started with Data Integration: FME Form 101
PDF
Empathic Computing: Creating Shared Understanding
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Machine Learning_overview_presentation.pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
Big Data Technologies - Introduction.pptx
PPTX
1. Introduction to Computer Programming.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Tartificialntelligence_presentation.pptx
Programs and apps: productivity, graphics, security and other tools
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Getting Started with Data Integration: FME Form 101
Empathic Computing: Creating Shared Understanding
Unlocking AI with Model Context Protocol (MCP)
The Rise and Fall of 3GPP – Time for a Sabbatical?
Diabetes mellitus diagnosis method based random forest with bat algorithm
NewMind AI Weekly Chronicles - August'25-Week II
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Per capita expenditure prediction using model stacking based on satellite ima...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
MYSQL Presentation for SQL database connectivity
Machine Learning_overview_presentation.pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Big Data Technologies - Introduction.pptx
1. Introduction to Computer Programming.pptx
Spectral efficient network and resource selection model in 5G networks
Tartificialntelligence_presentation.pptx

Enterprise Spice Scope

  • 1. Enterprise SPICE Scope Linda Ibrahim
  • 2. First Technical Decisions We need to decide Enterprise SPICE scope. This entails the following: What disciplines will Enterprise SPICE address? What standards will be integrated into Enterprise SPICE regarding those agreed disciplines?
  • 3. Scope Determination Process Steps to determine Enterprise SPICE initial scope: Develop criteria for additional disciplines and source standards Receive approval from Advisory Board on criteria Request and receive stakeholder inputs on suggested disciplines and source standards Review stakeholder inputs on suggested disciplines and source standards and provide recommendations to Advisory Board Receive approval from Advisory Board on disciplines and source standards to be included (in initial baseline model, in subsequent releases, etc according to prioritization discussions/decisions) Suggest this be accomplished within ~3 months Upon completion of scope determination, Technical Author Team and Authors will develop plan for product development
  • 4. Discipline Scope Current discipline scope for Enterprise SPICE, based on disciplines addressed in the iCMM and its extensions, includes: full lifecycle software engineering, full lifecycle systems engineering, acquisition, quality management, enterprise leadership and strategic processes, integrated process/product development, safety and security Examples of additional disciplines that might be considered: service management, human resource management, financial/ investment management, supply chain management, marketing, manufacturing, or other broad enterprise processes (etc) Discipline selection will be determined by Enterprise SPICE Advisory Board based on recommendations of collaborators and stakeholders. Criteria for discipline selection might include: relevance to stakeholder enterprises, perceived need for assessing processes in these disciplines in stakeholder enterprises, value of including these disciplines in enterprise assessments, etc. It is recommended disciplines be broad in focus, not industry-specific . It is recommended disciplines be prioritized in terms of criticality or need for inclusion.
  • 5. Discipline Scope Discussion Questions What criteria should be used to decide Enterprise SPICE discipline scope? What disciplines might be included in Enterprise SPICE?
  • 6. Source Material Sources: Once discipline scope is decided, source documents and reference documents need to be selected for agreed discipline scope Source documents are documents from which Enterprise SPICE practices are derived. Mapping of Enterprise SPICE practices to source practices is required and coverage of source documents, at an appropriate level of detail, will be demonstrated. Reference documents are documents identified as useful in developing best practice in certain areas, but full coverage and detailed mapping is not required. Source material will be determined by Enterprise SPICE Advisory Board based on recommendations of Enterprise SPICE collaborators and stakeholders. Criteria recommended for source material selection: only major, essential, widely-recognized standards/models be selected as source documents number of sources for a discipline limited to 3 to 5 for a given area.
  • 7. Current Source Material Current Source Material, based on disciplines in iCMM and its extensions, includes 18 sources : Four ISO Standards: ISO 9001:2000 Quality Management Systems ISO/IEC 12207* Software life cycle processes (ISO/IEC 15504-5) ISO/IEC 15288 ** System Life Cycle Processes (ISO/IEC 15504-6) ISO/IEC 15504 ** Process assessment Performance Excellence Criteria: Malcolm Baldrige National Quality Award/President’s Quality Award Criteria ** Five Capability Models: EIA 731 Systems Engineering Capability CMMI CMM Integrated SW-CMM CMM for Software SA-CMM Software Acquisition CMM SE-CMM Systems Engineering CMM * Need to address 12207 amendments ** selected aspects of human resource management not currently in iCMM scope
  • 8. Current Source Material (continued) Four Safety Sources: MIL-STD-882C: System Safety Program Requirements MIL-STD-882D: Standard Practice for System Safety IEC 61508: Functional Safety of Electrical/ Electronic/ Programmable Electronic Systems DEF STAN 00-56: Safety Mgmt Requirements for Defence Systems Four Security Sources: ISO 17799: Information Technology - Code of practice for information security management ISO 15408: The Common Criteria - Mapping of Assurance Levels and Families ISO/IEC 21827: SSE-CMM: Systems Security Engineering CMM NIST 800-30: Risk Mgmt Guide for Information Technology Systems
  • 9. Source Material Discussion Questions What criteria should be used to decide Enterprise SPICE source standards? What source standards might be included in Enterprise SPICE?
  • 10. Scope Prioritization Phases: Enterprise SPICE may evolve through phases to address broadening scope or evolving needs over time, and based on experience in enterprise assessments, e.g., Phase 1: Enterprise SPICE scope initially includes the baseline disciplines and standards/models (latest versions) addressed in the iCMM and extensions. Phase 2: Enterprise SPICE scope additionally includes service management plus any other high priority discipline. Phase 3: Enterprise SPICE scope addresses next highest priority set of disciplines.