NivaarExam PrepOfficial exam papers ↗

19-Soft-A6 Software Quality Assurance · December 2014

Question 1 of 8: SQA vs. SQC, Cost of Quality, and Quality Measures

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams, December 2014 — 04-Soft-A6, Software Quality Assurance (open book, non-communicating calculator permitted, 3 hours). Per the paper's own notes, FIVE of the EIGHT questions constitute a complete exam and each is of equal value; all eight are answered in full below as a complete study resource.

Reference texts. Pressman, Software Engineering: A Practitioner's Approach, 9th ed., Ch. 3 (agile and concurrent process models), Ch. 15 (SQA, cost of quality, configuration management), Ch. 17–18 (unit/integration/validation/system testing strategy, verification vs. validation), Ch. 19–20 (white-box basis-path testing, black-box equivalence partitioning & boundary value analysis); Sommerville, Software Engineering, 10th ed., Ch. 8 (Software Testing) and Ch. 24 (Quality Management); SWEBOK v4, Software Quality KA, Software Testing KA, and Software Configuration Management KA; ISO/IEC 25010 (SQuaRE) for the product quality model; ISO/IEC/IEEE 12207 (Software life cycle processes) for the SQA and configuration management process framework referenced in Questions 1 and 8.

Question 1: SQA vs. SQC, Cost of Quality, and Quality Measures (10 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

(a) SQA, SQC, and the difference between them

Software Quality Assurance (SQA) is the planned, systematic set of activities applied across the whole development process — reviews, standards enforcement, a defined testing strategy, change control, and measurement — that gives management, developers, and customers objective confidence that the software product and the PROCESS used to build it conform to established requirements and procedures. Software Quality Control (SQC) is the series of inspections, reviews, and tests used throughout the life cycle to ensure each individual work product meets the requirements placed on it, including a feedback loop to the process that created the product when a defect is found.

The difference is one of scope and focus: SQA is process-oriented and preventative — it asks "are we following the right process, organisation-wide, so defects are less likely to occur at all?" SQC is product-oriented and detective — it asks "does this specific artifact, right now, meet its own requirements?" SQC's inspections and tests are themselves one of the mechanisms SQA relies on to gain the evidence it needs; SQC is a constituent activity carried out under SQA's broader umbrella, not a separate, competing discipline.

(b) Structure of quality cost

The cost of quality is conventionally split into three categories, moving from cheapest-to-fix toward most-expensive-to-fix as a defect survives longer without being caught.

Prevention cost covers everything spent to keep a defect from ever occurring: quality planning (writing the SQA plan itself), formal technical reviews of requirements/design/code, acquiring and maintaining test equipment and tools, and training staff in quality practices and the applicable standards.

Appraisal cost covers activities that gain insight into the product's actual condition the first time through — in-process and inter-process inspection, calibration and maintenance of test/measurement equipment, and the testing itself (unit, integration, validation, system). Appraisal does not prevent defects; it finds ones that are already there, as early as possible.

Failure cost is the cost that would disappear entirely if no defect ever reached this point, and splits further into internal failure cost (rework, repair, and failure-mode analysis for defects caught before the product ships) and external failure cost (complaint resolution, product return and replacement, help-line/technical-support cost, warranty work, liability, and lost sales/goodwill for defects a customer finds). External failure cost is usually the hardest category to quantify precisely, and is typically the most expensive per defect — the whole economic argument for spending more on prevention and appraisal is that a dollar spent there avoids many dollars of external failure cost later.

(c) Software quality measures

Five commonly used measures: defect density (defects found per KLOC or per function point, normalising defect counts for size so different modules/releases are comparable); Defect Removal Efficiency, DRE (the fraction of defects present that are removed BEFORE release, computed as errors found pre-release divided by total errors found pre- and post-release — a direct measure of how effective the SQA/SQC activities in part (a)/(b) actually were); Mean Time Between Failures, MTBF (a reliability measure, the average operating time between one failure and the next, used once the product is in the field); cyclomatic complexity, V(G) (a structural complexity measure of a unit's control flow, used both to gauge how error-prone/hard-to-test a module is and, directly, to size its own basis-path test set — Question 6 works a full example); and customer-reported problems per user-month (a post-release field measure that closes the loop back to the prevention/appraisal spending decisions in part (b)).

← Paper overview