Enterprise Release Assurance for Interconnected Energy Data, Cloud, and Application Platforms A Governance Framework for Coordinated, Multi-Team Release Delivery
Main Article Content
Abstract
While there are times when the production of software or applications are quick and frequent, enterprise-grade software systems are almost never one single development team. The application teams, cloud services, databases, data pipelines, identity platforms, application programming interfaces, security reviewers, infrastructure teams, vendors, business users, and production-support groups are all major stakeholders in a large-scale energy enterprise release. This paper combines the work of release-planning, continuous-delivery, data-quality, cybersecurity, governance- theory, and organizational-culture research to create a model for coordinating releases across interweaving energy data, cloud, and applications platforms: the Enterprise Release Assurance Framework (ERAF). ERAF assesses release readiness in six assurance domains: functional and technical readiness; data integrity and reconciliation; dependency confirmation; cybersecurity and compliance; business and operational readiness; and support, recovery, and stabilization; and combines the evidence in those domains into a composite readiness score that categorizes releases as routine, elevated-risk, or critical. The paper also outlines a common 11- point Release Evidence Package, seven leading risk indicators, and seven outcome- evaluation metrics, such as deployment frequency, change-failure rate and rollback rate. Analysis of releases at each release tier, from each release tier, suggests that differentiating the intensity of the assurance process gives a speedier delivery without the same proportionate amount of operational, security or data-integrity risk. It provides energy companies with a structure that they can use to balance velocity with accountability and reliability in technically interdependent settings
Article Details
Section
How to Cite
References
[1] C. Batini and M. Scannapieco, Data Quality: Concepts, Methodologies and Techniques. Berlin, Germany: Springer, 2006.
[2] C. Batini and M. Scannapieco, Data and Information Quality: Dimensions, Principles and Techniques. Cham, Switzerland: Springer, 2016.
[3] H. C. Benestad and J. E. Hannay, “A comparison of model-based and judgment-based release planning in incremental software projects,” in Proc. 33rd Int. Conf. Software Engineering, 2011, pp. 766–775.
[4] G. G. Claps, R. Berntsson Svensson, and A. Aurum, “On the journey to continuous deployment: Technical and social challenges along the way,” Inf. Softw. Technol., vol. 57, pp. 21–31, 2015.
[5] D. Faquir, N. Chouliaras, V. Sofia, K. Olga, and L. Maglaras, “Cybersecurity in smart grids, challenges and solutions,” AIMS Electron. Electr. Eng., vol. 5, no. 1, pp. 24–37, 2021.
[6] D. Greer and G. Ruhe, “Software release planning: An evolutionary and iterative approach,” Inf. Softw. Technol., vol. 46, no. 4, pp. 243–253, 2004.
[7] M. Z. Gunduz and R. Das, “Cyber-security on smart grid: Threats and potential solutions,” Comput. Netw., vol. 169, art. 107094, 2020.
[8] S. Jantunen, L. Lehtola, D. C. Gause, U. R. Dumdum, and R. J. Barnes, “The challenge of release planning,” in Proc. 5th Int. Workshop Software Product Management, 2011, pp. 36–45.
[9] T. Karvonen, W. Behutiye, M. Oivo, and P. Kuvaja, “Systematic literature review on the impacts of agile release engineering practices,” Inf. Softw. Technol., vol. 86, pp. 87–100, 2017.
[10] O. F. Keskin, K. M. Caramancion, I. Tatar, O. Raza, and U. Tatar, “Cyber third-party risk management: A comparison of non-intrusive risk scoring reports,” Electronics, vol. 10, no. 10, art. 1168, 2021.
[11] B. Kitchenham et al., “Systematic literature reviews in software engineering—A tertiary study,” Inf. Softw. Technol., vol. 52, no. 8, pp. 792–805, 2010.
[12] E. Laukkanen, J. Itkonen, and C. Lassenius, “Problems, causes and solutions when adopting continuous delivery—A systematic literature review,” Inf. Softw. Technol., vol. 82, pp. 55–79, 2017.
[13] E. Laukkanen, M. Paasivaara, J. Itkonen, and C. Lassenius, “Comparison of release engineering practices in a large mature company and a startup,” Empir. Softw. Eng., vol. 23, no. 6, pp. 3535–3577, 2018.
[14] M. Lindgren, R. Land, C. Norstro¨m, and A. Wall, “Key aspects of software release planning in industry,” in Proc. 19th Australian Conf. Software Engineering, 2008, pp. 320–329.
[15] P. Mell and T. Grance, “The NIST definition of cloud computing,” NIST Special Publication 800-145, Nat. Inst. Standards Technol., Gaithersburg, MD, USA, 2011.
[16] F. Mohammadi, “Emerging challenges in smart grid cybersecurity enhancement: A review,” Energies, vol. 14, no. 5, art. 1380, 2021.
[17] L. Moreno et al., “ARENA: An approach for the automated generation of release notes,” IEEE Trans. Softw. Eng., vol. 43, no. 2, pp. 106–127, 2017.
[18] National Institute of Standards and Technology, “Framework for improving critical infrastructure cybersecurity,” Version 1.1, Gaithersburg, MD, USA, 2018.
[19] G. Ruhe and A. Ngo-The, “Hybrid intelligence in software release planning,” Int. J. Hybrid Intell. Syst., vol. 1, no. 2, pp. 99–110, 2004.
[20] M. Shahin, M. A. Babar, and L. Zhu, “Continuous integration, delivery and deployment: A systematic review on approaches, tools, challenges and practices,” IEEE Access, vol. 5, pp. 3909–3943, 2017.
[21] M. Shahin, M. Zahedi, M. A. Babar, and L. Zhu, “An empirical study of architecting for continuous delivery and deployment,” Empir. Softw. Eng., vol. 24, no. 3, pp. 1061–1108, 2019.
[22] M. Svahnberg et al., “A systematic review on strategic release planning models,” Inf. Softw. Technol., vol. 52, no. 3, pp. 237–248, 2010.
[23] P. P. Tallon, R. V. Ramirez, and J. E. Short, “The information artifact in IT governance: Toward a theory of information governance,” J. Manage. Inf. Syst., vol. 30, no. 3, pp. 141–178, 2013.
[24] R. Westrum, “A typology of organisational cultures,” Qual. Saf. Health Care, vol. 13, suppl. 2, pp. ii22–ii27, 2004.
[25] L. Zhang, J.-H. Tian, J. Jiang, Y.-J. Liu, M.-Y. Pu, and T. Yue, “Empirical research in software engineering—A literature survey,” J. Comput. Sci. Technol., vol. 33, no. 5, pp. 876–899, 2018.