Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Javascript is currently disabled for your browser. For an optimal search experience, please enable javascript.

Advanced Search

Basic Search

Content Type

Topics

Publication Date

Technical Report

Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation

  • September 2003
  • By David J. Carney, Edwin J. Morris, Patrick R. Place
  • This 2003 report describes the development of an approach to reduce the number of program failures attributable to COTS software: the COTS Usage Risk Evaluation (CURE).
  • Acquisition Support
  • Publisher: Software Engineering Institute
    CMU/SEI Report Number: CMU/SEI-2003-TR-023
  • Abstract

    The expansion in use of commercial off-the-shelf (COTS) products has been accompanied by an increase in program failures. Many of these failures have been due to a lack of familiarity with the changed approach that COTS products demand. This report describes the development of an approach to reduce the number of program failures attributable to COTS software: the COTS Usage Risk Evaluation (CURE). The origin of CURE and an overview of the method, along with detail on the materials and mechanisms used in CURE, are provided. The CURE process is outlined and the results of the evaluations that have been conducted are summarized. Finally, possible future directions for CURE are explored.

    CURE Components

    The CURE Components link below provides the following artifacts:

    • The overview describes the overall process for the COTS Usage Risk Evaluation (CURE) as seen from the viewpoint of a member of a program to which CURE is applied.
    • Initial questionnaire: a document sent to the program in order that the evaluation team can understand the goals of the program and shape the face-to-face interview.
    • Discussion document: a complete list of topics that might be discussed during the interview.
    • Evaluation record: a variant of the discussion document that is used by the evaluation team to record the information heard during the interview.
    • CURE database: a rudimentary Microsoft Access database (and accompanying image) that supports the evaluation team in the analysis of the data gained from the interview.
    • Analysis process: an outline of the steps of the analysis process.

     

     

  • CURE Components
  • Download

Cite This Report

SEI

Carney, David; Morris, Edwin; & Place, Patrick. Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation. CMU/SEI-2003-TR-023. Software Engineering Institute, Carnegie Mellon University. 2003. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6767

IEEE

Carney. David, Morris. Edwin, and Place. Patrick, "Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Report CMU/SEI-2003-TR-023, 2003. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6767

APA

Carney, David., Morris, Edwin., & Place, Patrick. (2003). Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation (CMU/SEI-2003-TR-023). Retrieved February 25, 2018, from the Software Engineering Institute, Carnegie Mellon University website: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6767

CHI

David Carney, Edwin Morris, & Patrick Place. Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation (CMU/SEI-2003-TR-023). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2003. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6767

MLA

Carney, David., Morris, Edwin., & Place, Patrick. 2003. Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation (Technical Report CMU/SEI-2003-TR-023). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6767

BibTex

@techreport{CarneyIdentifyingCommercial2003,
title={Identifying Commercial Off-the-Shelf (COTS) Product Risks: The COTS Usage Risk Evaluation},
author={David Carney and Edwin Morris and Patrick Place},
year={2003},
number={CMU/SEI-2003-TR-023},
institution={Software Engineering Institute, Carnegie Mellon University},
address={Pittsburgh, PA},
url={http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=6767} }