Improving software risk management in a medical device company

Fergal McCaffery, John Burton, Ita Richardson

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Software Risk Management (RM) within Medical Device (MD) companies is a critical area. Failure of the software can have potentially catastrophic effects, leading to injury of patients or even death. Therefore regulators penalise MD manufacturers that do not devote sufficient attention to the areas of hazard analysis and RM throughout the software lifecycle. This paper describes the experience of a MD software development organization when they engaged in a research project to improve their RM practices. We explain how this was achieved through the development of a software process improvement RM model that integrates regulatory MD RM requirements with the goals and practices of the Capability Maturity Model Integration (CMMI). This model is known as the Risk Management Capability Model (RMCM). The authors describe the complete project lifecycle and evaluate the success of the project.

Original languageEnglish
Title of host publication2009 31st International Conference on Software Engineering - Companion Volume, ICSE 2009
Pages152-162
Number of pages11
DOIs
Publication statusPublished - 2009
Event2009 31st International Conference on Software Engineering, ICSE 2009 - Vancouver, BC, Canada
Duration: 16 May 200924 May 2009

Publication series

Name2009 31st International Conference on Software Engineering - Companion Volume, ICSE 2009

Conference

Conference2009 31st International Conference on Software Engineering, ICSE 2009
Country/TerritoryCanada
CityVancouver, BC
Period16/05/0924/05/09

Fingerprint

Dive into the research topics of 'Improving software risk management in a medical device company'. Together they form a unique fingerprint.

Cite this