X-Git-Url: https://git.martlubbers.net/?a=blobdiff_plain;ds=sidebyside;f=report%2Freflection.auditing_process.tex;h=844a1d7020fa5d013f42beb7ff249f5bc42100ae;hb=HEAD;hp=3811140db64430be5f64cc6b763a5cd8dc8d5942;hpb=300e85f3c63352c982b683c730531a8ede1a3895;p=ssproject1617.git diff --git a/report/reflection.auditing_process.tex b/report/reflection.auditing_process.tex index 3811140..844a1d7 100644 --- a/report/reflection.auditing_process.tex +++ b/report/reflection.auditing_process.tex @@ -2,18 +2,18 @@ % Daan: If you would have to do something like this again? (...) We have noticed that, when doing an audit in a team, it is not feasible for -everybody to have read all source code. Henceforth, trying this is just a bad +everybody to have read all source code. Trying this is just a bad idea. We are happy to have divided the project by ASVS category, instead of -program component. For each requirement the the ASVS, the +program component. For each requirement the ASVS, the team had to verify that there were no mistakes in the code. This would have taken a lot of time if we had to verify each component for each requirement. Furthermore, the ASVS is an easy guide for dividing the work\footnote{The -categories in the ASVS are all of similar size. We settled on giving each team +categories in the ASVS are all more or less of similar size. We settled on giving each team member two categories to check.}. Dividing by component would have been a lot harder to do fairly, especially because when beginning the project we had -little knowledge of the internals (and component sizes) of the CMS. +little knowledge of the internals (and component sizes) of the \CMS{}. -We haven't experimented with working in pairs. This might be a good idea to +We have not experimented with working in pairs. This might be a good idea to experiment with. We are confident however that, because we have all checked each other's finished work (and the final product), we did not miss any problems.