Iteration Zero
Published date: April 22, 2024, Version: 1.0
Quick Links
Cyber Security Policies
Peer Review
Definition of Ready
Team Level Metrics
Delivery
Identify business stakeholder, portfolio manager
Roll out strategy (e.g. Big bang? Phases? Continuous Delivery?)
Set up RAID log in JIRA to manage risks, assumptions, dependencies and issues
Define Definitions of Ready & Done
Establish & Explain Story Point Estimation, Reporting Requirements, & System Monitoring Requirements
Refined backlog (N+2) / 2 iteration worth of refined stories ready for development
Budget + Governance
Set up Budget Tracker
Identify team members & update budget tracker for allocation
Determine SOW requirements and notify
Planview setup
Create CBA
Development
Development Process & Tools Definition Installation Packages Storage
Local Environment Setup Guide
Verification methods & Security Code Analysis Using
Guidelines: Coding, Unit Testing, Integration Testing, Contract Testing, Static Code Analysis
Code Review Process, Branching Strategy, Repository & Its Structure Definition
Infrastructure + CI/CD
Define Development & QA Environments
Non-digital platform integration requirements (e.g. Sendsuite, COSTAR, PPE, PMM, SFMC)
Infrastructure / Firewall access requirements
Agree plan for Stage Environment Configuration
Understand code merge responsibility and release tagging
Define CI/CD process and deployment strategy
Non-digital platform integration requirements (e.g. Sendsuite, COSTAR, PPE, PMM, SFMC)
Infrastructure / Firewall access requirements
Agree plan for Stage Environment Configuration
Understand code merge responsibility and release tagging
Define CI/CD pipelines
Security
Technical Design/Architecture artifact (e.g. TIA)
Applicable security artifact (e.g. NIRA, SAINT)
Determine if Pen Test is required
Determine engagement mechanism between risk assessor, security arch & solution arch
Quality Assurance
Define Test Approach for Testing: User Stories, Epics, Automation with Chapter Lead, Performance, Security, System Integration, User Acceptance, Regression, Business Acceptance, Accessibility (AODA)
Define Test: Calendar Plans, Progress Monitoring, Reports, Data, Strategy, Process,
Resources
Map stakeholders (both technology & business)
Assign Security Architect & Risk Assessor
Engage Security BSA Engage Enterprise Risk (ERM)
Onboarding
Define internal & External Communication Plans
Provision CTC system access for 3rd party resources
Onboard Testers & Developers
Configure Squad MS Teams chat, email distribution group, and calendar (for stat holidays and planned leave)
Configure Squad MS Teams chat, email distribution group, and calendar (for stat holidays and planned leave)
Align Squad working agreements
Configure new / leverage existing Jira & Confluence space (depending on type of initiative)
Request qTest instance (if applicable)
Related Content
Coupa
Coupa is a cloud-based spend management platform designed to help businesses control and optimize their expenses and procurement processes. It offers
...
Develop
Development refers to the process of deploying and enhancing software applications, systems, or products. It encompasses various activities,
methodolo...
Jenkins
Jenkins is an open-source automation server that facilitates Continuous Integration (CI) and Continuous Deployment (CD) in software development. It
au...
Confluence
Confluence is a collaboration and documentation tool developed by Atlassian. It provides teams with a centralized platform for creating, sharing, and
...