-
Notifications
You must be signed in to change notification settings - Fork 42
Description
Description:
suggested by email 4-April
I recently came across your website when investigating SDLC models. I have taken the time to go through the website and the model descriptions and it presented some valuable guidance!
However, I do have some feedback on readability of the website. For me, it took a long time to figure out what the meaning of Stream A and Stream B meant on the m
odel pages on the website. Since all model sections have Stream A and Stream B, I was trying to go through the website documentation to find the definitions of these two streams which I was unable to find. The FAQ states:
“Streams cover different aspects of a practice inside a business function. For example, in the Requirements-driven testing practice, the streams focus on positive and negative testing. See Requirements-driven Testing in the model.
Check out our about page for more on the structure of the SAMM model.”
, where the ‘about page’ itself only mentions that there are two streams for each section.
I only later discovered, by the downloadable PDF, that the green text underneath the ‘Stream’ designation is actually the definition of the stream and that they differ per model. I found this very confusing.
I have a suggestion that I think will help readers to interpret the models and streams properly. This suggestion is removing the mention of Stream A and Stream B entirely, and then use the per-model stream’s actual definition of the stream as column head (in black text). I think this makes the table much more readable and also takes away the notion that Stream A and Stream B from one model has relations to streams from another model.
I have attached two screenshots to visualize the suggestion (original.png and suggested.png).
I am interested to hear what you think of this suggestion on an otherwise very helpful model and website!
Acceptance criteria:
readers should be able to have an understanding of the relationship of the activities in the security practices where the concept of stream is either used in a consistent way and without confusion (that it links activities to other practices) or remove/replace streams (and A/B) altogether.
the simpeler it is, the better ....
Are there any known dependencies between this issue and any other issues?
no
Are there any outstanding questions?
no
Metadata
Metadata
Assignees
Labels
Type
Projects
Status