Let’s Play Poker: Effort and Software Security Risk Estimation in Software Engineering

February 27th, 2010 4:00 AM

Durham, NC

Effort and risk estimation are both important and problematic in software engineering. Inaccurate effort estimates can lead a team to making unrealistic commitments for completing a software project. Effort estimation models can be complex and require a significant amount of historical data to be collected and analyzed. As a result, effort estimates are often done in an ad hoc manner by management and/or team leaders. Likewise, software teams often estimate and rank their risks in a subjective manner due to problems quantifying the probability of a risk occurring and the impact of the risk. This talk will present the Planning Poker and Protection Poker “games” for collaborative effort and security risk estimation.

