<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Examples of practical use of ISO/IEC 25000</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Domenico Natale, Andrea Trenta</string-name>
          <email>dnatale51@gmail.com andrea.trenta@dataqualitylab.it</email>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Product Quality model</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Quality aspects on</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Data Quality model</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Accuracy</institution>
          ,
          <addr-line>Completeness, Consistency, Credibility, Currentness, Accessibility, Compliance, Confidentiality, Efficiency, Precision, Traceability, Understandability, Availability, Portability, Recoverability</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Artificial Intelligence</institution>
          ,
          <addr-line>Accuracy, Credibility, Currenteness, Compliance, Efficiency, Precision, Usability, Understandability, Security, Availability</addr-line>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Functional suitability</institution>
          ,
          <addr-line>Performance efficiency, Compatibility, Usability, Reliability, Security, Maintainability, Portability</addr-line>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>UNINFO UNI CT 504, Technical Committee System and Software Engineering</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2019</year>
      </pub-date>
      <abstract>
        <p>- In recent years the ISO/IEC 25000 series of standards seems to have reached their completeness and maturity expanding their definition from software to systems, data and IT service products. The ISO/IEC 25000 application in industry is on a voluntary basis, but it is also supported by public regulatory context. Some actions are also undertaken to apply these standards when new quality measures are defined.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>INTRODUCTION</title>
      <p>This paper concerns a description of ISO/IEC 25000
series adoption in Italy and an approach to allow application
of the series when customization measures are needed. It is
not an article concerning research work, but a brief
experiential story of regulatory laws and lessons learned.
II.</p>
      <p>STATE OF ART OF ISO/IEC 25000 IN ITALY</p>
      <p>The application of the ISO/IEC 25000 series was
primarily reflected in the companies where the attending
experts had participated in ISO/IEC JTC1/SC7 Working
Group 6 activities.</p>
      <p>Some examples of the first applications come from
companies with very large data bases, specially to
guarantee consistency between systems; the other
applications come from enterprises that can benefit of a
preventive and well-defined application of software
product quality control, specially to guarantee usability for
the final user.</p>
      <p>Another experienced context is the public procurement
of IT products, where the tender entity requires or
recommends the application of ISO/IEC 25000 series; this
followed the endorsement on behalf of the Italian IT
regulation authority of ISO/IEC 25010 and ISO/IEC 25012
as a quality reference.</p>
      <p>The following documents have been published by
public authorities (www.agid.gov.it - www.uni.com):
-Technical guide to the use of metrics for application
software developed on behalf of public administrations,
concerning ISO/IEC 25010 and ISO/IEC 25023 (by AgID
the Italian Agency for public administration);
- Technical rules to identify critical data base and to define
the updating methods to guarantee their data quality,
recommending ISO/IEC 25012 (by AgID);
- UNI/TS 11725 Guidelines for measuring data quality,
concerning the application of ISO/IEC 25024 (by UNI
Italian National Body);
- “Statements” of ISO/IEC 25000 compliance have been
recently issued by accredited companies that act as a
“third party” for the companies that wished to be certified.
III.
- companies have realized that for new technologies,
there is no need to reinvent the wheel, but combine the
defined quality characteristics and eventually enrich
them with new features or measures.</p>
      <sec id="sec-1-1">
        <title>IV. CONFORMING MEASURES</title>
        <p>The ISO/IEC 25000 defines 36 quality characteristics
and over 200 quality measures and expected further
multiplication of characteristics in the future, particularly of
measures.</p>
        <p>In the contexts above, to ensure the maximum
effectiveness, a detailed description of the measures
adopted/required/suggested is envisaged.</p>
        <p>This comes from the fact that measures are generally
defined or suitable for contexts that are not the same of the
desired one. It should be noted that ISO/IEC 25022,
ISO/IEC 25023, ISO/IEC 25024 clearly foresee the
possibility, at certain conditions, to define new measures
(conforming measures) if required by the user or by the
context. Following this approach there is no need to draft a
new standard for each new technology (Big Data, AI, etc..),
as it is up to the user to do so.</p>
        <p>For example: the ISO/IEC 25024 Acc-I-1 standard
measure was intentionally defined in a generic way, as the
score from strings comparison depends on the algorithm
chosen. The solution proposed in Italian working group of
UNINFO/UNI (Italian NB) is to register the new
conforming measure Acc-I-1-IT-1 1 . The new measure
specifies the Jaro-Winkler as the comparison algorithm to
be used, and so it is applicable; the user who needs a
different algorithm, can design a new conforming measure.
V.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>THE PROPOSAL</title>
      <p>But there arises a problem: how to distinguish a standard
ISO/IEC 25000 measure from a user-created one? Who is
in charge of checking and documenting the new measure
against ISO/IEC 25000 criteria? And secondly: how to
share a “user-created” measure to ensure comparison?
How to avoid duplication of similar user-created
measures?</p>
      <p>The mentioned national standard UNI/TS 11725
created a first version of measures that incorporates some
user-created measures for data quality; then the new user
created measures are:
-public (easy to be accessed);
-experts checked (against ISO/IEC 25000 rules);
-registered (non-duplicated).</p>
      <p>Moreover, when a National Body could be in charge of
this type of registration process, it should be assumed that
the user-defined measures have the same intellectual
property and the same legal value of the standard ones.</p>
      <p>Figure 2 shows a possible approach that can fulfill every
need of measurements exploiting the conforming measure
mechanism defined in §2 of ISO/IEC 2502n (n=2,3,4).
Measuring needs
covered by 2502x
standard measure?
•Ifyes,thenstop
(userwill use the
standardmeasure
that fulfills)
No
No</p>
      <p>Define* and
register**new
compliant measure
•Stop(userwill use
thenew
conforming
measuredesigned
to fulfill)</p>
      <p>Some issues are to be investigated in particular about
the registration of measures:
the registration process within and outside national
borders, interaction among National Bodies;
publishing and accessing user-defined measures;
feedback to ISO editors of quality models</p>
      <sec id="sec-2-1">
        <title>VI. CONCLUSION</title>
        <p>This approach can appropriately address some issues
recently investigated by the Future Directions Study Group
of ISO/IEC JTC1/SC7/WG6; in particular, the approach
depicted above is applicable for example to AI and other
themes. In those areas the algorithms - whose time
efficiency is a crucial measure - are evolving very rapidly
and there is the risk of reflecting them too late in a new
standard. The registering approach for user-defined new
measures, allows immediate application. Nevertheless, this
doesn’t preclude the evolution of standards, also making it
easier, as the new measures will come mostly from
experienced applications and not only by theoretical
reasonings.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1] ISO/IEC 25010:
          <article-title>2011Systems and Software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - System and software quality models</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2] ISO/IEC 25012:
          <article-title>2008 Systems and Software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - Data quality model</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3] ISO/IEC 25020:
          <year>2019</year>
          ,
          <article-title>Systems and Software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - Quality measurement framework</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4] ISO/IEC 25022:
          <year>2016</year>
          ,
          <article-title>Systems and Software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - Measurement of quality in use.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5] ISO/IEC 25023:
          <year>2016</year>
          ,
          <article-title>Systems and Software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - Measurement of system and software product quality</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6] ISO/IEC 25024:
          <year>2015</year>
          ,
          <article-title>Systems and Software engineering - Systems and software Quality Requirements and Evaluation (SQuaRE) - Measurement of data quality</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>