EDBT 2026 Demo / reviewers in the wild / expert
Sajjad Mahmood
dblp:15/4371
· DBLP profile ↗
45ranked-venue papers
8as first author
25since 2021 · last 2026
0000-0001-5786-5118ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 38 · 5 first-author · 23 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Image to Insight: Evaluating LLM Accuracy in Understanding UML Use Case Diagrams with Claude
Mohamed El-Attar 0001, Yasser A. Khan, Mahmood Niazi, Sajjad Mahmood, Mohammad R. Alshayeb |
ENASE (1) | 4 |
| 2026 | Assessing the Efficacy of Claude in Understanding Hand-Sketched UML Use Case Diagrams
Mohamed El-Attar 0001, Yasser Khan, Mahmood Niazi, Sajjad Mahmood, Mohammad R. Alshayeb, Mousa Al-Kfairy |
ICSOFT | 4 |
| 2026 | An exploratory study on effectiveness of GPT-4o in conducting sub-tasks of systematic literature reviews
Mohammad Shameem, Mohammad R. Alshayeb, Mahmood Niazi, Sajjad Mahmood, Aakash Ahmad, Jehad Al Dallal |
Autom. Softw. Eng. | 4 |
| 2026 | KRCapVLM: Beam-guided knowledge replay for knowledge-rich image captioning using vision-language model
Reem AlJunaid, Qasim Umer, Sajjad Mahmood, Mahmood Niazi, Muzammil Behzad |
Pattern Recognit. | 3 |
| 2026 | Low-Code and No-Code Tools: A Valuable Aid or a Potential Threat to Professional Developers?abstractABSTRACT Background The rapid adoption of low‐code (LC) and no‐code (NC) tools has transformed the software development landscape, offering faster development cycles and enabling non‐programmers to contribute to software creation. Objective This study systematically maps the effects of LC/NC tools on developers, addressing the critical need to understand whether these tools serve as a valuable aid or a potential threat to their roles. Methods By analyzing how LC/NC tools support development processes, the challenges they present, and their potential to replace traditional developers, this research fills a key knowledge gap by performing a systematic mapping study. Results The findings reveal that while LC/NC tools simplify certain tasks, they do not replace the need for professional developers to handle complex technical challenges, change management, and system integration. Conclusions Rather than posing a threat, these tools complement and enhance developers' expertise, empowering them to focus on more advanced aspects of software creation. This study provides valuable insights for the professional developer community and the broader software industry, advocating for the thoughtful integration of LC/NC tools as powerful aids rather than competitors to professional development. Saima Rafi, Muhammad Azeem Akbar, Sajjad Mahmood |
Softw. Pract. Exp. | 3 |
| 2025 | Introduction to software architecture for quantum computing systems special issue
Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood |
Inf. Softw. Technol. | 3 |
| 2025 | Complex outsourcing relationships management modelabstractAbstract Global software development (GSD) refers to developing software with a distributed team spanning multiple locations and time zones. Based on relationships, there are four types of outsourcing: dyadic (one client–one vendor), multi‐vendor (one client–many vendors), co‐sourcing (many clients–one vendor), and complex outsourcing (many clients–many vendors). Compared to the other types of outsourcing contracts, complex outsourcing contracts are the hardest to work on and have the highest risk of project failure. This paper presents a model, the complex outsourcing relationships management model (CORMM), to assist the complex outsourcing stakeholders (both the clients and vendors) in managing their relationships in the context of GSD. This paper aims to develop a CORMM to assist the complex outsourcing relationships management stakeholders in GSD. Also, we are interested in identifying the applicability and effectiveness of the CORMM in the real‐world industry. The research approach follows a structured methodology comprising multiple phases. Initially, it leverages a systematic literature review (SLR) as its primary research method. The second phase involves the validation of the SLR findings via an empirical study. Subsequently, in the third phase, a model is developed. Finally, the proposed research approach is validated by incorporating two industrial case studies to assess the organization's relationship management utilizing the Motorola tool. The case study results show that CORMM can successfully point out relationship management issues in a complex outsourcing context. The feedback received from the participants of both companies indicates several positive and valuable insights about the CORMM and its application in the context of complex outsourcing relationships. The results highlight that CORMM serves as an assessment tool for evaluating an organization's relationship management capability and a means for organizations to enhance their position. Through CORMM, complex outsourcing organizations (many clients–many vendors) can identify strengths and weaknesses in their relationship management practices, enabling targeted improvement efforts. Ghulam Murtaza Khan, Siffat Ullah Khan, Mahmood Niazi, Muhammad Ilyas 0002, Mamoona Humayun, Akash Ahmad, Javed Ali Khan, Sajjad Mahmood |
J. Softw. Evol. Process. | 8 |
| 2025 | Management of DevSecOps Process: An Empirical InvestigationabstractABSTRACT Context DevSecOps integrates security into the DevOps project lifecycle, uniting development, operations, and security practices. This integration, while beneficial for developing secure software, introduces complexity from a project management perspective. This study delves into this complexity by examining the 10 knowledge areas of the Project Management Body of Knowledge (PMBOK) within the context of DevSecOps project management. Objective This study aims to explore and understand the application of PMBOK's 10 knowledge areas in managing DevSecOps projects, focusing on the guidelines that are important to consider in integration of security practices throughout the development lifecycle. Method Our research approach involved two phases: Firstly, we developed a theoretical model grounded in DevSecOps guidelines identified from existing literature. Secondly, we conducted a quantitative survey targeting industry practitioners to gather insights into the practical application of the theoretical model. The study involved 138 responses from professionals, which were subsequently analyzed using correlation and Partial Least Squares (PLS) analysis to test the hypotheses posited in the theoretical model. Results The analysis reveals critical insights into the management of DevSecOps projects, highlighting the importance of adhering to specific guidelines to navigate the complexities introduced by the integration of security practices. The empirical data support the theoretical model, underscoring the relevance of PMBOK's knowledge areas in the successful management of DevSecOps projects. Conclusion For organizations committed to the DevSecOps paradigm, it is imperative to consider and implement the identified guidelines. These guidelines not only support the sustainable integration of security practices into DevOps projects but also contribute to the overall success and security of the software developed under this paradigm. Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood, Sami Hyrynsalmi |
Softw. Pract. Exp. | 3 |
| 2024 | Aligning Academic with Industrial Needs: Investigating DevOpsabstractOver recent years, DevOps has gained more attention within the software industry, owing to its pivotal role in facilitating continuous software delivery. The significant demand for DevOps practitioners necessitates substantial adjustments in conventional software engineering courses in higher educational institutions. Recent studies have highlighted DevOps principles, challenges, best practices, and tools to facilitate continuous delivery and deployment pipelines from an industrial perspective. As numerous universities are now introducing courses related to DevOps for students majoring in software engineering and computer science, this high demand for DevOps practitioners requires non-trivial adjustments in traditional software engineering courses and educational methodologies, including practices for teaching DevOps, training in DevOps, the level to which DevOps is currently taught and applied to measure the gap between teaching practices compared to industrial requirements. Our vision paper aims to highlight the crucial need for updated policies and tools to improve DevOps training in higher education, providing guidelines. By aligning academic curricula with industry standards, we can ensure students are better equipped for the demands of the workforce, fostering a seamless transition from academia to industry and promoting innovation in software engineering practices. Saima Rafi, Muhammad Azeem Akbar, Sajjad Mahmood |
EASE | 3 |
| 2024 | Successful management of cloud-based global software development projects: A multivocal studyabstractAbstract Software industry is continuously exploring better ways to develop applications. A new phenomenon to achieve this is cloud‐based global software development (CGSD), which refers to the adoption of cloud computing services by organizations to support global software development projects. The CGSD approach affects the strategic and operational aspects of the way projects are managed. The objective of the study is to identify the success factors which contribute to management of CGSD projects. We carried out a multivocal literature review (MLR) to identify the success factors from the state‐of‐the‐art and the state‐of‐the‐practice in project management of CGSD projects. We identified 32 success factors that contribute to the management of CGSD projects. The findings of MLR indicate that time to market, continuous development, financial restructuring, and scalability are the most critical success factors for CGSD. Moreover, the findings of the study show that there is a positive correlation between the success factors reported in both formal literature and industry based gray literature. The findings of this study can assist the practitioners to develop the strategies needed for effective project management of CGSD projects. Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood, Kari Smolander |
J. Softw. Evol. Process. | 3 |
| 2024 | Maturity model for secure software testingabstractAbstract Security is an essential attribute of high‐quality software. However, effectively incorporating security practices into different phases of the software development life cycle (SDLC) remains challenging. Owing to less mature secure testing processes, organizations are prone to ineffective testing practices for defect detection, including severe security‐related failures. Thus, in this study, we present a maturity model for secure software testing (MMSST) to assist software development organizations in improving the secure testing of software applications. We conducted a multivocal literature review and identified 68 primary studies from the formal and gray literature. Then, based on the available evidence, 27 process areas were identified to develop the proposed MMSST. The MMSST includes five main categories: governance, contrive and design, execution, deployment and configuration, and mature. The MMSST was subsequently evaluated using case studies related to practical environments. Results demonstrate that the proposed MMSST is useful for estimating the maturity level of an organization with respect to the secure testing phase of the SDLC. The participants of the case studies also agreed that the proposed MMSST is useful in terms of structure, user satisfaction, and ease of use. We believe that the proposed MMSST can help organizations evaluate and improve software security testing practices. In addition, the proposed MMSST is expected to provide researchers and industry practitioners with an effective foundation for developing new secure testing approaches and tools. Gulzar Alam, Sajjad Mahmood, Mohammad R. Alshayeb, Mahmood Niazi, Saad Zafar |
J. Softw. Evol. Process. | 2 |
| 2024 | DevOps project management success factors: A decision-making frameworkabstractAbstract Development and operations (DevOps) refer to the collaboration and multidisciplinary organizational effort to automate continuous delivery of information systems (IS) development project with an aim to improve the quality of the IS. The flexibility and quality production of software projects motivated the organizations to adopt DevOps paradigm. Organizations face several complexities while management of DevOps process. This study aims to explore and analyze the factors that could positively impact the management of DevOps process. Firstly, literature review was performed and identified 36 success factors that are related to 10 knowledge areas of DevOps project management. Secondly, a questionnaire survey study was conducted to get the insight of industry experts concerning the success factors of DevOps project. Finally, the fuzzy‐AHP was applied for ranking the success factors and examining the relationship between 10 knowledge areas of identified success factors. The results of this study will serve as a body of knowledge for researchers and practitioners to consider the highest priority success factors and develop the effective policies for the successful execution of DevOps project management. Muhammad Azeem Akbar, Arif Ali Khan, A. K. M. Najmul Islam, Sajjad Mahmood |
Softw. Pract. Exp. | 4 |
| 2024 | Trustworthy artificial intelligence: A decision-making taxonomy of potential challengesabstractAbstract The significance of artificial intelligence (AI) trustworthiness lies in its potential impacts on society. AI revolutionizes various industries and improves social life, but it also brings ethical harm. However, the challenging factors of AI trustworthiness are still being debated. This research explores the challenging factors and their priorities to be considered in the software process improvement (SPI) manifesto for developing a trustworthy AI system. The multivocal literature review (MLR) and questionnaire‐based survey approaches are used to identify the challenging factors from state‐of‐the‐art literature and industry. Prioritization based taxonomy of the challenges is developed, which reveals that lack of responsible and accountable ethical AI leaders, lack of ethics audits, moral deskilling & debility, lack of inclusivity in AI multistakeholder governance, and lack of scale training programs to sensitize the workforce on ethical issues are the top‐ranked challenging factors to be considered in SPI manifesto. This study's findings suggest revising AI‐based development techniques and strategies, particularly focusing on trustworthiness. In addition, the results of this study encourage further research to support the development and quality assessment of ethics‐aware AI systems. Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood, Saima Rafi, Selina Demi |
Softw. Pract. Exp. | 3 |
| 2024 | Organizations' readiness for insider attacks: A process-oriented approachabstractAbstract Context Organizations constantly strive to protect their assets from outsider attacks by implementing various security controls, such as data encryption algorithms, intrusion detection software, firewalls, and antivirus programs. Unfortunately, attackers strike not only from outside the organization but also from within. Such internal attacks are called insider attacks or threats, and the people responsible for them are insider attackers or insider threat agents. Insider attacks pose more significant risks and can result in greater organizational losses than outsider attacks. Thus, every organization should be vigilant regarding such attackers to protect its valuable resources from harm. Finding solutions to protect organizations from such attacks is critical. Despite the importance of this topic, little research has been conducted on providing solutions to mitigate insider attacks. Objective This study aims to develop an organizational readiness model to assess an organization's readiness for insider attacks. Method We conducted a multivocal literature review to identify practices that can be used to assess organizations' readiness against insider attacks. These practices were grouped into different knowledge areas of insider attacks for organizations. The insider attack readiness model was developed using identified best practices and knowledge areas: compliance, top management, human resources, and technical. Results This model was evaluated at two levels—academic and real‐world environments. The evaluation results show that the proposed model can identify organizations' readiness against insider attacks. Conclusion The proposed model can guide organizations through a secure environment against insider attacks. Azzah A. Alghamdi, Mahmood Niazi, Mohammad R. Alshayeb, Sajjad Mahmood |
Softw. Pract. Exp. | 4 |
| 2023 | Towards a successful secure software acquisition
Faisal Alnaseef, Mahmood Niazi, Sajjad Mahmood, Mohammad R. Alshayeb, Irfan Ahmad 0001 |
Inf. Softw. Technol. | 3 |
| 2023 | Toward a readiness model for secure software codingabstractAbstract The heart of the application's secure operation is its software code. If the code contains flaws, the entire program might be hacked. The issue with software vulnerabilities is that they reveal coding flaws that hackers could exploit. The prevention of cybersecurity issues begins with the program code itself. When writing software code, a software developer must consider expressing the application's architecture and design requirements, keeping the code streamlined and efficient, and ensuring the code is safe. Secure code helps save the system from various cyber‐attacks by eliminating the weaknesses that many hacks rely on. To assist the software organization in Secure Software Coding (SSC), this article proposes a readiness model for SSC, namely SSCRM. The proposed model has five levels; SSC challenges and best practices (BP) are mapped at each level. The proposed model will help the organizations better understand SSC challenges and BPs and provide a roadmap for developing secure software code. The proposed model was evaluated using three case studies. The findings demonstrate that the proposed approach helps determine an organization's SSC level. Mamoona Humayun, Mahmood Niazi, N. Z. Jhanjhi, Sajjad Mahmood, Mohammad R. Alshayeb |
Softw. Pract. Exp. | 4 |
| 2022 | Toward Effective and Efficient DevOps using BlockchainabstractRecently, blockchain and DevOps have received attention from the software industry as both offer number of benefits individually. Automation, measurement, and sharing are the core pillars of DevOps, and to securely manage these; blockchain can play an important role. This study aims to understand the role of blockchain technology in the DevOps paradigm. This study presents factors that influence the adoption of blockchain in DevOps. Furthermore, this study suggests a framework that assists in merging the characteristics of blockchain in the DevOps paradigm. The findings of this study give a knowledge base for industry experts and the research community to develop the roadmap and guidelines for the adoption of blockchain in the DevOps paradigm. Muhammad Azeem Akbar, Sajjad Mahmood, Dominik Siemon |
EASE | 2 |
| 2022 | Toward successful DevSecOps in software development organizations: A decision-making frameworkabstractDevelopment and Operations (DevOps) is a methodology that aims to establish collaboration between programmers and operators to automate the continuous delivery of new software to reduce the development life cycle and produce quality software. Development, Security, and Operations (DevSecOps) is developing the DevOps concept, which integrates security methods into a DevOps process. DevSecOps is a software development process where security is built in to ensure application confidentiality, integrity, and availability. This paper aims to identify and prioritize the challenges associated with implementing the DevSecOps process. We performed a multivocal literature review (MLR) and conducted a questionnaire-based survey to identify challenges associated with DevSecOps-based projects. Moreover, interpretive structure modeling (ISM) was applied to study the relationships among the core categories of the challenges. Finally, we used the fuzzy technique for order preference by similarity to an ideal solution (TOPSIS) to prioritize the identified challenges associated with DevSecOps projects. We identified 18 challenges for the DevSecOps process and mapped them to 10 core categories. The ISM results indicate that the “standards” category has the most decisive influence on the other nine core categories of the identified challenges. Moreover, the fuzzy TOPSIS indicates that “lack of secure coding standards,” “lack of automated testing tools for security in DevOps,” and “ignorance in static testing for security due to lack of knowledge” are the highest priority challenges for the DevSecOps paradigm. Organizations using DevOps should consider the identified challenges in developing secure software. Muhammad Azeem Akbar, Kari Smolander, Sajjad Mahmood, Ahmed Alsanad |
Inf. Softw. Technol. | 3 |
| 2022 | An end-to-end deep learning system for requirements classification using recurrent neural networks
Osamah AlDhafer, Irfan Ahmad 0001, Sajjad Mahmood |
Inf. Softw. Technol. | 3 |
| 2022 | Barriers of managing cloud outsource software development projects: a multivocal study
Muhammad Azeem Akbar, Sajjad Mahmood, Chandrashekhar Meshram, Ahmed Alsanad, Abdu Gumaei, Salman AlQahtani |
Multim. Tools Appl. | 2 |
| 2022 | Towards roadmap to implement blockchain in healthcare systems based on a maturity modelabstractAbstract Healthcare systems face various issues related to complex networks of intermediaries and a lack of transaction traceability. The most critical issues are the fragmentation of healthcare data, obstacles in providing efficient research and services, lack of clinical trial reporting, high cost and mismanagement of the drug supply chain, patient data security, and fake drugs. Blockchain technology has the potential to address these criticalities as it has in build traceability mechanisms and promises new business models by enabling incentive structures. This potential of blockchain gathers a high interest in the health industry. However, the implementation of blockchain in healthcare faces various issues as well. Currently, there are no practice‐oriented maturity models to improve such an implementation. In this paper, we present a roadmap to develop a maturity model for blockchain in healthcare (MMBH) based on critical barriers (CBs), critical success factors (CSFs), and the best practices for blockchain implementation in healthcare systems. As a first step to develop the MMBH, in this paper, we present the initial results of a systematic literature review (SLR) to identify critical success factors for implementing blockchain in healthcare systems. We also applied fuzzy technique order preference by similarity to ideal solution (TOPSIS) to prioritize the identified CSFs. Muhammad Azeem Akbar, Víctor Leiva, Saima Rafi, Syed Furqan Qadri, Sajjad Mahmood, Ahmed Alsanad |
J. Softw. Evol. Process. | 5 |
| 2022 | Selection of DevOps best test practices: A hybrid approach using ISM and fuzzy TOPSIS analysisabstractAbstract Testing is a complex phase in DevOps process due to need of an automated process that provides feedback at different strategies of continuous development and operations pipeline. Software organization face several challenges during the testing phase due to lack of understanding on testing best practices for the DevOps paradigm. The objective of this study is to prioritize DevOps best testing practices, which can facilitate the selection of testing practices during DevOps process. To perform this research, we have extended the work done by Hornbeek, using the 15 DevOps testing practices discussed in his study. First, we categorize the test practices against culture, automation, lean, measurement, and sharing (CALMS) pillars of DevOps adoption principles. Next, a questionnaire‐based survey was conducted to collect feedback from industry practitioners on the DevOps test practices and their categorization against CALMS criteria. Finally, we applied Interpretive Structure Modeling (ISM) to find the interrelationship between CALMS criteria, and fuzzy TOPSIS was used to prioritize the DevOps test practices that will assist practitioners to better manage the testing activities during DevOps process. Saima Rafi, Muhammad Azeem Akbar, Sajjad Mahmood, Ahmed Alsanad, Abdulrahman Alothaim |
J. Softw. Evol. Process. | 3 |
| 2021 | Prioritization of global software requirements' engineering barriers: An analytical hierarchy processabstractAbstract Software industry is adopting global software development (GSD) due to its potential to produce quality products at a lower cost. However, the GSD firms face many challenges that make development activities more complicated, especially related to the requirements engineering (RE) process. The objectives of this article are to investigate and prioritize the barriers faced by the GSD organizations during the RE process. First, we identified 17 barriers related to the RE process in the GSD projects. Next, the identified barriers were further validated with real‐world GSD practitioners using a questionnaire survey. Finally, we applied the analytical hierarchy process to prioritize the investigated barriers with respect to their significance for the RE process in the GSD domain. The results show that coordination is the most significant barrier category for the RE process in GSD projects. Lack of standard and procedure for RE in GSD, lack of synchronized communication infrastructure, and lack of mutual understanding between the overseas RE teams are also high‐ranked barriers for the RE process in GSD. The authors believe that the findings of this study will assist practitioners and researchers in developing effective strategies and plans for the successful implementation of the RE process in the GSD context. Muhammad Azeem Akbar, Wishal Naveed, Sajjad Mahmood, Saima Rafi, Ahmed Alsanad, Abeer Abdul-Aziz Alsanad, Abdu Gumaei, Abdulrahman Alothaim |
IET Softw. | 3 |
| 2021 | A robust framework for cloud-based software development outsourcing factors using analytical hierarchy processabstractAbstract Managing the cloud‐based software development outsourcing (CSDO) activities across the geographically distributed development sites are much challenging. This study aims to identify the success factors (SFs) for CSDO and prioritize them based on their significance. To achieve this objective, we conducted a systematic literature review (SLR) and survey study with industrial and academic experts. Finally, we applied the analytical hierarchy process (AHP) to develop the framework based on the prioritization of the identified SFs. We believe that the findings of this study will assist the industry practitioners and researchers in developing effective strategies for the successful implementation of CSDO activities. Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood, Ahmed Alsanad, Abdu Gumaei |
J. Softw. Evol. Process. | 3 |
| 2021 | Readiness model for DevOps implementation in software organizationsabstractAbstract DevOps is a new software engineering paradigm adopted by various software organizations to develop the quality software within time and budget. The implementation of DevOps practices is critical, and there are no guidelines to assess and improve the DevOps activities in software organizations. Hence, there is a need to develop a readiness model for DevOps (RMDevOps) with an aim to assist the practitioners for implementation of DevOps practices in software firms. To achieve the study objective, we conducted a systematic literature review (SLR) study to identify the critical challenges and associated best practices of DevOps. A total of 18 challenges and 73 best practices were identified from the 69 primary studies. The identified challenges and best practices were further evaluated by conducting a survey with industry practitioners. The RMDevOps was developed based on other well‐established models in software engineering domain, for example, software process improvement readiness model (SPIRM) and software outsourcing vendor readiness model (SOVRM). Finally, case studies were conducted with three different organizations with an aim to validate the developed model. The results show that the RMDevOps is effective to assess and improve the DevOps practices in software organizations. Saima Rafi, Yu Wu 0001, Muhammad Azeem Akbar, Sajjad Mahmood, Ahmed Alsanad, Abdu Gumaei |
J. Softw. Evol. Process. | 4 |
| 2020 | A maturity model for secure requirements engineering
Mahmood Niazi, Ashraf Mohammed Saeed, Mohammad R. Alshayeb, Sajjad Mahmood, Saad Zafar |
Comput. Secur. | 4 |
| 2020 | Factors influencing the requirements engineering process in offshore software development outsourcing environmentsabstractOffshore software development outsourcing (OSDO) is one of the popular development paradigms in the software industry. There are a number of challenges associated with OSDO including the challenges related to requirements engineering (RE) process. The objective of this study is to identify success factors (SFs) associated with RE processes in the OSDO context. A total of 25 SFs were identified using systematic literature review (SLR) and the identified SFs were further validated with practitioners using a questionnaire-based survey. The authors also examined the identified RE challenges with respect to their relevance for different organisation types (client and vendor) and sizes (small, medium, and large) with an aim to provide a clear understanding of the RE process and its SFs in the context of various OSDO organisations. They also conducted a comparative analysis between the SLR and questionnaire findings and the results indicate that there is a moderately positive correlation between the data sets. They believe that the findings of this study will provide a comprehensive model to help OSDO organisations assess and improve the effectiveness and efficiency of their RE activities. Muhammad Shafiq 0006, Qinghua Zhang 0001, Muhammad Azeem Akbar, Ahmed Alsanad, Sajjad Mahmood |
IET Softw. | 5 |
| 2020 | Requirement change management challenges in GSD: An analytical hierarchy process approachabstractAbstract Majority of software development firms are adopting the concepts of global software development (GSD) in order to develop high‐quality and low‐cost products. However, the requirements change management (RCM) becomes a significant challenge in the GSD environment because of the unavailability of proper RCM framework and taxonomy. The objective of this study is to develop a taxonomy of the challenging factors of the RCM process in GSD. The taxonomy is developed based on the results of the data collected during the survey study and the implementation of the analytical hierarchy process (AHP). Total 25 challenging factors are identified and mapped into four core categories, ie, “organizational management,” “team,” “technology,” and “process.” Moreover, the AHP analysis is performed to prioritize the challenging factors and their categories. The prioritization process highlight that “process” is the most significant category of the RCM challenging factors. The taxonomy developed in this study provides a robust framework to tackle problems associated with RCM activities in GSD environment, which is significant to the success and progression of GSD firms. Muhammad Azeem Akbar, Arif Ali Khan, Abdul Wahid Khan, Sajjad Mahmood |
J. Softw. Evol. Process. | 4 |
| 2020 | A multivocal study to improve the implementation of global requirements change management process: A client-vendor prospectiveabstractAbstract Software development is a complex task, and the introduction of multi‐site development teams spread across the globe makes it even harder. Requirement changes during the software development process are inevitable, and failing to manage evolving requirements is one of the contributors to project failures. Requirements change management (RCM) becomes difficult in global software development (GSD) projects due to the need to communicate and coordinate between stakeholders in a distributed environment. This research work aims to identify the factors that have positive impacts on RCM activities in GSD. We conducted a multi‐vocal literature review (MLR) and a questionnaire survey study to identify the RCM success factors. The results of the t‐test (ie, t = 0.0347 and P = .700 > .05) and correlation (rs (25) = 0.573, P = .003) indicates that there is no significant difference between the findings of MLR and the questionnaire survey. The identified factors were further analyzed in the context of client and vendor organizations to better understand the RCM success factors in both types of GSD firms. The findings of this study can provide a useful framework for tackling problems associated with RCM in a GSD environment that is significant to the progression of GSD firms. Muhammad Azeem Akbar, Sajjad Mahmood, Ahmed Alsanad, Abeer Abdul-Aziz Alsanad, Abdu Gumaei, Syed Furqan Qadri |
J. Softw. Evol. Process. | 2 |
| 2020 | Readiness model for requirements change management in global software developmentabstractAbstract Requirements Change Management (RCM) is one of the challenges faced by Global Software Development (GSD) organisations as requirements evolution is inevitable due to dynamic business and operating environments. GSD organisations face issues when dealing with RCM because many organisations embark on GSD without understanding their readiness to undertake such an initiative. Currently, there is no readiness model to assess the RCM process in the context of GSD. The objective of this study is to develop a requirements change management readiness model (RCMRM) for GSD organisations. A Systematic Mapping Study (SMS) was conducted to identify the primary studies related to RCM in the GSD projects. By using SMS, 109 primary studies were selected and 73 RCM practices were identified which were used to design the readiness levels of the proposed RCMRM. To validate the RCMRM, initially, two case studies were conducted in two GSD organisations. Based on the suggestions and recommendations of the case study participants,the RCMRM was further modified. The updated version of RCMRM was further validated by two different GSD organisations. The results of the second case study indicate that RCMRM is effective in assessing the readiness of the RCM process in the context of GSD. Muhammad Azeem Akbar, Sajjad Mahmood, Arif Ali Khan, Mohammad Shameem |
J. Softw. Evol. Process. | 2 |
| 2020 | GLOB: A global project management readiness frameworkabstractAbstract In global software development (GSD), software is developed by a team of geographically dispersed people. Many organizations that develop projects globally do not evaluate their project management readiness to undertake such projects. The objective of this paper is to propose a global project management readiness framework (GLOB) to help organizations in evaluating and assessing their GSD project management readiness to improve their capabilities in managing GSD projects. To develop GLOB, three systematic literature reviews (SLRs) were conducted. For each SLR, an empirical study was conducted with GSD practitioners to validate the SLR results in a real‐world environment. We identified 45 factors that can play a positive or negative role in global project management readiness. In total, 305 best practices were identified for global project management. Based on the findings of the SLRs and empirical studies, GLOB was developed. Two case studies were conducted to evaluate GLOB in a real‐world context. The case study results show that GLOB has the potential to measure an organization's project management readiness for global projects. It is hoped that GLOB will provide GSD practitioners with the ability to understand the strengths and weaknesses of current project management processes and to address weak areas. Mahmood Niazi, Sajjad Mahmood, Mohammad R. Alshayeb |
J. Softw. Evol. Process. | 2 |
| 2019 | Package-Level stability evaluation of object-oriented systems
Jawad Javed Akbar Baig, Sajjad Mahmood, Mohammad R. Alshayeb, Mahmood Niazi |
Inf. Softw. Technol. | 2 |
| 2019 | A survey on UML model smells detection techniques for software refactoringabstractAbstract Bad smells tend to have a negative impact on software by degrading its quality. It is beneficial to detect model smells to avoid their propagation to later stages of software development. The objective of this paper is to present the state‐of‐the‐art research on techniques for detecting UML model bad smells. The detection techniques are compared and evaluated using a proposed evaluation framework. The framework consists of two parts. The first part of the framework compares the techniques in terms of the implemented approach, the investigated model, and the explored model smells, while the experimental design is explored in the second part of the framework. We found that the detection of bad smells in class and sequence diagrams is accomplished via design patterns, software metrics, and predefined rules, while model smells in use cases are detected using metrics and predefined rules. We also found that the class diagram is the most investigated UML model in the context of model smell detection, whereas there is a lack of work on other UML models. In addition, there is a scarcity of independent studies on sequence diagrams. Furthermore, the studies investigating class diagrams are mostly validated, whereas use case diagrams and sequence diagrams are rarely validated. Haris Mumtaz, Mohammad R. Alshayeb, Sajjad Mahmood, Mahmood Niazi |
J. Softw. Evol. Process. | 3 |
| 2018 | An empirical study to improve software security through the application of code refactoring
Haris Mumtaz, Mohammad R. Alshayeb, Sajjad Mahmood, Mahmood Niazi |
Inf. Softw. Technol. | 3 |
| 2017 | Key factors that influence task allocation in global software development
Sajjad Mahmood, Sajid Anwer, Mahmood Niazi, Mohammad R. Alshayeb, Ita Richardson |
Inf. Softw. Technol. | 1 |
| 2017 | Motivators for adopting social computing in global software development: An empirical studyabstractManaging communication in collaborative global software development (GSD) projects is both critical and challenging. While social computing has received much attention from practitioners, social computing adoption is still an emerging research area in GSD. This research paper provides a review of the academic research in social computing and identifies motivators for adopting social computing in the GSD context. We applied the systematic literature review (SLR) and questionnaire survey with 35 software industry experts to address the research objective. Firstly, we implemented a formal SLR approach and identified an initial set of social computing adoption motivators. Secondly, a questionnaire survey was developed based on the SLR and was tested by means of a pilot study. The findings of this combined SLR and questionnaire survey indicate that real-time communication and coordination, knowledge acquisition, expert feedback, and information sharing are the key factors that motivate social computing adoption in GSD projects. The results of t test (ie, t = .558, P = .589) show that there is no significant difference between the findings of SLR and questionnaire. The results of this study suggest the need for developing social computing strategies and policies to guide the strategic adoption of social computing tools in GSD projects. Mahmood Niazi, Sajjad Mahmood, Mohammad R. Alshayeb, Abdulrahman Baqais, Asif Gill |
J. Softw. Evol. Process. | 2 |
| 2016 | Challenges of project management in global software development: A client-vendor analysis
Mahmood Niazi, Sajjad Mahmood, Mohammad R. Alshayeb, Mohammed Rehan Riaz, Kanaan Faisal, Narciso Cerpa, Siffat Ullah Khan, Ita Richardson |
Inf. Softw. Technol. | 2 |
| 2016 | A framework for an integrated unified modeling languageabstractThe unified modeling language (UML) is one of the most commonly used modeling languages in the software industry. It simplifies the complex process of design by providing a set of graphical notations, which helps express the objectoriented analysis and design of software projects. Although UML is applicable to different types of systems, domains, methods, and processes, it cannot express certain problem domain needs. Therefore, many extensions to UML have been proposed. In this paper, we propose a framework for integrating the UML extensions and then use the framework to propose an integrated unified modeling language-graphical (iUML-g) form. iUML-g integrates the existing UML extensions into one integrated form. This includes an integrated diagram for UML class, sequence, and use case diagrams. The proposed approach is evaluated using a case study. The proposed iUML-g is capable of modeling systems that use different domains. Mohammad R. Alshayeb, Nasser Khashan, Sajjad Mahmood |
Frontiers Inf. Technol. Electron. Eng. | 3 |
| 2015 | Identifying the factors that influence task allocation in global software development: preliminary resultsabstractOver the last decade, an increasing number of organizations have started software development in a globally distributed environment. One of the major challenges is that many organizations endorse the process of global software development without testing their management readiness for the globally distributed development activity. This includes work distribution through task allocation in the globally distributed development environment. The objective of this research paper is to identify factors that influence task allocation in global software development through carrying out a systematic literature review. We used customized search terms, derived from our research question, to identify literature on work distribution and task allocation in a global context. We identified criteria such as site technical expertise, time zone difference, resource cost, task dependency, vendor reliability, task size and vendor maturity level as key task allocation factors in globally distributed software projects. Based on the systematic literature review results, we suggest that there is a need to develop work distribution strategies and standards through global task allocation to help software development organizations in achieving the true potential of global software development at lower development costs and shorter time-to-market. Sajjad Mahmood, Sajid Anwer, Mahmood Niazi, Mohammad R. Alshayeb, Ita Richardson |
EASE | 1 |
| 2013 | Reuse environments for software artifacts: Analysis frameworkabstractSystematic software reuse facilitates achieving quality software, faster and at a lower cost. Software reuse environments play an important role in exploiting reusable artifacts to the extent. Environments that support reusing early-stage software artifacts are of great interest. There have been a number of reuse environments proposed in the literature for reuse of software artifacts. However, there is no framework to allow analyzing (i.e. classifying and comparing) reuse environments. The significance of such a framework is twofold: (1) to be used by reuse practitioners to select appropriate environment; and (2) to be used by researchers to identify gaps for future research. In this paper, we present an attribute-based framework to provide such aid to practitioners and researchers. The paper also presents an indicative survey of current reuse environments proposed for systematic reuse of software artifacts. We use the framework to analyze those reuse environments. The analysis provides an understanding of current systematic reuse approaches and respective reuse environments; and identifies corresponding shortcomings. Consequently, we post research questions for future work. Sajjad Mahmood, Moataz A. Ahmed, Mohammad R. Alshayeb |
ICIS | 1 |
| 2013 | Software Requirements Elicitation - A Controlled Experiment to Measure the Impact of a Native Natural LanguageabstractSoftware development is a collaborative activity where the quality of the end product depends to a great extent on the quality of the requirements engineering process. This paper examines the impact of multi-natural language backgrounds (English and Arabic) of the requirements engineers on the quality and correctness of the use case modeling. The study is done through a controlled experiment. The results show that using a native language for system description improves the functional correctness of the use case model. However, the time required to perform use case modeling and the quality of use case diagrams is not affected by using either native or English (as a second language). Sajjad Mahmood, Samuel Ajila |
COMPSAC | 1 |
| 2013 | RE-UML: A Component-Based System Requirements Analysis LanguageabstractRequirements analysis and component selection is widely recognized as an interrelated process that plays a central role in overall component-based system (CBS) development. Fundamental to the success of CBS is a requirement analysis model in which both stakeholders and candidate components balance the conflicting interests between what is needed and what is available. The effectiveness of CBS relies heavily on a system analyst's expertise to select suitable components. Owing to the lack of a language that could describe component alternatives with respect to stakeholder requirements, there is a need to develop one to describe CBS requirement analysis. In this paper, we present an extension to unified modelling language (UML) named RE-UML with a formal semantics utilizing Prolog programming language to support CBS requirements analysis. It helps balance the conflicts between what is required for a CBS-to-be and what features are supported by candidate components. RE-UML extends the UML sequence diagrams with a satisfaction interaction frame and mapping operators to model matching criteria between stakeholder demands and candidate component features. Further, associations between requirements and candidate components are introduced to model risk assessment and conflict resolutions during CBS requirements analysis. To demonstrate the usefulness of RE-UML, its application to the Seven-Eleven Japan software system is also presented. Sajjad Mahmood, Richard Lai 0001 |
Comput. J. | 1 |
| 2011 | An industrial study on the importance of software component documentation: A system integratorʼs perspective
Sajjad Mahmood, Azhar Khan |
Inf. Process. Lett. | 1 |
| 2008 | A complexity measure for UML component-based system specificationabstractAbstract A component‐based system (CBS) is integration centric with a focus on assembling individual components to build a software system. In CBS, component source code information is usually unavailable. Each component also introduces added properties such as constraints associated with its use, interactions with other components and customizability properties. Recent research suggests that most faults are found in only a few system components. A complexity measure at a specification phase can identify these components. However, traditional complexity metrics are not adequate for a CBS as they focus mainly on either lines of code (LOC) or information based on object and class properties. There is therefore a need to develop a new technique for measuring the complexity of a CBS specification (CBSS). This paper describes a structural complexity measure for a CBSS written in Unified Modelling Language (UML) from a system analyst's point of view. A CBSS consists of individual component descriptions characterized by its syntactic, semantic and interaction properties. We identify three factors, interface, constraints and interaction, as primary contributors to the complexity of a CBSS. We also present an application of our technique to a university course registration system. Copyright © 2006 John Wiley & Sons, Ltd. Sajjad Mahmood, Richard Lai 0001 |
Softw. Pract. Exp. | 1 |
| 2005 | A survey of component based system quality assurance and assessment
Sajjad Mahmood, Richard Lai 0001, Yong-Soo Kim, Ji Hong Kim, Seok Cheon Park, Hae Suk Oh |
Inf. Softw. Technol. | 1 |