Ten questions to test whether code reading fits your problem.
Answer ten questions about the systems, evidence and change in front of you. The result says whether code reading fits, what it would need, or why it is the wrong tool.
There are ten questions, and one bounded result is assembled from the answers you select.
The result can fit, name what is needed, or say which tool fits instead.
Scripts off? Every question and each possible reading is set out below as a document.
Scripts are off in this browser, which is fine.
Answer on paper or in your head, then find your reading below: the rule
for finding it is written at the top of the readings.
01
The questions
02
The reading
Nothing you select leaves this page.
The mail carries this reading, word for word, in
your own mail client. Nothing is sent by this page.
The reading is composed on this page, from your
answers and nothing else. Change an answer and press the button again,
and it recomposes.
03Your reading
The reading
Composed from your ten answers, on this page
03The readings
The readings, in full
Scripts compose one of these three short readings from your answers.
All three are visible here when scripts are unavailable.
Your answers point to a code-reading problem.
The auditor's request
A source reading establishes a dated path from figure to producing code.
The dependency map under CPS 230
Named source tests the dependency map against the code itself.
The change with an unknown affected set
A pre-release source reading names each path the change can reach.
The system being moved
Named source versions support comparison before and after cutover.
The systems changing hands
Supplied source is read before signing, and the rest becomes a named post-close item.
The person leaving
Source can be read while the expert can still disagree with it.
Forming a view
The review covers source-linked results and their stated assumptions.
What a first pass covers
A first pass takes one question and one system's source, and the result sets the next step.
The vendor products in your path
The reading covers what you supply and names the vendor source it
was not given.
What a reading gives a model
It is given the record, in which a reading has established from the
source what depends on what, graded each relationship by the
evidence the code could give, and refused where the evidence runs
out while keeping the reason. No model is involved in producing it.
A model holding the record has the map as the code established it,
with the grade on each relationship and the refusals with their
reasons, and without it the model infers those relationships from
names and documentation. What the model
does with the record, and whether it is fit to be put over these
systems, stays with your team and its risk function.
What to do next
The next step is one question and its source.
Your answers say the evidence you already hold is enough, for now.
Answer it with what you hold
Your current evidence appears sufficient, and the measure to retain
is its production time.
Departure, on your answers
Your documents appear to carry the system map, so the handover can
retain judgement and compare them with source.
A view, formed
Your logic is readable and your evidence is current, and a change to
either is the point to reassess.
The standard to hold it to as it grows
The standard is source-linked evidence, with any unread part
named as such.
What to do next
The evidence you already hold is the right answer for now.
Your answers say code reading is the wrong tool for this problem.
Where the source sits decides it
The relevant source sits with the vendor, so code reading is the wrong
tool for that part, and the vendor process is right.
The shape of answer that fits
Vendor evidence covers the product, and a separate assessment fits the
configuration and integration code whose source you hold.
If some of that source is yours
Assess that part separately when its source is supplied.