Section outline
-
Lesson 5. Introduction to Software Certification and Conformity Assessment: Regulatory Frameworks, Types of Certification, and Engineering Basis
Objective: formation of students' complex of knowledge, legal literacy and practical engineering and auditing skills in the field of conformity assessment and software certification in accordance with international and national regulatory frameworks. The student must master the concept of conformity assessment, the legal status of certification, its importance for software legalization, distribution of responsibility and admission to tenders. In the process of learning, special attention is paid to understanding and comparative analysis of legislative forms of certification (mandatory/regulatory for safety-critical systems and voluntary/market), as well as the systemic classification of certification schemes according to the ISO/IEC 17067 standard (product certification according to ISO 25010, process certification according to ISO 12207/CMMI and certification of quality management systems according to ISO 9001). Students should learn to clearly distinguish the conceptual differences between verification ("are we building the product correctly?") and validation ("are we building the right product?"), master methods of static and dynamic code analysis, and acquire practical skills in forming an evidence base for certification through the creation and audit of a structured package of software lifecycle engineering artifacts (SRS according to ISO 29148, SAD according to ISO 42010, CMP according to ISO 82890, V&V reports according to ISO 29119, and RTM traceability matrix) to ensure transparency, security, and successful receipt of legally significant certificates of conformity.