Monday, January 30, 2017

ISTQB Advanced Security Tester Certification Training - March 7 - 10, Irving, TX

I am excited to announce the first public course in the USA (and perhaps the world) for the ISTQB Advanced Security Tester Certification. This course will be held March 7 - 10, 2017 in Irving, Texas.

With cyber attacks occurring daily, most businesses and government agencies are under constant cyber attack. Unfortunately, many organizations are not doing enough to defend their physical and digital assets. Even more concerning is that while some organizations have firewalls, intrusion detection systems and other defenses, few of those organizations regularly test their defenses to determine their effectiveness.

In this course, you will learn a complete framework for testing security, regardless of the technology involved. This course and certification covers much more than just penetration testing. Certainly, penetration testing is an important part of security testing, but there are many other threats and vulnerabilities that require other security testing approaches.

Who Should Attend?

This course is for:
  • Software testers that hold the ISTQB Certified Tester, Foundation Level (CTFL) and want to expand their knowledge of security testing, 
  • Security testers who hold the CTFL and wish to obtain an advanced certification to solidify their knowledge, 
  • Security administrators who want to learn more about how to test the security defenses in their organization, and 
  • Anyone who wants to learn more about security testing but do not necessarily want to take the CTAL-SEC exam.

What You Need to Know:

1. This course follows the ISTQB Advanced Security Tester Syllabus and is written and presented by Randall W. Rice, chair of the ISTQB Advanced Security Tester Syllabus Working Group and holder of the CTAL-SEC, as well as all three ISTQB Core Advanced Certifications.

2. Anyone may attend this training, but to sit for the ISTQB Advanced Security Tester exam, you must hold the ISTQB Certified Tester, Foundation Level (CTFL) designation (or equivalent) and have 3+ years of software testing and related experience. Basic security and security testing concepts are assumed knowledge.

3. The course is four full days in length. No exam will be administered during the class, but attendees that meet pre-requisites will receive a voucher to take the exam at a Kryterion Exam Center. http://www.kryteriononline.com/Locate-Test-Center

4. This is an intense, advanced level course with 28 exercises that cover all K3 and K4 learning objectives.

5. The venue is the Holiday Inn Express in Irving, Texas. The hotel is very close to the DFW airport for those who plan to travel to the course. The address is 4235 W. Airport Freeway, Irving, TX 75062. It is your responsibility to book your own hotel room.

6. Light breakfast and lunches are included.

7. A remote attendee option is available.

8. The cost is $2,795 (exam included) for in-person attendees and $2,295 for remote attendees. There is a 10% discount for groups of 3 or more people.

9. The course program and details can be seen here: http://www.riceconsulting.com/home/index.php/ISTQB-Training-for-Software-Tester-Certification/istqb-advanced-security-tester-course.html

10. To register, please visit https://www.mysoftwaretesting.com/ISTQB_Adv_Security_Tester_Certification_Course_p/secdfw.htm

If you have any questions, please contact me at 405-691-8075 or from the contact form at http://www.riceconsulting.com.

I hope to see you at this event!

Thanks,

Randy

Tuesday, December 06, 2016

Ten Ways to Build Your Software Testing Skills

As a software testing and QA consultant over the past 27 years, I have worked with hundreds of organizations and tens of thousands of testers. Over that time, I have observed two types of people – those that see software testing as a job and those that see software testing as a career.

Those that see testing as a career typically advance in their jobs and have a higher level of self-esteem. Those that see testing as only as a job, often get bored and complain about the lack of opportunities. The “job only” perspective also indicates that someone is only in the testing role for a limited time. Therefore, there is little incentive to invest in personal improvement.

Of course, not everyone is cut out for software testing. The role can be frustrating at times, especially when the tester is blamed for the defects they report. I jokingly say that software testing conferences are like mass group therapy for software testers and test managers. It is interesting to see the realization of people when they see that they are not the only ones with unrealistic project managers, difficult end-users, technologies that are difficult to test, and oh, that automation stuff looks so easy but it can be so difficult to implement.

I know that I am around professional testers when vigorous (not vicious) debate breaks out over seemingly minor differences in test philosophies, approaches and techniques. It shows that people have thought a lot about the ideas they are defending or opposing.

If you see software testing as a profession instead of a job, then it’s up to you to grow. The greatest mistake you can make is to stop learning and growing. For those that see software testing and QA (yes, there is a difference) as a professional career choice, here are some ways to grow your career.

1. Set growth goals for the coming year. These don’t have to be huge goals, but without these goals it’s easy to lose focus. Goals also paint the target. You know when you have hit them. Here are some examples:

Learn how to apply a test technique that is unfamiliar to you
Develop a specialty area of security testing
Learn how to use a particular test tool
Read three books about testing or some related (or even unrelated) topic
Obtain a certification in testing or a related field
Speak at a conference
Write an article

2. Read one or more books on software testing or related topics. It is amazing to me how few people read books that relate to the testing and software development professions. You have more choices than ever before with hundreds of testing books on the market. Perhaps the greater challenge is to find the books that are worthy of your time. By the way, some of the best books are also the oldest books that are available for $5 - $10 from online used booksellers such as www.abebooks.com. Two of my top recommendations are “The Art of Software Testing, 1st Ed.” By Glenford Myers and “Software Testing Techniques, 2nd Ed.” by Boris Beizer. These are foundational books in software testing, written over 30 years. However, don’t dismiss them due to age. These books are good for any tester to read. The Beizer book has a technical focus that would serve any tester well in today’s world of testing.

3. Take a training course that aligns with your goals. Even an online course is an easy reach in terms of time and cost. It is amazing what a little training can do. While good training typically will cost money, there are free and inexpensive online courses available. I have over twenty-three e-Learning courses at www.mysofwaretesting.com.

4. Create content. If you really want to learn and grow, then develop a small course, write a major article or start a blog. This not only stretches your abilities, but provides exposure as well. I never thought back in 1989 when I wrote my first testing course (unit testing) that one day I would be able to say I’ve personally written over 70 courses! I never thought I would write two books (and working on five others). And… I’m not saying that is where you will arrive. But the thing I can say is that I learn ten times more creating a class than attending a class. As the saying goes, “The best way to learn is to teach.”

5. Find a coach or mentor. Then, meet with them often enough to glean their wisdom. I know it’s hard sometimes to find the right person to mentor you, but they are out there. Look for people with lots of experience in what you want to do. Ask questions and listen. The trick on this one is that you must take the initiative to seek out the mentoring relationship.

6. Coach or mentor someone yourself. This is where you get to repay your coach or mentor. You learn by listening to the person you are mentoring. I have mentored many people and I learn by dealing with the tough questions they bring me. Admittedly, some people are difficult and are not worthy of your time. However, I have found it to be rare that a mentoring relationship has not been beneficial, both to me, and the person I am mentoring.

7. Test something totally different than you have ever tested before. Yes, this is on your own time and at your own effort, but you can learn a lot and come away with a new marketable skill. Interested in mobile testing? Find a mobile app you find interesting and challenging and test it. A way to make this profitable is to become a crowd tester. I can recommend www.mycrowd.com as a place to learn more about getting started as a crowdtester.

8. Read or watch something totally unrelated to software testing and find lessons in it for testing. Once you start looking for analogies of testing, they are everywhere. One of my favorite TV shows for testing lessons is Mythbusters, but I have also learned from Kitchen Nightmares, Hotel Impossible, Undercover Boss and many others. Novels such as Jurassic Park have some great testing lessons in them. Take notes, then write about what you learn.

9. Speak at a conference. The trends are in your favor. Smaller conferences are becoming more popular, as is finding speakers who are not well-known names in the field. Get a great topic, a case study and develop it into a conference presentation. No takers on your idea? Fine. Create a YouTube video and you will have more views in a few weeks than you would have at a physical conference! The skill you develop in speaking is that of oral communication - a skill that can really propel your success in any field.

10. Contribute to forum discussions. I’m not talking about short, one-sentence responses, but respectful, well-reasoned responses to people’s questions and/or opinions. LinkedIn groups are a great place to start. The growth comes in the articulation and sharing of your feedback and ideas. Especially on LinkedIn, group contributors gain a stronger profile and presence.

You will notice that most of the items I list are active in nature. You grow by doing.

Consider the idea that each of the above actions might have a 5% or more increase in your value to your team, your career or to your company. The combined effect of doing all of these would be phenomenal. The combined effect is not an addition function, but a multiplier function. Doing all ten items would not be a 50% value addition, but more like a 200% or more addition of value to your career and to your role in your company. I can attest to this in my own career.

This is important because in today’s marketplace, you are paid for the value you bring to a project. Low-value activities are often the first to go when companies decide to cut-back. The same holds true for people. The people that are more likely to be retained are those that add value to a project and to a company.

It’s better to build skills today for tomorrow than to realize one day you need skills that will take time to acquire and build.

Friday, November 04, 2016

Online Study Group Forming for the ISTQB Advanced Security Tester Certification

I am forming an online virtual study group for people who wish to prepare for and take the new ISTQB Advanced Security Tester Certification. The exam has been in place since March of 2016, but the missing piece has been training courses.

I am working hard to finish my course in both live and e-learning formats. My plan is to have a beta version of the e-Learning course available in mid-November. This beta version will not be accredited because that process takes several weeks. However, the official release version will be accredited.

I know there are people that would like to start studying for this certification now. For that reason, I am forming this online virtual study group that also includes access to the e-Learning content as it is completed.

The cost of the exam ($200) is not included in the price of the course.


Also, please note there are two pre-requisites to sit for the exam:

1. You must hold the CTFL or equivalent
2. You must have 3 or greater years experience in software testing or a related field.

Security testing experience is not required.

Here’s How it Works:

We will meet weekly for one hour in a web meeting format. I will lead the meeting, but the purpose is to answer your questions and provide additional insights to the topics. We will cover sample exam questions. The exact day and time of the meetings may vary, but my plan is to hold the meetings on Wednesday around noon, Central time. There may be times when I either must reschedule or have a fill-in facilitator.

There are 11 sessions, including the kick-off session. Tentative start date is Thursday, Nov. 17th, with a goal end date of January 25th. That may sound like a long time, but with e-Learning courses, most people take several months to complete the advanced courses.

If you can’t attend a meeting, that’s fine. We will record each meeting so you will be able to watch and listen later if you like. You can also send me your questions and feedback by e-mail and I will be happy to respond. You also have phone access to me to ask questions.

If you join after the official start date, that’s fine too. Each chapter of the syllabus stands on its own. While it is optimal to start at Chapter 1, you can either catch-up with the recorded modules, or “wrap around” in the next study group (provided there is enough interest in a second group.)

You will have access to all the e-Learning content I have produced to date. This includes narrated slide shows, course notes, exercises and solutions, as well as the ISTQB sample exam questions.

As I continue to add new content, you will have first access to it. However, I expect that all the content will be in place by the second week of the study group.

Each week, we will focus on a chapter in the syllabus. In two chapters, there will be two weeks each, due to the amount of materials. The time required to view the pre-recorded lessons will be about 2 hours per week. The exercises will require another 1.5 to 2 hours.

You will have access to other attendees to get their thoughts as well. The group and course are housed in my e-Learning Management System with forums so you can freely post ideas and questions.

You will get personal attention and mentoring from me. I expect this group will be 12 – 15 people or fewer people in size.

After the group ends, you still have access to the e-Learning course. This is helpful for review before you sit for the exam.

You have direct access to the person who chaired the development of the syllabus. I can provide context and input that is not in the syllabus or the course. And I can answer your “why” questions.

At any time you feel the group is too much for you to handle time-wise, you always have the option to continue on your own through the e-Learning modules. You still have access to me to ask any questions. In fact, you can still attend the weekly sessions. However, without doing with weekly preparation, you may feel a little disconnected.

Financial Details

The price for the full 11-week study group is $795. The cost of the exam ($200) is not included in the price of the study group.

Payment is in advance and can be made by major credit cards (Visa, MasterCard, Amex and Discover). We also accept PayPal and company checks.

How to Get Started
br /> You can register and pay at https://www.mysoftwaretesting.com/ISTQB_Advanced_Security_Tester_Study_Group_p/advsecgrp.htm

Access instructions will be sent in advance of the first session.

le="font-family: "arial" , "helvetica" , sans-serif;">Questions?

Just contact me here
Tentative Schedule and Topics


1. Thursday, Nov. 17, 12:00 p.m. - 1:00 CST - Kick-off
2. Wednesday, Nov. 23, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 1 (Basis of Security Testing)
3. Thursday, Dec 1, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 2 (Security Testing Purposes, Goals and Strategies)
4. Thursday, Dec 8, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 3 (Security Testing Processes)
5. Thursday, Dec 15, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 4 (Security Testing Through the Lifecycle, Part 1)
6. Thursday, Dec 22, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 4 (Security Testing Through the Lifecycle, Part 2)
7. Thursday, Dec 29, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 5 (Testing Security Mechanisms, Part 1)
8. Wednesday, Jan 4, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 5 (Testing Security Mechanisms, Part 2)
9. Thursday, Jan 12, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 6 (Human Factors in Security Testing)
10. Thursday, Jan 19, 12:00 p.m. - 1:00 CST - Review and Discussion of Modules 7 and 8 (Security Test Reporting, Security Test Tools)
11. Thursday, Dec 26, 12:00 p.m. - 1:00 CST - Review and Discussion of Module 9 (Standards and Industry Trends), Summary and Final Exam Tips

Thursday, November 03, 2016

ISTQB Advanced Security Tester Course Coming Soon!

A question I am asked often by people interested in the new ISTQB Advanced Security Tester certification is "When will courses be ready?"

I am excited to announce my course will be available soon in beta format - both live in-house and e-learning formats. I do not have an exact date at this time for the beta release, but I am looking at mid-November.

Since this is a beta version, the course will not be accredited initially. The plans are to have accreditation by the end of 2016. However, as chair of the ISTQB Advanced Security Tester Syllabus working party, I think I have a pretty good grip on the material.

The live course is 4 days in length and is a 50/50 mix of presentation and exercises. The e-learning course has the same content and exercises as the live course.

Here is the link to the course description: http://www.riceconsulting.com/home/index.php/Security-Testing/istqb-advanced-security-tester-course.html

If you are interested in the course or have any questions, either as an individual or as a company, please contact me through the contact form on my website: http://www.riceconsulting.com/home/index.php/component/com_formmaker/Itemid,453/id,1/view,formmaker/

I am taking course bookings for December and forward into 2017. I expect this to be a popular course, so act early to get your spot on my calendar. I will be the main instructor for the course.

Thursday, September 01, 2016

Happy Labor Day and The Software Quality Perspective

I hope you are having a great week. Me? I'm looking forward to a weekend Labor Day holiday with family and friends. To kick it off, I'm getting a cavity filled tomorrow!

For those of us in the USA, the Labor Day holiday is to commemorate the contributions of working people and labor unions. Since I have worked in IT most of my working years, I have never belonged to a union, so I'll just speak briefly here to the work ethic in software quality. However, I think much of this could apply to other fields as well.

Like you, perhaps, I have been on projects that required extreme effort and commitment to complete. Even then, some of the projects failed.

Over my 25+ years in software testing consulting, I have heard people complain about how difficult some tasks can become. My reply is something along the lines of, "Yes, that why we call it work."

I have also worked for managers that were totally clueless when it came to how to treat people. These managers expected 100% availability, no allowance for sickness or family emergencies, provided no training or encouragement to the team, and generally created a work environment that was de-motivating in nature. That is the dark side of work, in my opinion.

If I had to capsulize what a person should bring to a project, they would include:
  • Motivation - Passion for the job
  • Skills - Knowing how to do the job, and continuously learning new skills
  • Creativity - Being able to do things differently and better
  • Problem solving - So that the team lead doesn't have to do everything
  • Integrity - Doing the right thing when no one is looking
  • Caring - For the quality of work performed, and for the welfare of others
  • Vision - To see the big picture of what they are doing
  • Calling - To know why they are doing what they are doing
  • Respect - For others, for other people's ideas, for leaders

You might have other things that would fit well on the list. By the way, my two favorite books on this topic are "Peopleware" by DeMarco and Lister, and "The Mythical Man-Month" by Fred Brooks.

So, relax this weekend and enjoy the fruit of your labor. Ironically, some people will not be able to do that. They will be working. This normally includes law enforcement, military, medical professionals, broadcasters, and people working tech support, food service and retail. I salute those fine people and wish them safety in what they do.

Thursday, August 11, 2016

Recording and Slides From Today's Webinar on Decision Tables

Thanks to everyone that attended today's webinar on decision tables. For those that could not get in
due to capacity limits, I apologize.

However, here are the slides:
http://www.riceconsulting.com/public_pdf/Webinar_Decision_Tables.pdf

And here is the recording:
https://youtu.be/z5RlCBKxfF4

I am happy to answer any questions by e-mail, phone or Skype. If you want to arrange a session, my contact info is on the final slide.

Thanks again,

Randy

Wednesday, July 06, 2016

Lessons Learned in Test Automation Through Sudoku

For many years, I have recommended Sudoku as a mind training game for testers. I think Sudoku requires some of the same thinking skills that testers need, such as the ability to eliminate invalid possibilities, deduce correct answers and so forth.

Much like an application that may lack documentation, Sudoku only gives you a partial solution and you have to fill in the rest. Unlike software, however, guessing actually prevents you from solving the puzzle - mainly because you don't see the impact of an incorrect guess until it is too late to change it.

My friend, Frank Rowland, developed an Excel spreadsheet some time ago, that he used to help solve Sudoku puzzles by adding macros to identify cells that had only one possible correct value. At the time, I thought that was pretty cool. Of course, you still had to enter one value at a time manually. But I thought it was a good example of using a degree of automation to solve a problem.

Fast forward to last week. I was having lunch with Frank and he whips out his notebook PC and shows me the newest version of the spreadsheet. After listening to a math lecture from The Great Courses, he learned some new approaches for solving Sudoku.

Armed with this new information, Frank was successful in practically automating the solution of a Sudoku puzzle. I say "practically" because at times, some human intervention is required.

Now, I think the spreadsheet is very cool and I think that the approach used to solve the puzzle can also be applied to test automation. The twist is that the automation is not pre-determined as far as the numeric values are concerned. The numbers are derived totally dynamically.

Contrast this with traditional test automation. In the traditional approach to test automation (even keyword-driven), you would be able to place numbers in the cells, but only in a repeatable way - not a dynamic way.

In Franks's approach, the actions are determined based on the previous actions and outcomes. For example, when a block of nine cells are filled, that drives the possible values in related cells. The macros in this case know how to deduce the other possibilities and also can eliminate the invalid possibilities. In this case of "Man vs. Machine", the machine wins big time.

I don't have all the answers and I know that work has been done by others to create this type of dynamic test automation. I just want to present the example and would love to hear your experiences in similar efforts.

I think the traditional view of test automation is limited and fragile. It has helped in establishing repeatable tests for some applications, but the problem is that most applications are too dynamic. This causes the automation to fail. At that point, people often get frustrated and give up.

I've been working with test automation since 1989, so I have seen a lot of ideas come down the pike. I really like the possibilities of test automation with AI.

I hope to get a video posted soon to show more about how this works. Once again, I would also love to hear your feedback.  


Friday, July 01, 2016

ASTQB Mobile Tester Certification - Live Virtual Classes in August and September, 2016

According to a very recent survey published by Techwell, only 25% of respondents felt they had the knowledge/skills and tools needed for testing mobile applications!

That needs to change and I have just the way to do it.

I am launching a new schedule of live virtual training courses for this new certification from the ASTQB, starting August 9 – 11. 

I have been holding off offering this course as a live virtual course until I was 100% positive you would feel fully engaged while taking the course. I have developed a technique that I feel will keep you engaged in the material and prepare you for the exam. (By the way, the exam is not included in the cost of this course but you can add the $150 exam to your registration.)

Also, let me encourage you to keep building new skills in testing. Mobile testing is a great specialty area and it is also a great skill set to have in your career. The time to learn mobile testing is NOW. Don't wait until your employer is looking to build that special team...or (and I hope this never happens in bad way, but...) if you are looking for employment.

I will be the instructor for all presentations of this course. I am a co-author of the ASTQB Mobile Tester syllabus and author of this course. This course is fully accredited by the ASTQB. And...I have been teaching mobile testing since 2001!  You get personal access to me throughout the course and after the course to ask any questions.

This course covers all aspects of mobile testing. More about the live virtual classes can be found here:

and the course brochure is here:

In the most recent ASTQB newsletter that was published on Tuesday, I have an offer of 15% off any ASTQB Mobile Testing course – live or e-learning. Just use promo code “MOBILE15” when paying for your registration. This offer is only good through August 15. For more details on this course or to register, please visit http://www.riceconsulting.com/home/index.php/Mobile-Testing/astqb-certified-mobile-tester-live-virtual-course.html

If you want to learn more about the ASTQB Mobile Tester certification, just go to:

I hope to see you there!

Randy

Friday, May 06, 2016

ISTQB Advanced Level Security Tester Certification Officially Available!

I am very excited to announce that the ISTQB Advanced Security Tester certification is officially available. I am the chair of the effort to write the syllabus for this certification. It took us over 5 years to complete this project. We had input from security testers worldwide.

The syllabus is not yet posted on the ASTQB web site, but it will be available there very soon. It will take training providers such as myself a while to create courses and get them accredited, but they will also be out in the marketplace in the coming weeks and months.

Cybersecurity is a very important concern for every person and organization. However, only a small percentage of companies perform continuous security testing to make sure security measures are working as designed. This certification prepares people to work at an advanced level in cybersecurity as security testers. This is a great specialty area for testers looking to branch out into a new field - or to show their knowledge as security testers.

Below is a diagram showing the topics in the certification (click to enlarge):

Thursday, February 25, 2016

Coming to Dallas/Ft. Worth - Testing Mobile Applications - ASTQB Certification Course - April 19 - 20, 2016

I hope you can join me for this special course presentation for the new Certified Mobile Tester (CMT) designation from the American Software Testing Qualifications Board.

We will be in the DFW area (Irving, TX) on the dates of Tuesday, April 19 and Wednesday, April 20 at the Holiday Inn Express - 4235 West Airport Freeway, Irving, TX 75062

Seating is limited, so I recommend registering as soon as possible to get your place. (This class size is limited to 15 people.)

To register: https://www.mysoftwaretesting.com/ProductDetails.asp?ProductCode=CMTDFW

About the Course and Certification

In the fall of 2015, the ASTQB (of which I am on the board of directors) felt there was a compelling need for testers to have a robust and meaningful certification focused on testing mobile applications. So, we set about writing a syllabus and exam for that certification. I was honored to contribute as a co-author of the syllabus. At the present, this is a certification only offered by the ASTQB.

To learn more about the certification, see the syllabus and sample exam, just go to:
http://www.astqb.org/get-certified/mobile-tester/

To see the course outline, go to:
http://www.riceconsulting.com/home/index.php/Mobile-Testing/testing-mobile-applications-astqb-certification-course.html

There are no pre-requisites for this certification! While we reference concepts from the ISTQB Foundation Level, everything you need to know is taught in this course.

We have exercises to reinforce key concepts and sample exams after each module to give you a taste of what to expect on the actual exam. You can also bring your own mobile device as a way to perform the exercises, although this is not required.

Costs and Logistics

Cost: $1,500 USD per person, plus exam ($150).

You can attend the course without taking the exam. However, we will be offering a live exam at the end of the 2nd day.

There will also be the option to take the exam later electronically, if you desire. However, we need to know your preference 2 weeks in advance.

This class will be streamed live, so if you want to attend virtually, that is possible. There is a $100 discount for virtual attendees. Virtual attendees in the USA will receive a course notebook in advance of the training and will also have access to the e-learning course at no extra cost.

For teams of 3 or more, there is a 10% discount of the course registration fee. The exams are not discounted.

We will not have breakfast items, however, we will have a light lunch (pizza, sandwiches, etc.) brought in each day. Please let us know if you have any dietary needs or requests.

Important Notice for Those Who Plan to Travel to DFW to Attend

Please do not book any non-refundable travel (air fare, hotel, etc.) until we confirm the class. We make every attempt to not cancel a class, but sometimes this is unavoidable. We make the call about 2 - 3 weeks in advance of the class, or earlier, if possible.

We located this class to be close to the DFW airport for the convenience of those who may be traveling in for the class. The hotel runs a free airport shuttle.

You are responsible for making your own hotel reservations.

If you plan to take the exam on Day 2, the exam will take place from 3:30 p.m. to 4:30 p.m.  Please allow adequate time to catch your flight. The hotel is 6.4 miles from the DFW airport.

Other Questions?

Feel free to call our office with any questions or special needs - 405-691-8075.






Monday, January 25, 2016

Survey Results for the Tester to Developer Ratio - January 2016

For the past month, I have been collecting surveys to see which tester to developer ratios are in use in various organizations. In addition, I asked some other questions about management attitudes toward dealing with testing workloads. I'll publish those results a little later.

This was a small survey of 22 companies worldwide, 19 of which were able to provide accurate information about their tester to developer ratio.

This survey is part of ongoing research I have been conducting since 2000.

Thanks to everyone who has contributed to date.

Before I get into the findings, I want to refer to two articles I have written on this topic. These articles explain why I feel that the data show there is no single ratio that works better than others. Getting the right workload balance is a matter of tuning processes and scope, which includes optimizing testing to get the most efficiency with the resources you have.

You can read these articles at:



The recent findings are:
  • The range of ratios are much tighter. The range was 1 tester to 1 developer on the richer end of the scale, to 1 tester to 7 developers on the leaner end. I feel that some of this is due to the small sample size.
  • The majority of responses (16) indicated just three ratios: 1 tester to 1 developer on the low side to 1 tester to 3 developers on the high side.
  • The most common ratio was 1 tester to 2 developers
  • The average was also 1 tester to 2 developers 
  • People reported poor, workable and good test effectiveness at all ratios. The variation was wide. There were no noticeable indications that a particular ratio of testers to developers worked any better than another, simply due to the ratio.

This survey showed much richer ratios than any other survey I’ve taken. This could be due to the impact of agile methods. Most of these companies (13) reported they do not anticipate hiring more testers in 2016. I plan to continue this survey to get a more significant sample size.

If you have not contributed to this survey yet, you can still add your responses at:
https://www.surveymonkey.com/r/55LVHFZ

All responses are anonymous.

Thanks!

Randy

Thursday, December 17, 2015

Friday, October 02, 2015

Friday, June 19, 2015

A Tribute to My Father


-->
In honor of this upcoming Father’s Day here in the USA, I want to pay a special tribute to my dad, Marvin Rice. I’m thankful he is still alive and I am able to visit with him. I know that many people don’t have that blessing.

When my dad was very young he worked in the broomcorn fields of southern Oklahoma. As he grew into adolescence, he showed an aptitude for working with mechanical things, so he helped support his parents and siblings by working on cars. He was drafted into the Army after WWII to go to Japan as part of the rebuilding effort. There, he was a small arms specialist.

When he returned home from Japan, he opened a Texaco station in Chickasha, OK. The building is still standing today.

I got my love of business from my dad. From the age of 8 or 9, I was helping at the service station he leased in Chickasha from Champion Oil Company (that building is still there, too). That station was located in the “bad” part of town, but the early 60’s was a different time in our country, and especially in Chickasha. I remember how the old men, both white and black, would sit around the stove in the station just shooting the bull.

I saw how my dad served people of all races and economic levels the same way. (By the way, gasoline was 19 cents a gallon then!) For those of you too young to remember, there was a time when most gas stations were full-service. Not only did someone else put the gas in your car, but you got your windshield cleaned, your oil checked, hoses and belts checked, and maybe even your tires were checked.

As a kid, I washed a lot of windows and checked a lot of tire pressure!

I saw my dad bounce back from financial setbacks, like the time someone stole all the cash from the day’s business. That would have been roughly $3,000 in today’s money.

He worked long hours, gave good service and had loyal customers because he enjoyed what he did, even though it was hard at times. He was always working to improve himself. I remember early in my life when he took a Dale Carnegie course – a big thing back then. Guess what? I listened to the tapes as well and read the book, “How to Win Friends and Influence People” before I graduated High School and they shaped how I deal with people.

As I got older, Dad became my scoutmaster and I learned lessons of leadership. We also rebuilt two engines! In fact, we are working together right now to restore a 1949 Plymouth that has been in our family for 65 years. That has taught me a lot about problem-solving.

My dad is a man of few words, but I think the thing he told me most often (usually while working on something) is "If a job is worth doing, it's worth doing right." That sure fits into the quality picture, doesn't it?

Much of what you see in the work I do through Rice Consulting Services, is actually a branch off a tree with deep roots of skills, hard work, integrity, creativity, tenacity, and a strong belief in God and Country. I try my best to maintain the standards my dad has in his own life.


It is incredible, but at age ninety, he still works almost daily on sewing machines. He has a steady stream of customers. I find that both inspiring and depressing - inspiring that he still has the energy and desire to still be active and working - depressing that I may have inherited that same gene.

As I look at my two sons, both fathers, one a software tester and one an auto technician, I see his legacy forming in their lives as well and it makes me proud.

That’s what this posting is really about. Not just buying your father a card and gift for Father’s Day, but if you are able, to tell him what he has handed down to you in your life. Too many times we remember the disagreements or strife, but there were likely good times in there as well. How has he shaped your life? What is his legacy? I’ll bet if you tell him how he helped to shape your life, that will be the greatest Fathers’ Day gift of all. If you can’t tell him in person or by phone, then set aside a few quiet moments and reflect on his memory.

Have a great weekend (and a Happy Fathers’ Day if that applies to you)!

Randy


Friday, May 29, 2015

Flushing Out the Bugs

-->
First, let me say that all of May has been a very difficult month weather-wise for those of us in Oklahoma, then later in May, for folks in Texas. Thankfully, all the tornadoes and flooding did not affect us personally, but we have friends and neighbors who were impacted and some of the stories are just tragic. So, I ask that if you are able to send a relief gift to the Red Cross designated for these disasters, please do so. It would really help those in need.

Here in Oklahoma we have had two years of extreme drought. One of the major lakes was over 31 feet below normal levels. Now, it has risen to 99% capacity. We have some lakes that are 33 feet above normal. Just in the month of May we have had 27.5 inches of rain, which shatters the record for the wettest month in history 
--> (May 2013 with 14.52 inches and the all time monthly record was 14.66 in June of 1989). Texas has also seen similar records broken. In short, we’ve had all the rain we need, thank you. California, we would be happy for you to get some of this for your drought.

The image above is of the main street of my hometown, Chickasha, OK.

Then, there are the tornadoes that make everything even more exciting. One night this month, we had to take shelter twice but no damage, thankfully. Then yesterday morning I was awakened at 5:30 a.m. to the sounds of tornado sirens. That is freaky because you have to act fast to see what is really happening. In this case, the tornado was 40 miles away, heading the opposite direction. I question the decision to sound the alarm in that situation.

Anyway…with that context…

About a week ago, I started noticing ants everywhere in and around our house. I mean parades of them everywhere. Ironically, I even found one crawling on my MacBook Pro!

Then, came the spiders, a plethora of other bugs, snakes and even fish in some peoples’ years. A friend reported seeing a solid white opossum near his house, which is very unusual.

And you perhaps heard that in one tornado event nearby on May 6, a wild animal preserve was hit and it was reported for a while that lions, bears, tigers, etc. were loose. Turns out that was a false report, too. But it did make for some juicy Facebook pictures for “Tigernado” movies.

-->
Other weird things have happened as well, such as storm shelters and entire swimming pools popping out of the ground due to the high water table (and poor installation in some cases)!

But back to the ants and bugs and why they are everywhere. Turns out that we have had so much rain, their nests and colonies were destroyed and they are now looking for other habitats. The same has occurred with spiders, snakes, mice and rats.

In fact, my wife and I are finding bugs we have never seen before. I had to look some of them up on the Internet just to know what kind of bug I was killing.

That caused me to think about a new testing analogy to reinforce a really great testing technique. To flush out the bugs in something, change the environment.

Of course, the difference here in this analogy is that software bugs are not like actual bugs in many regards. However, there are some similarities:

·      Both have taxonomies
·      Both can be studied
·      Both can mutate
·      Both can travel
·      Both can destroy the structure of something
·      Both can be identified and removed
·      Both can be prevented
·      Both can be hidden from plain view

The main differences are:

·      Bugs have somewhat predictable behavior – not all software defects do
·      Bugs can inhabit a place on their own initiative – software defects are created by people due to errors

(Although I have wondered how squash bugs know how just to infest squash plants and nothing else…)

In the recent onslaught of ants, it is the flooding that has caused them to appear in masses. In software, perhaps if you flooded the application with excessive amounts of data such as long data strings in fields, you might see some new bugs. Or, you could flood a website with concurrent transaction load to see new and odd behavior.

Perhaps you could do the opposite and starve the environment of memory, CPU availability, disk space, etc. to also cause bugs to manifest as failures.

This is not a new idea by any means. Fault injection has been used for many years to force environmental conditions that might reveal failures and defects. Other forms of fault injection directly manipulate code.

Another technique is to test in a variety of valid operational environments that have different operating systems, hardware capacities and so forth. This is a great technique for testing mobile devices and applications. It’s also a great technique for web-based testing and security testing.

The main principle here is that if you can get the application to fail in a way that causes it to change state (such as from “normal state” to “failure state”, then it is possible to use that failure as a point of vulnerability. Once the defect has been isolated and fixed, not only has a defect been found and fixed, but also another security vulnerability has been eliminated.

Remember, as testers we are actually trying to cause failures that might reveal the presence of defects. Failure is not an option – it is an objective!

Although, we commonly say that testers are looking for defects (bugs), the bugs are actually out of our view many times. They are in the code, the integration, APIs, requirements, and so forth. Yes, sometimes we see the obvious external bug, like an error message with confusing wording, or no message at all.

However, in the external functional view of an application or system, testers mainly see the indicators of defects. These can then be investigated for a final determination of really what is going on.

As testers, we can dig for the bugs (which can also be productive), or we can force the bugs to manifest themselves by flushing them out with environmental changes.

There is one more aspect to this situation. With all the standing water and moisture, the next phase will be mosquitoes and ticks. The tick invasion has already started.  Instead of being flushed out my the flooding, these parasites are attracted to it. What attracts the bugs in your software?

And let’s be real here. In some software, the bugs are not at all hard to find!

Me? I’ll continue to both dig and flush to find those defects. Even better, I’ll go upstream where the bugs often originate (in requirements, user stories, etc.) and try to find them there!