Stakeholder

A group of people standing with their backs to camera, except one, who's turning to look back
Photo by cottonbro studio on Pexels

 

Overview

Stakeholders are anyone who has a stake and vested interest in the success of the project and the value it brings (or in the case of disfavoured stakeholders, those who have a vested interest in the failure of the project). Stakeholders matter to the project because they benefit from the value it brings in a way that matters to the project, or are vulnerable to harm it can cause, and therefore decide on what quality means. Anyone who doesn’t have any vested interest in the project is not a stakeholder and doesn’t matter to the project.

For software testers, identifying stakeholders is critical to evaluating quality, as lost value and harm is subjective, and the subjects are the stakeholders. Identifying stakeholders up front enables good risk coverage in identifying all the threats and bugs that may cause problems. Being able to include the stakeholder in any risk story gives weight to the risk and any bug reported that includes it.

 

Vulnerable

The most important stakeholder in any quality story of risk is the most vulnerable which may not be the most obvious. Testers must identify all the stakeholders but also the level of risk to each one, the most vulnerable stakeholder, the one(s) that could come to the greatest level of harm, are the ones the tester prioritises the most. Typically the most weight is put to the most visible stakeholders, the clients/customers and end users, but this is often not the case especially when it comes to risk of harm.

 

Favoured Stakeholders

Clients/Customers

Those who pay for the software, decide if the software is value-for-money and therefore an important judge of its quality. They may be the same person as the end users and administrators.

 

End Users

Part of day-to-day operations. They could be the same people as the clients and customers, being every-day members of the public, or could be employees of customers used in the day-to-day operations of other companies (e.g. enterprise software). They may also be end users of the end users. They may or may not be highly technical but are domain experts who are using the software to help solve a problem, complete a task or achieve an objective for themselves or their employers.

 

System Administrators

Privileged users who support and maintain the software whether employed by the same company as part of the project team or employed by the client or customer. The goal of the administrator is to install, setup and/or configure the application as part of initial deployment and support operations. They differ from end users as they don’t use the software for its main purpose and value. They are more often than not more technical than domain end users and support end users with the technical side of the software.

 

Project Teams

The internal business people, developers, testers, operations, designs, owners, coaches and managers that make up a project team to deliver the software to clients and customers. They have a stake and vested interest in the success of the project due to continued employment or sense of achievement.

 

Business

Shareholders, investors, board directors, senior management who own and run the software business. They have a stake and vested interest of the software project to make a profit and/or remain in employment themselves.

 

Government

Regulations followed and relevant legislation enforced, who have the power to fine and even prosecute individuals such as company board directors.

 

Public

The general public or society as a whole; in delivering value to one set of stakeholders also means avoiding harm to members of the public.

 

Disfavoured Stakeholders

Threat Actors

Threat actors may attempt to obtain confidential information, compromise the integrity of the information or services, or affect the availability of the information or services to legitimate people though exploiting vulnerabilities in the software product or project. This may be to gain value themselves at the expense or undesirability of favoured stakeholders, and/or cause harm to others through use of malware, social engineering attacks or exploiting vulnerabilities. There are many different types of threat actors including:

  • Criminals: Usually for financial reasons including selling data on the black market or exploitation through ransomware
  • States: Usually for political or miliary reasons, including attacking government or military institutions, or attempting to change public opinion in another state
  • Insiders: Those who are internal to project teams or business who work from the inside against the project. This can be by themselves or with outsiders for financial, revenge (e.g. begrudged employee) or coerced or threatened by external threat actors.
  • Hacktivists: Those who want to spread a political message
  • Hobbyists: Those who do it for the joy, thrill or challenge, or want to practice to improve their skills for other reasons, including wanting to move into legitimate cybersecurity or penetration testing roles.

Penetration testers are testers that specialise in the security quality aspect and form part of the project team. They may often take on the role of a threat actor to see how they might be able to exploit the system.

 

Corporate Rivals

Rival companies (or in the case of multiple projects, people or teams working on different solutions to the same project, promotion or job opening) that will benefit due to lost value of the project’s software product due to bugs, poor initial idea, design, marketing or other reasons. They may also benefit from information security breaches, whether directly engaging in corporate espionage as threat actors or simply benefit form company data being leaked publicly to themselves or others.

You may also like these