Cybersecurity Program Management

Agile vs. Traditional vs. Hybrid Project Management

A questionnaire with credit to PMI.org and Doing Agile Right by Darrell Rigby, Sarah Elk and Steve Berez

  1. Speed - How important is delivering with speed for your Cybersecurity team?
    1. Quality is more important than Speed. We need our team to rarely make mistakes (0 points)
    2. Quality and Speed have the same priority. A few mistakes will be acceptable, if we are regularly delivering (5 points)
    3. Speed is more important than quality, issues or rework is okay (10 points)

 

  1. Cost - How much of your budget is for projects to add new capabilities?
    1. We have a significant budget and are routinely making large investments in cybersecurity improvements (0 points)
    2. Our team has a balance of several projects with a good amount of routine operational efforts (5 points)
    3. We have a modest budget with less than 5 new projects per year (10 points)

 

  1. Clarity - For your most important projects, how clear and well defined are the requirements?
    1. Our needs are well understood and unlikely to change (0 points)
    2. Requirements for the largest projects are somewhat defined but may change (5 points)
    3. The requirements for our cybersecurity improvements are not very well defined, and will evolve during the work (10 points)

 

  1. Collaboration - Are there cybersecurity experts available to routinely collaborate with your project teams?
    1. We have a few experts on the team who help make important project decisions (0 points)
    2. Each team has access to a pool of experts who can help when a project is started or when an issue comes up (5 points)
    3. There are several experts available to provide regular guidance for each project team (10 points)

 

  1. Deadlines - How many efforts have a fixed timeline, where the Cybersecurity efforts must be completed by a specific date?
    1. Many of our cybersecurity projects have a firm due date we must hit, to support the business or for compliance reasons (0 points)
    2. There are several projects with fixed due dates, however most projects have flexible internal delivery dates (5 points)
    3. Most of our cybersecurity projects have a flexible finish date or can be delivered incrementally over time (10 points)

 

  1. Dependencies - How often do projects have dependencies on Infrastructure, Application Development or other teams?
    1. Most projects have multiple dependencies to manage with other teams (0 points)
    2. Many projects require collaboration with other teams, and we re willing to have regular ceremonies to manage it (5 points)
    3. Most projects are self-contained, where the people on the team is able to deliver the project (10 points)

 

  1. Cybersecurity Expertise - How much would you trust your team to be self-directed, and make important decisions?
    1. We don t have strong enough teams yet to be able to empower them, so important decisions are made by leadership (0 points)
    2. Some of our teams could be self-directed, but due to talent gaps we are careful about which teams to empower (5 points)
    3. All project teams will be empowered to make decisions, and will be held accountable for consulting well (10 points)

 

  1. Agile Experience - To what extent would your current team need to be trained on the Agile way of working?
    1. Extensive training would be required, for each role on the team (0 points)
    2. Some of our staff will require training, and ongoing training would be ideal for all roles (5 points)
    3. Our staff is very familiar with the Agile way of working, and is even able to help train others (10 points)

 

  1. Budgeting - How flexible is your Finance team regarding the financial planning process?
    1. Finance is very concerned about any budget variances. They expect accurate budgets and forecasts (0 points)
    2. Our Finance team is a great partner, and has some flexibility regarding how budgeting and budget variance is accounted for (5 points)
    3. Our organization s Finance team has embraced Agile and is comfortable budgeting frequently or with flexibility to address when we need to pivot (10 points)

 

  1. Team Size - How large is your typical project team?
    1. Each project tends to have very few (3 or less) or very many (20 or more) people engaged for many months, to focus on that project (0 points)
    2. Each project is broken down into smaller pieces that can be assigned to a smaller team to be completed (5 points)
    3. Every team has about 5-7 people, with all the skills needed to deliver the project (10 points)

 

Total number of points = __________

 

Scoring the Results:

If your total number of points is 55 or more, your Cybersecurity Team would benefit the most from using an Agile program management methodology.

If your total number of points is 20 or less, your Cybersecurity Team would benefit the most from using a traditional predictive (schedule-based) program management methodology.

If your total number of points is between 20 and 80, your team should consider the benefits of using a Hybrid program management approach. 

 

 

Click here to return to the Cybersecurity Program Management home page.