blaukc / pe

0 stars 0 forks source link

NFRs do not seem reasonably achievable/out of scope for this 2103 project #15

Open blaukc opened 2 months ago

blaukc commented 2 months ago

Some NFRs they state that might not be reasonable achievable:

industry-standard encryption, RBAC

image.png

Some out of scope NFRs are:

disaster recovery measures in event of server failure (i believe this is an offline app)

image.png

also talks about managing database queries which is out of scope

image.png

image.png

nus-se-script commented 2 months ago

Team's Response

No details provided by team.

Items for the Tester to Verify

:question: Issue response

Team chose [response.NotInScope]

Reason for disagreement: This mentions NFRs like use of a DB, which is not allowed in this project. Furthermore, they do mention adhering to industry standard encryption, which I believe was not done and is probably unreasonable in the first place. This should actually be escalated to a severity.Low

image.png