IT MANAGEMENT     2 
 
Software Development and Maintenance Policies 
  Every functional area related to the operational management for the project organization 
must always have an access control and software development and maintenance security 
policies. The paper includes some of the factors that get incorporated in the scope and range of 
the access control software development considering their maintenance and security policies.  
  Firstly, the developers have to consider the risk of the application. They have to 
determine how important then system is important to the operations of the organization. A high 
risk application is the one that its failure will greatly impact on the operations of the department. 
Considering the size and complexity of the system, the development of a small and simple 
software or computer application should not take more than a year of effort and or cost more 
than one hundred and fifty thousand dollars (Sahin & Zahedi 2001). The maintenance of small 
and simple system should take less than a month of the staff’s effort time and cost less than 
fifteen thousand dollars. There are also some maintenance standards for the small modifications 
directed on the low risk applications include that the developers must log in and retain the 
request for change of the emails if necessary. They must also document any of the program 
changes. Considering the aspect of the source control, the changes to the existing systems must 
incorporate the procedures for segregating the production and the test code.  
  The users of the software must also participate in the various stages of the change 
process. Their requests for enhancement or identification of the problems in the systems must 
always get considered. The developers must follow the procedures for the identification and the 
resolution of all the issued revolving around the proposed changes.