Working with software houses / SDLC expertise
-
Our company have been outsourcing development of several business systems for a number of years, with various software houses/vendors, and have been surprised that many do not come with a predefined "SDLC package", but rather expect us to tell them how to work. Despite instructions being given, we've also had a few issues with them following processes; e.g. - After one vendor left the project we tried to work with the projects they'd left behind only to find a number of items only partially checked in (i.e. some developers were clearly checking things in, others just working on their local copy and only selectively checking in a subset of the files required for the solution to work). - With a vendor we're currently working with, we ran an audit only to find they'd stopped checking in code a year previously after their firewall blocked their access to VSTS; so they just stopped using it without telling anyone, rather than fixing the issue or even informing us of a problem. We told them how to fix that issue, but since then every issue they've had they've come to us for support rather than resolving their own issues. NB: These issues are with standard products / their set up; the only thing we control is their permissions within VSTS, which are all correct. We've had other similar issues, but these 2 were the major WTF moments (the software houses we're dealing with are multi-national companies supporting a variety of products, including all of those they're developing for / involved in our SDLC lifecycle). Questions: - Is our experience common; i.e. not being able to trust a software vendor to adhere to basic SDLC practices / having to put considerable effort into supporting & auditing them? - Are there ways of working to help ensure that you manage your vendor correctly / get them to provide you with a quality service without having to manage & support each member of their team directly? - Are there any resources for comparing the quality of service customers can expect from different vendors? NB: I'm deliberately keeping company names out of this as feel that may be inappropriate / our experiences may not be representative.