SD-17.9 — Application Portfolio & Engineering
Business Domain: BD-17 Corporate Services & Resources (Cross-cutting — corporate) · Applies: BOTH
Purpose
The firm’s capability to build the technology it runs — the application portfolio’s executing artefacts, the software-development lifecycle, software-engineering practice, and the build / test / release pipeline. SD-17.9 is the build layer of the firm’s CTO / CIO function. It executes against the strategy and architecture SD-17.7 sets, and produces the running artefacts SD-17.10 operates. It is the elemental capability “the firm builds software”; the standards it builds to, and the production platforms it deploys to, belong to its peers.
Service Operations
- Manage the application portfolio inventory — maintain the executing inventory of business applications: their owners, dependencies, lifecycle stage, and technical-debt position. The strategic shape of the portfolio is SD-17.7’s; the operational inventory is here.
- Run the software-development lifecycle — operate the SDLC: requirements intake, design, build, test, release. The end-to-end engineering process for software the firm develops.
- Operate the engineering platforms — the source-control, code-review, CI/CD, artefact-management, secrets-management and engineering-productivity tooling that the firm’s engineers build through. The platform engineers build on; the firm’s production platforms are SD-17.10’s.
- Manage build, test and release — the engineering pipeline that produces deployable artefacts: build automation, automated testing, release engineering, deployment automation. The artefact crosses to SD-17.10 at release.
- Govern engineering practice — code quality, code-review discipline, branching and trunk-based-development practice, technical-debt and refactor cadence, developer experience.
Inputs and outputs
- Inputs: the architecture standards and target-state from SD-17.7; business and capability demand for new and changed applications; security architecture from SD-14.5; the engineering and DevOps body of practice.
- Outputs: the running engineering practice, the application-portfolio inventory, the build/test/release pipeline producing deployable artefacts — consumed by SD-17.10 (which deploys and runs the artefacts), SD-13.12 (which builds and runs its data-platform pipelines through the same engineering practice), every Business Domain consuming software the firm builds, and SD-14.4 / SD-14.5 (which control what is built).
Entities
- Consumes: E-15 Document Metadata; the reference entities; the SD-14.5 security architecture; the SD-17.7 architecture standards and target-state.
- Owns: none — the application-portfolio executing inventory is a candidate entity.
Standards
- The DevOps body of practice — DORA (DevOps Research and Assessment) metrics (deployment frequency, lead time for changes, change failure rate, mean time to restore service), the State of DevOps research findings. Not to be confused with the EU Digital Operational Resilience Act (“DORA”) cited elsewhere in the model under SD-14.5 / SD-14.6 / SD-17.7 / SD-17.8 / SD-17.10 / SD-12.16 — same acronym, unrelated bodies; “DORA” in this Service Domain refers to the DevOps research only.
- CI/CD practice — the build / test / release pipeline discipline.
- The Accelerate book (Forsgren / Humble / Kim) — the practitioner reference for high-performing engineering capability.
- The OWASP Software Assurance Maturity Model (SAMM) — the maturity reference for build-side security practice (the control SD-14.5 oversees).
Open extensions
- The application-portfolio executing-inventory entity.
- The deployment / release record as a modelled artefact.
- The engineering-platform component register.