lectures-final-vorgehensmodelle |
p1-p4 |
non-substantive |
|
Title, phase-assignment overview diagram, table of contents, learning goals/literature — orientation only. |
lectures-final-vorgehensmodelle |
p5-p6 |
complete |
final/vorgehensmodelle.html#vm-grundlagen |
Motivation (problem/solution) and benefits of process models. |
lectures-final-vorgehensmodelle |
p7 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-vorgehensmodelle |
p8-p9 |
complete |
final/vorgehensmodelle.html#vm-grundlagen |
Definition of Vorgehensmodell; classification and selection of presented models. |
lectures-final-vorgehensmodelle |
p10 |
non-substantive |
|
Section divider slide ("Traditionelle Ansätze"). |
lectures-final-vorgehensmodelle |
p11-p13 |
complete |
final/vorgehensmodelle.html#vm-wasserfall |
Waterfall model — properties, advantages, disadvantages, application area. p12 diagram is an illustrative re-rendering of the described modified waterfall. |
lectures-final-vorgehensmodelle |
p14-p17 |
complete |
final/vorgehensmodelle.html#vm-vmodell |
Basic V-Model, validation vs verification, V-Model diagram labels (p15), and successors (V-Modell XT, BVM). |
lectures-final-vorgehensmodelle |
p18-p21 |
complete |
final/vorgehensmodelle.html#vm-spiral |
Spiral model — iterative/risk-driven properties, four phases (p19), advantages/disadvantages/application. p20 schematic is illustrative of the described structure. |
lectures-final-vorgehensmodelle |
p22-p26 |
complete |
final/vorgehensmodelle.html#vm-rup |
RUP — six best practices, two dimensions, four phases, advantages/disadvantages/application. p25 hump chart is illustrative. |
lectures-final-vorgehensmodelle |
p27 |
non-substantive |
|
Section divider slide ("Agile Ansätze"). |
lectures-final-vorgehensmodelle |
p28-p30 |
complete |
final/vorgehensmodelle.html#vm-agiles-manifest |
Agile Manifesto — definition, four values, twelve principles. |
lectures-final-vorgehensmodelle |
p31-p36 |
complete |
final/vorgehensmodelle.html#vm-scrum |
Scrum — definition, development philosophy, elements, roles. p36 graphic is illustrative. |
lectures-final-vorgehensmodelle |
p37-p45 |
complete |
final/vorgehensmodelle.html#vm-xp |
eXtreme Programming — values, principles, techniques, roles, development philosophy. p40/p44 graphics are illustrative. |
lectures-final-vorgehensmodelle |
p46-p47 |
complete |
final/vorgehensmodelle.html#vm-kanban |
Kanban — WiP limit, board, no roles/meetings, Kanban vs Scrum. p47 board image is illustrative. |
lectures-final-vorgehensmodelle |
p48 |
non-substantive |
|
Section divider slide ("Traditionell -> Agil"). |
lectures-final-vorgehensmodelle |
p49-p50 |
complete |
final/vorgehensmodelle.html#vm-trad-vs-agil |
Traditional vs agile — no silver bullet, practical tips. p50 waterfall-vs-iterative comparison is illustrative. |
lectures-final-vorgehensmodelle |
p51-p53 |
complete |
final/vorgehensmodelle.html#vm-boehm-turner-factors |
Boehm/Turner decision factors and decision-model diagram (p53 preserved as source artifact). |
lectures-final-vorgehensmodelle |
p54 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-vorgehensmodelle |
p55 |
complete |
final/vorgehensmodelle.html#vm-zusammenfassung |
Summary — key principles for selecting and adapting process models. |
work-blatts-final-vorgehensmodelle |
p1 |
non-substantive |
|
Cover/TOC and general worksheet notes (administrative). |
work-blatts-final-vorgehensmodelle |
p2 |
complete |
final/vorgehensmodelle.html#vm-trad-vs-agil |
(Un)flexible project phases — captured as question vm-q-flexible-phases. |
work-blatts-final-vorgehensmodelle |
p3 |
complete |
final/vorgehensmodelle.html#vm-boehm-turner-factors |
Requirements in agile, showing prototypes, model selection, standard-model benefits — captured as questions vm-q-agile-requirements, vm-q-show-prototype, vm-q-choose-model, vm-q-standard-model-benefits. |
work-blatts-final-vorgehensmodelle |
p4 |
complete |
final/vorgehensmodelle.html#vm-pm-prototyp-aufwand |
Effort estimation prototype-vs-product scenario — captured as question vm-q-prototype-effort. |
work-blatts-final-vorgehensmodelle |
p5-p6 |
complete |
final/vorgehensmodelle.html#vm-pm-projektzeitplan |
Linear estimation pitfalls and project schedule (basic + advanced) — captured as questions vm-q-linear-estimate, vm-q-project-schedule. |
work-blatts-final-vorgehensmodelle |
p7 |
complete |
final/vorgehensmodelle.html#vm-pm-projektzeitplan |
UI effort estimation (Ticketline) and the human side — represented in vm-pm-lineare-schaetzung and vm-pm-projektzeitplan. |
lectures-final-implementierung |
p1-p4 |
non-substantive |
|
Title, phase-assignment diagram, table of contents, learning goals/literature. |
lectures-final-implementierung |
p5-p6 |
complete |
final/implementierung.html#impl-codequalitaet |
Code-quality motivation (productivity decline; rescue-rewrite); represented with the Oracle example block. |
lectures-final-implementierung |
p7 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-implementierung |
p8-p13 |
complete |
final/implementierung.html#impl-grundlagen |
Definition, goals, preconditions, macro/micro architecture and its evolution. |
lectures-final-implementierung |
p14-p15 |
non-substantive |
|
Repeated TOC and "Programmiersprachen" section divider. |
lectures-final-implementierung |
p16-p24 |
complete |
final/implementierung.html#impl-sprachen |
Programming languages — definition, classification, paradigms, selection. |
lectures-final-implementierung |
p25 |
non-substantive |
|
Frameworks section divider slide. |
lectures-final-implementierung |
p26-p32 |
complete |
final/implementierung.html#impl-frameworks |
Framework definition, benefits, advantages/disadvantages, selection, types. |
lectures-final-implementierung |
p33 |
complete |
final/implementierung.html#impl-ioc |
Inversion of Control — advantages/disadvantages. |
lectures-final-implementierung |
p34 |
complete |
final/implementierung.html#impl-framework-auswahl |
Whitebox/blackbox frameworks, hot spots, method hooks. |
lectures-final-implementierung |
p35-p36 |
complete |
final/implementierung.html#impl-framework-vs-lib |
Framework vs library, with code examples. |
lectures-final-implementierung |
p37 |
non-substantive |
|
Entwicklungsumgebung section divider slide. |
lectures-final-implementierung |
p38-p44 |
complete |
final/implementierung.html#impl-ide |
IDE — definition, feature set, advantages/disadvantages. p44 Eclipse screenshot is illustrative. |
lectures-final-implementierung |
p45 |
non-substantive |
|
Versionsmanagement section divider slide. |
lectures-final-implementierung |
p46-p49 |
complete |
final/implementierung.html#impl-vm-begriffe |
Version management definition, reasons, terms, branching, benefits. |
lectures-final-implementierung |
p50-p53 |
complete |
final/implementierung.html#impl-vm-arten |
Version-management types (local/central/decentral). p53 distributed-SCM diagram is illustrative. |
lectures-final-implementierung |
p54-p60 |
complete |
final/implementierung.html#impl-vm-kollaboration |
Collaboration (Lock-Modify-Unlock vs Copy-Modify-Merge) and refactoring with SCM. p55/p57/p58/p59 diagrams are illustrative of the described strategies. |
lectures-final-implementierung |
p61 |
complete |
final/implementierung.html#impl-vm-begriffe |
SCM integration into the workday (IDE integration, diff/commit/history GUIs, EGit). Illustrative screenshots; substance folded into the version-management terms block. |
lectures-final-implementierung |
p62 |
non-substantive |
|
Buildmanagementsystem section divider slide. |
lectures-final-implementierung |
p63-p64 |
complete |
final/implementierung.html#impl-build |
Build management definition, reasons. |
lectures-final-implementierung |
p65-p66 |
non-substantive |
|
Dependency-management illustration slides (no extractable text; content covered by the build block). |
lectures-final-implementierung |
p67 |
complete |
final/implementierung.html#impl-build |
Dependency management — goals and open questions. |
lectures-final-implementierung |
p68-p69 |
non-substantive |
|
Repeated TOC and "Coderichtlinien" section divider. |
lectures-final-implementierung |
p70-p73 |
complete |
final/implementierung.html#impl-coderichtlinien |
Code conventions definition, importance (readability/maintainability), magic numbers & Command-Query Separation (also impl-magic), example conventions. |
lectures-final-implementierung |
p74-p76 |
complete |
final/implementierung.html#impl-coderichtlinien |
Reporting and standardization. |
lectures-final-implementierung |
p77 |
non-substantive |
|
Benennungskonventionen section divider slide. |
lectures-final-implementierung |
p78-p81 |
complete |
final/implementierung.html#impl-naming |
Naming conventions and recommendations (loop vars, returns, formatting, type inference/var). |
lectures-final-implementierung |
p82-p83 |
complete |
final/implementierung.html#impl-null |
Handling null — never give null a meaning; Optional vs default values/empty collections. |
lectures-final-implementierung |
p84 |
non-substantive |
|
Source Code Kommentare section divider slide. |
lectures-final-implementierung |
p85-p91 |
complete |
final/implementierung.html#impl-kommentare |
Source-code comments — definition, types, advantages, usage, Javadoc, good vs bad examples. |
lectures-final-implementierung |
p92 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-implementierung |
p93-p96 |
complete |
final/implementierung.html#impl-komponenten |
Component-oriented development — goals, advantages, microservices/interfaces. p95/p96 are illustrative. |
lectures-final-implementierung |
p97 |
non-substantive |
|
Dependency Injection section divider slide. |
lectures-final-implementierung |
p98-p105 |
complete |
final/implementierung.html#impl-di |
Dependency Injection — definition, advantages, step-by-step code example. |
lectures-final-implementierung |
p106 |
non-substantive |
|
Design by Contract section divider slide. |
lectures-final-implementierung |
p107-p110 |
complete |
final/implementierung.html#impl-dbc |
Design by Contract — purpose, practice study, pre/post-conditions, invariants, strengths. |
lectures-final-implementierung |
p111 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-implementierung |
p112 |
complete |
final/implementierung.html#impl-probleme |
Known problems / best-practice areas overview (logging, error handling, localization, strings, security, concurrency, team communication, deployment). |
lectures-final-implementierung |
p113-p114 |
non-substantive |
|
Logging intro illustration slides (no extractable text; covered by the logging block). |
lectures-final-implementierung |
p115-p117 |
complete |
final/implementierung.html#impl-logging |
Logging — purpose, problems with System.out, log levels, SLF4J example. |
lectures-final-implementierung |
p118 |
complete |
final/implementierung.html#impl-fail-strategies |
Error handling — the four fail strategies (ignore/recover/soft/hard). |
lectures-final-implementierung |
p119-p125 |
complete |
final/implementierung.html#impl-exceptions |
Exception management — diagnosis questions, try/catch/finally, checked vs unchecked, best practices, hierarchies, JDK statistics. |
lectures-final-implementierung |
p126-p127 |
complete |
final/implementierung.html#impl-exceptions |
Notification Pattern — definition, example, explanation. |
lectures-final-implementierung |
p128-p129 |
complete |
final/implementierung.html#impl-lokalisierung |
Localization — best practices, Android example, toString() not for CLI output (also impl-tostring). |
lectures-final-implementierung |
p130-p131 |
complete |
final/implementierung.html#impl-strings |
String handling — manipulation (StringBuilder), text blocks, formatting helpers. p130 has no extractable text (illustration). |
lectures-final-implementierung |
p132 |
complete |
final/implementierung.html#impl-concurrency |
Concurrency — race conditions and Java support. |
lectures-final-implementierung |
p133 |
complete |
final/implementierung.html#impl-refactoring-linters |
Team communication — techniques, documentation, traceability, Linux kernel example. |
lectures-final-implementierung |
p134-p137 |
non-substantive |
|
Summary recap slide and literature recommendations (Clean Code, Effective Java). Summary content already represented across the lecture sections. |
work-blatts-final-implementierung |
p1-p2 |
non-substantive |
|
Cover/TOC and general notes/introduction (administrative). |
work-blatts-final-implementierung |
p3 |
complete |
final/implementierung.html#impl-codequalitaet |
Oracle bad-code report (impl-codequalitaet) and Golden Hammer (impl-golden-hammer) — questions impl-q-bad-code, impl-q-golden-hammer. |
work-blatts-final-implementierung |
p4 |
complete |
final/implementierung.html#impl-null |
NullPointerExceptions/Optional and Fail strategies — questions impl-q-null, impl-q-fail. |
work-blatts-final-implementierung |
p5-p6 |
complete |
final/implementierung.html#impl-naming |
YAGNI/KISS/DRY, naming, method heads, static, magic, no-surprises/CQS — questions impl-q-kiss-dry-yagni, impl-q-naming, impl-q-method-head, impl-q-static, impl-q-magic, impl-q-surprises. |
work-blatts-final-implementierung |
p7-p8 |
complete |
final/implementierung.html#impl-enums |
Advanced enums, AOP, toString() — questions impl-q-enums, impl-q-aop, impl-q-tostring. |
work-blatts-final-implementierung |
p9 |
complete |
final/implementierung.html#impl-enums |
Comparable, clone (shallow/deep), interfaces vs abstract classes/ISP — questions impl-q-comparable-clone, impl-q-interfaces-abstract. |
work-blatts-final-implementierung |
p10 |
complete |
final/implementierung.html#impl-builder |
Complex object creation — telescoping constructors vs builder — question impl-q-builder. |
work-blatts-final-implementierung |
p11 |
complete |
final/implementierung.html#impl-di |
Dependency Injection, composition vs inheritance, Law of Demeter, readability, static vs dynamic typing — questions impl-q-di, impl-q-composition, impl-q-demeter, impl-q-typing, and impl-coderichtlinien. |
work-blatts-final-implementierung |
p12 |
complete |
final/implementierung.html#impl-kommentare |
Source-code comment claims — question impl-q-comments. |
work-blatts-final-implementierung |
p13-p15 |
complete |
final/implementierung.html#impl-refactoring-linters |
Linters/automatic review and refactoring (movie-rental, PrintPrimes) — questions impl-q-linters, impl-q-refactoring. |
work-blatts-final-implementierung |
p16-p17 |
complete |
final/implementierung.html#impl-vm-begriffe |
SCM (distributed adoption, branching, commit-test-revert) and memory management/leak — questions impl-q-scm, impl-q-memory. |
software-engineering-i-architektur-tipps-und-tricks |
p8-p9 |
complete |
final/implementierung.html#impl-kiss-dry-yagni |
KISS, appropriateness, DRY, YAGNI, uniform code style — folded into the principles section to back final-worksheet topics. |
software-engineering-i-architektur-tipps-und-tricks |
p11 |
partial |
final/implementierung.html#impl-interfaces-vs-abstract |
SOLID overview (SRP/OCP/LSP/ISP/DIP); only ISP/DIP are used here to back interfaces-vs-abstract and DI. SRP/OCP/LSP are Block-3 (midterm) design material, treated as already learned and intentionally not re-prepared. |
software-engineering-i-architektur-tipps-und-tricks |
p14 |
complete |
final/implementierung.html#impl-composition-inheritance |
Best practice: prefer interfaces and composition — backs composition-vs-inheritance. |
software-engineering-i-architektur-tipps-und-tricks |
p1-p7,p10,p12-p13,p15-p32 |
non-substantive |
|
Remainder is Block-3 (Entwurf/architecture, midterm) design material — SRP/LSP detail, modelling, examples — treated as already learned and out of final scope; only the KISS/DRY/YAGNI/ISP/composition points pulled into the final via the worksheet are represented. |
lectures-final-qualitaessicherung |
p1-p4 |
non-substantive |
|
Title, phase-assignment diagram, table of contents, learning goals. |
lectures-final-qualitaessicherung |
p5-p7 |
complete |
final/qualitaessicherung.html#qa-motivation |
Motivation — failure examples, error statistics (residual table also in qa-restfehler), automatic tests in practice. |
lectures-final-qualitaessicherung |
p9-p10 |
complete |
final/qualitaessicherung.html#qa-methoden |
QA method taxonomy and software quality factors. |
lectures-final-qualitaessicherung |
p11-p12 |
complete |
final/qualitaessicherung.html#qa-kosten |
Cost model (latency, cost optimization). |
lectures-final-qualitaessicherung |
p13-p15 |
complete |
final/qualitaessicherung.html#qa-error-fault-failure |
Error/fault/failure definitions, triggering, causes of errors (qa-motivation). |
lectures-final-qualitaessicherung |
p16 |
complete |
final/qualitaessicherung.html#qa-verifikation-validierung |
Verification vs validation. |
lectures-final-qualitaessicherung |
p17 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-qualitaessicherung |
p18 |
complete |
final/qualitaessicherung.html#qa-statische-analyse |
Static QA and static analysis. |
lectures-final-qualitaessicherung |
p19-p21 |
complete |
final/qualitaessicherung.html#qa-metriken |
Software metrics and object-oriented metrics (p19 is a section divider). |
lectures-final-qualitaessicherung |
p22-p32 |
complete |
final/qualitaessicherung.html#qa-reviews |
Reviews — definition, pros/cons, roles, process, types, code reviews (p22 divider; qa-reviews, qa-review-arten). |
lectures-final-qualitaessicherung |
p33 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-qualitaessicherung |
p34-p35 |
complete |
final/qualitaessicherung.html#qa-statische-analyse |
Dynamic QA/analysis intro and Therac-25 example (independent testing); dynamic-analysis substance folded into the testing-basics and motivation blocks. |
lectures-final-qualitaessicherung |
p36-p41 |
complete |
final/qualitaessicherung.html#qa-testen-grundlagen |
Testing definition, importance, goals, ISTQB principles (p36 divider; qa-testen-def, qa-testen-ziele, qa-istqb). |
lectures-final-qualitaessicherung |
p42 |
complete |
final/qualitaessicherung.html#qa-standards |
Testing standards/certifications (ISTQB/ISAB, ISO/IEC/IEEE 29119) — folded into the standards block. |
lectures-final-qualitaessicherung |
p43-p46 |
complete |
final/qualitaessicherung.html#qa-doubles |
Test doubles/test drivers, test data, data-driven tests, positive/negative tests (qa-datengetrieben). |
lectures-final-qualitaessicherung |
p47-p53 |
complete |
final/qualitaessicherung.html#qa-testfalldoku |
Test cases (triangle example also in qa-coverage-traps), influences on test cases, and test-case documentation (p47 divider). |
lectures-final-qualitaessicherung |
p54-p56 |
complete |
final/qualitaessicherung.html#qa-stufen-typen |
Roles in software testing and test strategy (p54 divider). |
lectures-final-qualitaessicherung |
p57-p73 |
complete |
final/qualitaessicherung.html#qa-teststufen |
Test/integration levels and types, component/integration (strategies)/system/smoke/acceptance/regression tests (p57 divider; qa-integration, qa-akzeptanz, qa-regression). Diagrams p59/p66/p73 illustrative. |
lectures-final-qualitaessicherung |
p74-p79 |
complete |
final/qualitaessicherung.html#qa-box |
Coverage approaches and black/gray/white-box tests with pros (p74 divider). |
lectures-final-qualitaessicherung |
p80-p90 |
complete |
final/qualitaessicherung.html#qa-coverage-c |
Structural methods C0/C1/C2/C3/C4 with the discount example and short-circuit trap (p80 divider). Control-flow graphs p82 illustrative. |
lectures-final-qualitaessicherung |
p91-p109 |
complete |
final/qualitaessicherung.html#qa-testdesign |
Functional methods — equivalence classes, boundary values, state-based, classification tree, informal/exploratory/ad-hoc (qa-aequivalenz, qa-grenzwert, qa-aequivalenz). Example diagrams p105/p107 illustrative. |
lectures-final-qualitaessicherung |
p110-p118 |
complete |
final/qualitaessicherung.html#qa-automatisierung |
Non-functional tests — performance/load, usability, security/penetration (p110 divider). |
lectures-final-qualitaessicherung |
p119-p123 |
complete |
final/qualitaessicherung.html#qa-automatisierung |
Test automation — unit and GUI (capture/replay vs scripting) (p119 divider; p122 diagram illustrative). |
lectures-final-qualitaessicherung |
p124-p130 |
complete |
final/qualitaessicherung.html#qa-testprozess |
Test process phases and defect-management process (p124 divider; qa-fehlermanagement; p129 diagram illustrative). |
lectures-final-qualitaessicherung |
p131-p135 |
complete |
final/qualitaessicherung.html#qa-tdd |
Traditional testing vs TDD and the Think/Red/Green/Refactor steps (p131 divider; qa-tdd-context; p135 diagram illustrative). |
lectures-final-qualitaessicherung |
p136-p137 |
complete |
final/qualitaessicherung.html#qa-organisatorisch-block |
Organizational QA (knowledge/configuration management, templates, checklists) (p136 repeated TOC). |
lectures-final-qualitaessicherung |
p138-p140 |
complete |
final/qualitaessicherung.html#qa-standards |
Quality-management standards (ISO 9001, CMM/CMMI, SPICE) (p138 repeated TOC). |
lectures-final-qualitaessicherung |
p141-p143 |
non-substantive |
|
Summary recap and repeated table-of-contents slides; summary content already represented across the sections. |
lectures-final-qualitaessicherung |
p144-p147 |
complete |
final/qualitaessicherung.html#qa-standards |
Formal verification appendix — SAT/SMT and Z notation. |
work-blatts-final-qualitaessicherung |
p1-p2 |
non-substantive |
|
Cover/TOC and general notes/introduction (administrative). |
work-blatts-final-qualitaessicherung |
p3 |
complete |
final/qualitaessicherung.html#qa-kosten |
Quality costs and effort, fuzzing teaser, coverage/responsibility — question qa-q-quality-costs. |
work-blatts-final-qualitaessicherung |
p4 |
complete |
final/qualitaessicherung.html#qa-error-fault-failure |
Verification vs validation, good/bad tests, residual-defect table, error/fault/failure (Y2K) — questions qa-q-verification-validation, qa-q-error-fault-failure, and qa-testen-ziele. |
work-blatts-final-qualitaessicherung |
p5 |
complete |
final/qualitaessicherung.html#qa-defect-priorisierung |
Defect prioritization scenario, test types, black/gray/white — questions qa-q-defect-prioritization, qa-q-black-gray-white. |
work-blatts-final-qualitaessicherung |
p6-p7 |
complete |
final/qualitaessicherung.html#qa-lesbare-tests |
Readable tests (Gherkin/Cucumber, data-driven) — question qa-q-readable-tests. |
work-blatts-final-qualitaessicherung |
p8-p9 |
complete |
final/qualitaessicherung.html#qa-coverage-c |
Full coverage worth?, triangle/bar coverage trap, C0/C1/C2/C3 counting and C4 effects — questions qa-q-coverage-counting, qa-q-coverage-sense. |
work-blatts-final-qualitaessicherung |
p10-p11 |
complete |
final/qualitaessicherung.html#qa-aequivalenz |
Equivalence classes (Media-Markt discount/bonus) and boundary-value analysis (fridge) — questions qa-q-equivalence, qa-q-boundary. |
work-blatts-final-qualitaessicherung |
p12-p13 |
complete |
final/qualitaessicherung.html#qa-doubles |
Test doubles/drivers, TDD account example, asserts pre/post/invariants weak/strong — questions qa-q-test-doubles, qa-q-tdd, qa-q-asserts. |
work-blatts-final-qualitaessicherung |
p14-p15 |
complete |
final/qualitaessicherung.html#qa-fuzzing |
Fuzzing for regression, GUI testing, test best practices, documentation — question qa-q-fuzzing and qa-testfalldoku/qa-automatisierung. |
work-blatts-final-qualitaessicherung |
p16-p18 |
complete |
final/qualitaessicherung.html#qa-cyclomatic |
Code reviews and cyclomatic complexity (M=E-N+2, sqrt example) — questions qa-q-code-reviews, qa-q-cyclomatic. |
lectures-final-sicherheit |
p1-p6 |
non-substantive |
|
Title, phase-assignment diagram, TOC, learning goals, scope limitations, and an "all phases" illustration slide. |
lectures-final-sicherheit |
p7-p9 |
complete |
final/sicherheit.html#sec-motivation |
Motivation — breaches/financial interest, GDPR fines, ELBA example. |
lectures-final-sicherheit |
p10 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-sicherheit |
p11-p13 |
complete |
final/sicherheit.html#sec-definitionen |
IT-security and vulnerability definitions, risk formula, vulnerability types (sec-schwachstellen-arten). |
lectures-final-sicherheit |
p14-p17 |
complete |
final/sicherheit.html#sec-motivation |
Challenges of IT security. |
lectures-final-sicherheit |
p18-p21 |
complete |
final/sicherheit.html#sec-angriff-phasen |
How attacks are planned/carried out; classic-network/web-platform examples p20/p21 illustrative. |
lectures-final-sicherheit |
p22-p26 |
complete |
final/sicherheit.html#sec-prozess |
No absolute security, cost-benefit, security-is-a-process, cost structure, privacy/security by design (Datensparsamkeit). |
lectures-final-sicherheit |
p27-p28 |
non-substantive |
|
Repeated TOC and "Security in der Analysephase" section divider. |
lectures-final-sicherheit |
p29-p30 |
complete |
final/sicherheit.html#sec-anforderungen |
Security requirements and the CIA triad. |
lectures-final-sicherheit |
p31-p32 |
complete |
final/sicherheit.html#sec-anforderungen |
Protection classes, CVE/CVSS, threat/risk analysis. |
lectures-final-sicherheit |
p33-p38 |
complete |
final/sicherheit.html#sec-bedrohungsmodellierung |
Attack trees, misuse cases, threat modeling and its steps (example diagrams p34/p36 illustrative). |
lectures-final-sicherheit |
p39 |
non-substantive |
|
Security in der Entwurfsphase section divider. |
lectures-final-sicherheit |
p40-p41 |
complete |
final/sicherheit.html#sec-entwurf-grundlagen |
Security in the design phase (security/attack patterns, UMLSec); p41 weakest-link illustration. |
lectures-final-sicherheit |
p42-p46 |
complete |
final/sicherheit.html#sec-design-prinzipien |
Design principles for secure architecture incl. Kerckhoffs (sec-kerckhoffs) and social components (p46 illustration). |
lectures-final-sicherheit |
p47-p48 |
complete |
final/sicherheit.html#sec-legacy |
Legacy systems and the onion/wrapper model. |
lectures-final-sicherheit |
p49 |
non-substantive |
|
Security in der Implementierungsphase section divider. |
lectures-final-sicherheit |
p50-p51 |
complete |
final/sicherheit.html#sec-arch-prog |
Architecture/programming interplay, attacker-needs-one-flaw, anti-patterns. |
lectures-final-sicherheit |
p52-p53 |
complete |
final/sicherheit.html#sec-runtime |
Secure programming in Java overview and runtime security features. |
lectures-final-sicherheit |
p54-p57 |
complete |
final/sicherheit.html#sec-dos |
Denial of Service — resource exhaustion, parsers, ZIP bomb/billion laughs/XXE, integer overflow checks. |
lectures-final-sicherheit |
p58-p62 |
complete |
final/sicherheit.html#sec-vertrauliche-daten |
Protecting confidential data (exceptions, logging, memory, plaintext passwords, no own crypto). |
lectures-final-sicherheit |
p63-p67 |
complete |
final/sicherheit.html#sec-injection-validierung |
Code injection and validation (whitelist vs blacklist, repair pitfalls, validate early). |
lectures-final-sicherheit |
p68-p72 |
complete |
final/sicherheit.html#sec-erweiterbarkeit |
Extensibility and access rights (Hashtable/Provider entrySet bypass, composition over inheritance). |
lectures-final-sicherheit |
p73-p76 |
complete |
final/sicherheit.html#sec-injection-validierung |
Input validation (Proxy 65535-interface example, fuzzing). |
lectures-final-sicherheit |
p77-p85 |
complete |
final/sicherheit.html#sec-sicherer-code |
Secure code (immutability, copies, public/static fields, FunctionTable example, enums). p77 section divider. |
lectures-final-sicherheit |
p86-p91 |
complete |
final/sicherheit.html#sec-sicherer-code |
Object creation (partial init/finalize attack, final classes, init flag). |
lectures-final-sicherheit |
p92-p94 |
complete |
final/sicherheit.html#sec-serialisierung |
Serialization risks and defenses (whitelist/look-ahead, avoid untrusted deserialization). |
lectures-final-sicherheit |
p95-p99 |
complete |
final/sicherheit.html#sec-tests |
Security-relevant tests, penetration testing limits, management support (p95 divider; p96/p97 illustrations). |
lectures-final-sicherheit |
p100-p103 |
complete |
final/sicherheit.html#sec-betrieb |
Security during/after the operation phase (ITIL, collaboration, decommissioning) (p100 divider; p102 illustration). |
lectures-final-sicherheit |
p104-p108 |
complete |
final/sicherheit.html#sec-sql-injection |
SQL injection — background, vulnerable/safe implementations, countermeasures (p104 divider). |
lectures-final-sicherheit |
p109-p113 |
complete |
final/sicherheit.html#sec-mitm |
Man-in-the-middle — ARP spoofing, certificate pinning countermeasures (p111 diagram illustrative). |
lectures-final-sicherheit |
p114 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-sicherheit |
p115-p116 |
complete |
final/sicherheit.html#sec-prozess |
Summary — security process, by design, process extensions (CLASP, MS SDL, SAMM). |
lectures-final-sicherheit |
p117-p118 |
non-substantive |
|
Repeated TOC and literature recommendations (OWASP, CERT, Eckert). |
work-blatts-final-security |
p1 |
non-substantive |
|
Cover/TOC and general notes/introduction (administrative). |
work-blatts-final-security |
p2 |
complete |
final/sicherheit.html#sec-nih-kerckhoffs |
Not Invented Here custom crypto and secrecy/Kerckhoffs — question sec-q-nih-crypto. |
work-blatts-final-security |
p3 |
complete |
final/sicherheit.html#sec-password-comparison |
Least privilege/validation/key storage and the password-comparison code — questions sec-q-least-privilege, sec-q-password-comparison. |
work-blatts-final-security |
p4 |
complete |
final/sicherheit.html#sec-mac-ordering |
MAC ordering and Java serialization risk — questions sec-q-mac-ordering, sec-q-serialization. |
work-blatts-final-security |
p5 |
complete |
final/sicherheit.html#sec-trust-boundaries |
Trust boundaries, 2FA, all-or-nothing, server trust, obfuscated command — question sec-q-trust-boundaries. |
lectures-final-inbetriebnahme-rollout-wartung |
p1-p4 |
non-substantive |
|
Title, phase-assignment (Zuordnung) diagram, table of contents, and learning goals — orientation only. |
lectures-final-inbetriebnahme-rollout-wartung |
p5-p6 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-definitionen |
Motivation and the definitions of commissioning/operation/maintenance. |
lectures-final-inbetriebnahme-rollout-wartung |
p7-p11 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-applikationstypen |
Application types (web apps/services, apps, rich clients, embedded) and their operation/update implications. |
lectures-final-inbetriebnahme-rollout-wartung |
p12 |
non-substantive |
|
Illustrative example of a project infrastructure (diagram of the toolchain described on p13-p16). |
lectures-final-inbetriebnahme-rollout-wartung |
p13-p16 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-toolchain |
The toolchain (Toolchain 1-3) and development strategies. |
lectures-final-inbetriebnahme-rollout-wartung |
p17-p19 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-ci-cd-cd |
Development stages — Continuous Integration vs. Delivery vs. Deployment. |
lectures-final-inbetriebnahme-rollout-wartung |
p20-p21 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-ci-cd-cd |
Self-made continuous deployment (Gradle) and GitLab CI. |
lectures-final-inbetriebnahme-rollout-wartung |
p22 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-inbetriebnahme-rollout-wartung |
p23-p25 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-akzeptanz |
Involving system users — acceptance, training, and user documentation. |
lectures-final-inbetriebnahme-rollout-wartung |
p26 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-inbetriebnahme-rollout-wartung |
p27-p29 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-inbetriebnahme-grundlagen |
Commissioning — fundamentals and key questions (Fragestellungen 1-2). |
lectures-final-inbetriebnahme-rollout-wartung |
p30-p35 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-abnahme |
Acceptance/introduction phase and formal acceptance of software (Abnahme 1-4). |
lectures-final-inbetriebnahme-rollout-wartung |
p36-p37 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-integrationsansatz |
Module/component integration and a good integration approach. |
lectures-final-inbetriebnahme-rollout-wartung |
p38-p39 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-eip-intro |
Enterprise integration context (point-to-point vs. patterns). |
lectures-final-inbetriebnahme-rollout-wartung |
p40-p43 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-eip-patterns |
The four enterprise integration patterns (File Transfer, Shared DB, RPI, Messaging). |
lectures-final-inbetriebnahme-rollout-wartung |
p44 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-inbetriebnahme-rollout-wartung |
p45-p47 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-betrieb-grundlagen |
Operation — ITIL and the operation roles (operators, administrators, support). |
lectures-final-inbetriebnahme-rollout-wartung |
p48-p50 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-betrieb-anforderungen |
Operation requirements and SLAs (SMART principle). |
lectures-final-inbetriebnahme-rollout-wartung |
p51-p55 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-monitoring-optimierung |
Monitoring (Nagios), optimization, and the operation checklist. |
lectures-final-inbetriebnahme-rollout-wartung |
p56 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-inbetriebnahme-rollout-wartung |
p57-p59 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-migration-grundlagen |
Migration — motivation and the migration types. |
lectures-final-inbetriebnahme-rollout-wartung |
p60-p63 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-migration-strategien |
Migration strategies (Cold-Turkey vs. Chicken-Little, forward/reverse, ETL). |
lectures-final-inbetriebnahme-rollout-wartung |
p64 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-rollout-strategien |
Migration example — switching versions via load balancer (relates to rollout strategies). |
lectures-final-inbetriebnahme-rollout-wartung |
p65 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-migration-strategien |
Migration vs. integration (physical vs. logical integration). |
lectures-final-inbetriebnahme-rollout-wartung |
p66 |
non-substantive |
|
Repeated table-of-contents slide. |
lectures-final-inbetriebnahme-rollout-wartung |
p67-p70 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-wartung-grundlagen |
Maintenance — motivation, definition, and details. |
lectures-final-inbetriebnahme-rollout-wartung |
p71-p74 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-wartungstypen |
Maintenance categories and the four maintenance types (corrective/adaptive/preventive/perfective). |
lectures-final-inbetriebnahme-rollout-wartung |
p75-p77 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-wartungsprozesse |
The maintenance processes (Wartungsprozesse 1-3). |
lectures-final-inbetriebnahme-rollout-wartung |
p78-p80 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-wartung-grundlagen |
Maintenance measures/terms (reengineering, refactoring, reverse engineering, anti-patterns) and artefacts. |
lectures-final-inbetriebnahme-rollout-wartung |
p81 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-changelog |
Documentation of changes — the changelog (and versioning) — question irw-q-changelog. |
lectures-final-inbetriebnahme-rollout-wartung |
p82 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-wartung-grundlagen |
Maintenance vs. further development (Abgrenzung zur Weiterentwicklung). |
lectures-final-inbetriebnahme-rollout-wartung |
p83-p84 |
non-substantive |
|
Repeated table-of-contents slide and closing summary recapping already-covered content. |
work-blatts-final-inbetriebnahme-rollout-wartung |
p1 |
non-substantive |
|
Cover/TOC, general notes and introduction (administrative/orientation). |
work-blatts-final-inbetriebnahme-rollout-wartung |
p2 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-ci-cd-cd |
Development environment in the large — knowing the tools and assigning them to CI/Delivery/Deployment. |
work-blatts-final-inbetriebnahme-rollout-wartung |
p3 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-robustness-performance |
Robustness vs. performance and premature optimization/measuring — questions irw-q-robustness-performance, irw-q-premature-optimization. |
work-blatts-final-inbetriebnahme-rollout-wartung |
p4 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-eip-patterns |
Enterprise integration patterns and version-optimization rollout strategies — questions irw-q-enterprise-integration, irw-q-rollout-strategien. |
work-blatts-final-inbetriebnahme-rollout-wartung |
p5 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-semver |
Versioning schemes (SemVer), changelog, and the Lehman/Belady maintenance laws — questions irw-q-versionsschemata, irw-q-changelog, irw-q-lehman-belady. |
work-blatts-final-inbetriebnahme-rollout-wartung |
p6 |
complete |
final/inbetriebnahme-rollout-wartung.html#irw-lock-in |
Framework updates/lock-in effects and Brooks' second-system effect — questions irw-q-lock-in, irw-q-second-system. |