Case Study: A structured software lifecycle from tested build to secure, governed release

Client: Department of Defence, Joint Collective Training Branch (JCTB)

Project: Software lifecycle management programme

How Profectus introduced a structured software management process that keeps software tested, version-controlled, security scanned, current and procured with financial governance across the Defence Training and Experimentation Network, fully integrated with ITSM.

Client and context

Managing software in a Defence environment demands strict control over versioning, release processes and lifecycle integrity. Within the Joint Collective Training Branch environment, software provisioning required consistency, traceability and coordination with AE962 requirements for simulation software and AE587 requests for commercial software and cloud services, so that software delivered across the Defence Training and Experimentation Network remained functional, compliant and maintainable.

Teams were dealing with fragmented version control, ad hoc testing practices and limited documentation of software activities. There was also a lack of visibility across stakeholders regarding updates and lifecycle milestones, making it difficult to assure software currency, security and financial governance across the environment.

The engagement

Profectus was engaged to introduce a structured software management process aligned with ITSM and security practices. The remit spanned fully tested and compliant software, clearly tracked version control, repeatable and consistent releases, active software currency monitoring, mandatory security scanning before deployment, streamlined AE962, AE587 and simulation software requests, accountable procurement, traceable budget outcomes and Section 23 compliance for all financial commitments.

The challenge

Bringing discipline to software delivery in a live Defence training environment placed several compounding demands on the team:

  • Mindset shift: moving from reactive delivery to structured lifecycle management, against initial tool fragmentation that slowed the setup of consistent practices
  • Overlapping roles: coordinating across teams where responsibilities overlapped between software and infrastructure, requiring active engagement and clarification of ownership
  • Incomplete data: running manual audits across non-ELA software assets required coordination with multiple custodians and validation of incomplete data fields
  • Currency without disruption: keeping software current and secure without disrupting operations, particularly where legacy systems remained in use, and educating stakeholders on the new JCTB-led procurement process

Our approach

Profectus embedded lifecycle discipline across four connected controls, integrated with ITSM change processes and the CMDB.

Version control and repeatable releases

Version control discipline was embedded using a centralised repository with mandatory stakeholder approvers. All software modifications were tracked against change tickets, regularly updated and referenced in audits. JCTB requests tied to AE962 requirements, AE587 commercial and cloud services and simulation software were proactively supported with templated workflows and pre-approved baselines, delivering a consistent, repeatable release process.

Software currency and security scanning

Regular reviews tracked vendor support timelines and identified software approaching end-of-life, with upgrades or replacements scheduled and aligned to operational requirements and coordinated through ITSM change and the CMDB. All software, whether newly introduced or modified, was subject to security scanning before deployment, including automated vulnerability scans, dependency checks and, where required, manual security assessments, with findings documented and addressed prior to production.

Accountable procurement

Procurement of new software was transitioned from the Software Asset Management (SAM) team to JCTB. JCTB adopted the SAM team standardised Software Procurement and Software Business Request Form processes, retaining the governance framework while bringing procurement closer to operational needs. This improved responsiveness and alignment with project and BAU requirements while maintaining licensing oversight, financial control and Section 23 compliance.

Non-ELA audit and continual improvement

Manual audits were introduced in the standalone environment to strengthen oversight of non-ELA software, capturing device name, asset number, device type, operating system, OS version, number of sockets and cluster name. This enhanced visibility into the software landscape and flagged irregularities for remediation. Documentation was embedded within delivery cycles rather than treated as a postscript, and internal reviews tracked continual improvement actions.

What we delivered

  • Repeatable releases: a consistent, repeatable release process aligned with AE962, AE587 and simulation software requirements, with all changes and software builds tied to traceable requests or incidents
  • Tested and versioned: software tested, versioned and signed off in alignment with compliance checks, with security scanning embedded as a mandatory pre-deployment step
  • Current and documented: software currency monitored and actively managed across platforms, with lifecycle documentation kept current and accessible
  • Governed procurement: software procurement transitioned to JCTB while retaining SAM controls and approval pathways, with budget reporting and Section 23 compliance embedded within the software lifecycle process
  • Improved oversight: manual audits of non-ELA software improved oversight and compliance tracking, while opportunities for automation and documentation improvement were captured in the backlog for future cycles

Systems and methods

Centralised version control · Security scanning (automated vulnerability and dependency checks) · ITSM change integration · CMDB · SAM procurement framework · AE962 and AE587 request streams · Section 23 financial governance

The result

Software delivery within the JCTB environment is now more transparent, reliable and aligned with ITSM and security processes. With structured version control, consistent testing, mandatory security scanning, software currency controls, manual audit processes and disciplined procurement, the team can deliver and support software with greater confidence and traceability, and ongoing improvements continue to be identified and actioned.