MoSCoW Prioritization

A technique for ranking requirements into four groups: Must have, Should have, Could have, and Won't have. The order reflects decreasing importance: Musts are essential for a workable product, while Won't haves are deliberately excluded for now even if they would be nice to include.

Key Points

  • Uses four categories: Must have, Should have, Could have, and Won't have (this time).
  • Must haves define the minimum viable scope; missing any Must means the release is not viable.
  • Applied in backlog refinement and release planning to manage scope within fixed time and budget.
  • Won't haves are explicitly out of scope for the current release but may be revisited later.

Example

An agile team planning a 2-month release for a help desk system uses MoSCoW: Must have items include creating tickets, assigning tickets, and tracking SLAs; Should have items include email notifications; Could have items include dashboard themes; Won't have items include AI-based suggestions. When testing takes longer than expected, the team protects all Musts, trims some Shoulds, and drops the Coulds to meet the fixed date.

PMP Example Question

An agile team has a fixed deadline and limited capacity. Using MoSCoW, which action best aligns with this approach?

  1. Commit to all Must items first, then include Should and Could items only if capacity remains; keep Won't items out of the release.
  2. Assign equal priority to all user stories to maintain fairness.
  3. Defer Must items until technical debt is cleared to reduce risk.
  4. Split every story until each is the same size, then pull randomly.

Correct Answer: A — Prioritize Musts, flex Should/Could, exclude Won'ts

Explanation: MoSCoW orders work by criticality. Musts are non-negotiable, Shoulds and Coulds are flexible, and Won'ts are out of scope for the current release.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Launch your career!

HK School of Management provides world-class training in Project Management with AI and Agile Methodologies. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More