Is Current Incremental Safety Assurance Sound?
نویسندگان
چکیده
Incremental design is an essential part of engineering. Without it, engineering would not likely be an economic, nor an effective, aid to economic progress. Further, engineering relies on this view of incrementality to retain the reliability attributes of the engineering method. When considering the assurance of safety for such artifacts, it is not surprising that the same economic and reliability arguments are deployed to justify an incremental approach to safety assurance. In a sense, it is possible to argue that, with engineering artifacts becoming more and more complex, it would be economically disastrous to not “do” safety incrementally. Indeed, many enterprises use such an incremental approach, reusing safety artifacts when assuring incremental design changes. In this work, we make some observations about the inadequacy of this trend and suggest that safety practices must be rethought if incremental safety approaches are ever going to be fit for purpose. We present some examples to justify our position and comment on what a more adequate approach to incremental safety assurance may look like.
منابع مشابه
Safety Assurance Contracts for Integrated Modular Avionics
This paper describes a method for performing safety analysis on an Integrated Modular Avionics system in a manner which supports the incremental development and change of system components. This is achieved by analysing each component in the context of the overall system design and then finding derived safety requirements. Each IMA component (hardware, software or both) is then examined to dete...
متن کاملIdentifying Safety Dependencies in Modular Computer Systems
The aviation industry has started to adopt complex distributed computing networks (known as Integrated Modular Avionics (IMA)). IMA raises a number of new issues for syste development. Firstly, IMA is designed to use logical partitioning of data, both to provide security of access to resources and also to support incremental change of one component with limited impact on other components. Secon...
متن کاملChallenging Safety Regulation – a Wake-up Call
In presenting a framework for tackling these issues, the paper examines current safety practices. In particular it challenges, from a theoretical perspective, and by reference to recent research, two common misconceptions that safety is largely a matter of equipment reliability and that process-based assurance can provide adequate evidence of system safety. It argues that failure to address the...
متن کاملProbative Blindness and False Assurance about Safety
Safety activities may provide assurance of safety even where such assurance is unwarranted. This phenomenon – which we will call “probative blindness” – is evident both in hindsight analysis of accidents and in the daily practice of safety work. The purpose of this paper is to describe the phenomenon of probative blindness. We achieve this by distinguishing probative blindness from other phenom...
متن کاملVerification of an Incremental Garbage Collector in Hoare-Style Logic
Many of the current software systems rely on garbage collectors for automatic memory management. This is also the case for various software systems in real-time applications. However, a real-time application often requires an incremental working style of the underlying garbage collection, which renders the garbage collector more complex and less trustworthy. We present a formal verification of ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015