The Need for SoS Safety Cases
نویسندگان
چکیده
When you create a System of Systems (SoS), you are doing wilful design. It follows that you need a safety case: a justification of why that system will be safe. All safety cases must have certain common properties: they must focus on risk, they must provide appropriate confidence in their claims, and they must have a clear relationship to a causal model of the system's safety behaviour. None of those are particularly easy for SoS, and there are several areas where SoS are particularly problematic, such as what exactly "the system" comprises, and what on Earth its lifecycle actually is. On the other hand, not everything about SoS safety is necessarily hard, and not every problem faced in SoS safety is an "SoS problem". Motivation: have we got a case? A System of Systems (SoS) is a system composed of components that are themselves systems, and that have their own goals and some degree of autonomy, yet still remain part of a whole with some shared goals and management. When you create an SoS, you are doing wilful design. If you define a configuration of assets to achieve certain aims, and agree that they will communicate and coordinate in certain specific ways, then you are doing explicit, conscious design. When you allow personnel within an SoS to adopt a pattern of using a certain configuration of assets to achieve certain aims, and habitually coordinate their actions by specific patterns of communication, then you are doing implicit, passive design. Either way, you are responsible for the consequences of those design decisions, and could be held accountable if they lead to an accident which causes
منابع مشابه
The Need for Systems of Systems Safety Cases
When you create a System of Systems (SoS), you are doing wilful design. It follows that you need a safety case: a justification of why that system will be safe. All safety cases must have certain common properties: they must focus on risk, they must provide appropriate confidence in their claims, and they must have a clear relationship to a causal model of the system's safety behaviour. None of...
متن کاملReducing the Runtime Acceptance Costs of Large-Scale Distributed Component-Based Systems
Software Systems of Systems (SoS) are large-scale distributed component-based systems in which the individual components are elaborate and complex systems in their own right. Distinguishing characteristics are their short expected integration and deployment time, and the need to modify their architecture at runtime, while preserving the integrity of the system. Integration testing is a commonly...
متن کاملPlanes, Trains and Automobiles — An Investigation into Safety Policy for Systems of Systems
Systems of systems comprise entities that are complex enough to be considered as systems in their own right. The interactions within a system of systems (SoS), unlike monolithic systems, are not constrained by physical design. The dynamic nature of SoS means that complex interactions are allowed to occur between the entities of a SoS. These interactions can lead to accidents. The road, rail and...
متن کاملCharacterisation of Systems of Systems Failures
The increasing role of such systems in safety-critical applications establishes the need for methods to analyse and justify their safety. However, the essential characteristics of SoS present serious difficulties for traditional hazard analysis techniques. Operational independence, heterogenous composition, emergent behaviour and the desire for dynamic reconfiguration make conventional hazard a...
متن کاملSystem of Systems Safety Analysis of GNSS based on Functional Dependency Network Analysis
The characteristics of the system of systems (SoS) present great challenges to the safety analysis of Global Navigation Satellite Systems (GNSS). Traditional safety analysis methods and techniques do not work well in a complex SoS, so new safety analysis technologies are needed to adapt to safety problems in SoS. This study first expounds upon the shortcomings of traditional safety analysis met...
متن کامل