A safety case is a well-reasoned argument, supported by evidence that a system is acceptably safe to operate in a particular context. For many, evolving a safety case in step with the design has proved to be an effective means of identifying and addressing safety concerns during a system’s lifecycle. However, ultimately safety cases address only one system attribute safety. Increasingly, the idea of extending the well-established concept of the safety case to address wider dependability concerns is being discussed. Attempting to address all dependability attributes can result in competing objectives. As a consequence, there are trade-offs among the dependability attributes that need to be resolved in order to achieve the optimum dependability characteristics for the system. Furthermore, the balance of these trade-offs can depend heavily upon the context in which the system operates. In this paper we examine the suitability of extending existing methodologies and concepts from safety case development practice to address the wider concerns of dependability arguments. We will discuss existing approaches to managing trade-offs between competing design objectives and explain how trade-offs may be supported within the Goal Structuring Notation (GSN) framework. In particular we examine how trade-off resolution during the evolution of the dependability objectives, contributes to establishing a final dependability argument.
[1]
Divya Prasad,et al.
Dependable systems integration using measurement theory and decision analysis
,
1998
.
[2]
Rick Kazman,et al.
Making Architecture Design Decisions: An Economic Approach
,
2002
.
[3]
William A. Wulf,et al.
Practical computer security analysis
,
1998
.
[4]
Claudia Biermann.
The Defence
,
2003,
International Criminal Law Developments in the Case Law of the ICTY.
[5]
FenelonPeter,et al.
An integrated tool set for software safety analysis
,
1993
.
[6]
Tim Kelly,et al.
Arguing Safety - A Systematic Approach to Managing Safety Cases
,
1998
.
[7]
Roy A. Maxion,et al.
Improving software robustness with dependability cases
,
1998,
Digest of Papers. Twenty-Eighth Annual International Symposium on Fault-Tolerant Computing (Cat. No.98CB36224).
[8]
Luca Santillo.
Early FP Estimation and the Analytic Hierarchy Process
,
2000
.