Modification of safety critical systems: an assessment of three approaches

Abstract This paper sums up the experience at SINTEF Telecom and Informatics on analysis of safety critical systems. After a short description of the system under consideration, the paper naturally falls into two parts. The first one is a describtion of two modifications, how they were implemented and how they were analysed for safety. The second one contains a discussion of the three methods used—FTA, FMECA and code analysis. We here concentrate on how these methods differ in focus, the knowledge and information needed, and the types of problems they can handle. The paper's conclusion is that all three methods are needed when analysing the modifications of a safety critical system. The knowledge needed and the problem focus will, however, differ.