Ontario Hydro's Experience with New Methods for Engineering Safety Critical Software

Ontario Hydro has had experience in designing and qualifying safety critical software used in the reactor shutdown systems of its nuclear generating stations. To govern this work, a high level Standard for Software Engineering of Safety Critical Software has been jointly developed by Ontario Hydro and Atomic Energy of Canada Limited (AECL). Detailed sub-tier standards and procedures have also been developed which define the specific detailed methodology to be used for the specification and implementation of each software engineering process.

[1]  D. L. Parnas,et al.  On the criteria to be used in decomposing systems into modules , 1972, Software Pioneers.

[2]  Nancy G. Leveson,et al.  Analyzing Software Safety , 1983, IEEE Transactions on Software Engineering.

[3]  David Lorge Parnas,et al.  Active design reviews: principles and practices , 1985, ICSE '85.