NASA NTRSDate not supplied
System properties such as “safety” and “dependability” cannot, in practice, be proven, and must be argued in an “assurance case” aimed at supporting risk-acceptance decisions that have to be made by system acquirers and/or regulatory authorities. The paper is concerned with applications of the “assurance case” idea early in design and development of new systems, when (apart from dedicated testing) the only available operating experience information derives from previous (non-identical) systems. Much of the discussion is based on an evolving acquisition model at the US National Aeronautics and Space Administration; previously, most major systems were developed in-house, but some major systems will now be developed by and acquired from commercial providers. Key points discussed include the following. (1) By promoting a particular kind of focused discussion between acquirers and providers, the use of assurance cases should be particularly valuable under the new acquisition model. (2) In principle, objectives-driven (sometimes called “performance-based”) approaches to assurance of performance have significant advantages in cases where they are applicable. (3) For truly novel systems, completeness of the safety analysis is a significant issue; it is important for the assurance case to include a commitment by the provider (or applicant) to seriously pursue analysis of operating experience, so that previously unrecognized hazards can be identified and addressed. (4) Inquiries into major accidents often point to deficiencies in management oversight in all parts of the life cycle; management processes need to be addressed in the formulation and the implementation of an assurance case. Under the new acquisition model, these considerations imply a serious reconsideration of the way in which the development process is managed by both providers and acquirers.