Conclusion

To prevent this kind of accidents, check the following features:

Control design

Risk  If the mode is implicit, the machine cannot check if it complies with the situation .

Guideline  Guidelines for designing mode selectors

Probing design

Risk  If the functional unit cannot report on its state, the cannot check if it complies with the active state .

Guideline  Guidelines for state elicitation

Scenario consistency

Risk  The system did not identify the exceptional scenario because the primary mode sets was implicit.

Guideline  Guidelines for assuring scenario consistency


Updated on 12 Jun 2016.