Resilience-oriented specifications

The specification document would include a definition or the operational scenarios and situations, and of the expected combinations of them, defining the design scope. In this example, the operational scenarios are the Primary operational modes, and the subordinate modes are those of the backup cooling systems.

Guideline  Guidelines for rule definition

Guideline  Guidelines for rule specification

Primary operational modes

The specifications would include the following mode set for the Primary operational modes: {Production, Maintenance}

Backup modes

The specifications would include the following mode set for the backup cooling sub system: {Stand-by, Disconnected for maintenance}

Problematic combinations

The combination Disconnected mode in the Production mode may be classified as either:

Guideline Guidelines for situation-dependent mode transition

  Demonstration in the guide ...

According to this classification, the operational rules should be either constraining or alerting.

Specification of the constraining option

The specification is about what should be acceptable. In the example, the acceptable combinations are the combinations

Guideline  Guidelines for constraining

Specification of the alerting option

The requirements should also specify the exceptional combinations. In this example, the only exceptional combination is of the Production mode with the Maintenance mode of the safety sub-systems.

Guideline  Guidelines for alerting


Updated on 20 Apr 2016.