Conclusion

To prevent this kind of accidents, check the following features:

Terminology validation

Risk  The special steering Disconnected mode was called Control mode, which is too general, and does not hint about the actual purpose.

Guideline  Guidelines for terminology validation

Control design

Risk  If the mode is implicit, the machine cannot check if it complies with the situation .

Guideline  Guidelines for designing mode selectors

Probing design

Risk  If the functional unit cannot report on its state, the cannot check if it complies with the active state .

Guideline  Guidelines for state elicitation

Scenario consistency

Risk  The system did not identify the exceptional scenario because the primary mode sets was implicit.

Guideline  Guidelines for assuring scenario consistency

 


Updated on 12 Jun 2016.