The argument pattern relating to this stage is shown in Figure 31 below and key elements from the pattern are described in the following sections.
This argument is created for each tier, to demonstrate that the verification evidence that is provided for that tier is sufficient to show that the safety requirements defined at that tier are satisfied.
The claim is supported by making an argument over the chosen verification strategy that is defined in [RR]. A justification for why the defined strategy has been chosen must also be provided (J8.1). The strategy may involve testing, formal verification, or some combination of these approaches. Where testing is used, claim G8.2 must be instantiated. Where formal verification is used, claim G8.6 must be instantiated.
Where testing is being used, for each of the defined safety requirements it must be demonstrated that the testing undertaken demonstrates that the requirement is satisfied. To support this claim it is necessary to show that the tests that were performed have been passed (G8.3), that sufficient tests have been performed for each requirement (G8.4), and that the tests were undertaken in a manner such that the results obtained are trustworthy (G8.5).
In order to show that the testing has been performed in a trustworthy manner, the rigour of the testing process is considered as well as sufficiency of the test platform. The verification log ([SS]) can be used as evidence of the process that was followed, as well as the suitability of the people and tools that were used to implement the testing. The verification plan ([ZZ]) provides evidence that the test platform that was used to perform the tests is sufficiently representative of the target system.
Where formal verification is being used, for each of the defined safety requirements it must be demonstrated that the verification undertaken demonstrates that the requirement is satisfied. To support this claim it is necessary to show that the formally specified properties have been proven to be satisfied (G8.7), that the analysis that is performed is sufficient to demonstrate each requirement is met (G8.8), and that the analysis is undertaken in a manner such that the results obtained are trustworthy (G8.9).
To demonstrate that the analysis performed is sufficient, it is necessary to demonstrate firstly that the properties that have been specified for the formal analysis are sufficient to capture the intent of the safety requirement that needs to be demonstrated (G8.10). The verification plan ([ZZ]) should provide this justification. Secondly, it imust be demonstrated that the formal model that is used to undertake the analysis is a sufficiently accurate reflection of the real AS in its operating environment. This claim is made at G8.11 and is again supported by evidence from the verification plan ([ZZ]).