MADE Workflows > Perform System Software Hazard Analysis
WF73: Perform System Software Hazard Analysis
Pre-Requisites
- A. Hazard Diagram(s): Hazard diagram(s) with connectivity.
- B. SRA Module: access enables Hazard analysis to be performed.
- C. Criticality Profile Selected: Hazard path requires that the correct OSD-supported criticality profile is selected.
Detailed Steps
- Access Hazard Diagram — using the project explorer, select a model item and right-click to select "Hazard Diagram".
- Select Risk Profile — to perform the hazard analysis, select the desired risk profile. Accessed through Preferences -> Criticality profile editor.
- Assign Hazard Concept Criticality Parameters — return to the hazard diagram and select a hazard concept; Criticality parameters (Probability, Severity, Software Control) can be assigned through the 'MIL-STD-882E' tab of the Properties viewer. If the hazard is related to software, update the software control parameter value to be greater than or equal to 1 in the 'MIL-STD-882E' section.
- Decision — Existing Hazard Control Measures? If yes, Assign Hazard Control Measures (Compensating Provisions, Detection Methods, Prevention Controls, Substantiation Actions); revise criticality parameters via Barrier Matrix inside the control measures window. If no, skip ahead.
- Perform Hazard path analysis — using the project explorer, select the system-level item and right-click to select "Hazard Path Analysis".
- Review Hazard Path Analysis — for each row, review the Hazard Sources, Initiating Mechanisms, Target/Threat Outcomes and Initial Risk.
- Decision — Software Risk Level Acceptable? For each row in the hazard path analysis, review the Software Control Index (SwCI) and Software Risk Level and determine if it meets safety requirements. If no, Assign Hazard Concept Control Measures: hazard control measures can be assigned to the appropriate concept within the hazard path (right-click the concept, select control measures, choose predefined or custom control provision). If yes, System Software Hazard Analysis Complete.
- Revise Hazard Concept Criticality Parameters — upon assignment of a hazard control measure, criticality parameters (Probability, Severity, Software Control) can be revised through the Barrier matrix inside the control measures window. Loop back to Criticality Editor (WF09) as needed.
Screen-by-screen detail (from embedded screenshots)
- Step 1: Access Hazard Diagram Viewer — Same as WF72: Project Explorer, right-click model item (e.g. "Control Unit") > "Hazard Diagram".
- Step 2: Select Risk Profile — Main menu: Preferences > Criticality Profile Editor. Select "PHMT Risk Assessment Method (RAC)" (or other profile) as Active Project Profile. The "Software Safety Assessment" / "SSC Matrix" tab shows a "Software Safety Criticality Matrix": Software Control Category (Autonomous, Semi-Autonomous, Redundant Fault Tolerant, Influential, No Safety Impact) x Severity Category (Catastrophic, Critical, Marginal, Negligible), color-coded by Software Control Index (SwCI 1 through SwCI 5).
- Step 3: Assign Hazard Concept Criticality Parameters — Properties > MIL-STD-882E tab, e.g. "Electromagnetic Interference": Probability 10.0 "Frequent", Software Control 0.0 "OFF"; "High Temperature": Probability 10.0 "Frequent", Software Control 9.0 "Autonomous"; "Severe Financial Impact" (outcome node): Probability 4.0 "Improbable", Severity 4.0 "Marginal".
- Step 4: Assign Hazard Concept Control Measures — Right-click concept (e.g. "High Temperature") > Control Measures. "Control Measures - High Temperature" dialog lists Compensating Provision measures (Abort Mission — Software Control mitigation, "Aborting or cancelling the mission in resp..."; Procedures — Software Control mitigation, "Operator actions in response to failure whi...") and Detection Methods (Sensing Device — Software Control mitigation, "A method that involves the use of a sensin..."). Taxonomy tree available for adding new measures (same categories as WF72).
- Step 5: Perform System Hazard Path Analysis — Project Explorer, right-click system-level item (e.g. "Vehicle System") > "Hazard Path Analysis".
- Step 6: Review Hazard Path Analysis (Software Risk Level) — First table: Hazard Cause/Control Measure, Initiating Mechanism/Control Measure, Threat Outcome/Control Measure hierarchy (e.g. Property mismatch -> Extreme Heat [Control Measure: Condition Based Repair] -> Major Loss of Operational Capability [Control Measure: Abort Mission]; Open circuit -> High Temperature [Control Measures: Procedures, Sensing Device, Abort Mission] -> Severe Financial Impact [Control Measures: Safety Devices, Warning Device]). Second table: Subsystem, System, Initial Risk, Revised Risk, Initial/Revised Severity, Initial/Revised Severity Class, Initial/Revised Probability, Initial Probability Class — example rows: Power Generation/Vehicle System Initial Risk "High (1A)" -> Revised "Serious (3A)" (Severity 10.0 -> 5.0, Severity Class Catastrophic -> Marginal); second row Initial Risk "High (2A)" -> Revised "Serious (3A)" (Severity 7.0 -> 3.0, Severity Class Critical -> Marginal). Third table (scrolled right) includes: Revised Probability Class, Initial/Revised Software Control, Initial/Revised Software Control Level, Software Control Index (SwCI), Software Risk Level, Hazard Code — example: SwCI 3, Software Risk Level "Medium" for both rows.
- Step 7: Assign System Software Hazard Concept Control Measures (if Software Risk not acceptable) — Right-click concept (e.g. "High Temperature", "Extreme Heat") > Control Measures. "Control Measures - High Temperature" adds Compensating Provision "Abort Mission" and "Procedures", plus Detection Methods "Sensing Device". "Control Measures - Extreme Heat" adds Prevention Controls "Condition Based Repair" ("Repair of item after degradation has been i...").
- Step 8: Revise Hazard Concept Criticality Parameters — Click "Barrier Matrix" for a control-measure-assigned concept (e.g. "High Temperature"): flow view No Control -> Procedures -> Sensing Device -> Abort Mission -> Revised Control, with rows Probability/Occurrence and Software Control. Example deltas: Probability/Occurrence stays 10.0 -> 10.0 across procedures/sensing/abort (unaffected in this branch), while Software Control 9.0 -> (-2.0 at Sensing Device, -2.0 at Abort Mission) -> revised Software Control 5.0. Resulting Hazard Path Analysis table shows updated Software Control Index (e.g. "SwCI 4") and Software Risk Level ("Low") for both rows after revision.
Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/Workflows/WF73-Perform System Software Hazard Analysis.pdf · retrieved 2026-07-09