21.2. SOTIF Extensions

Limitations

For the Safety of the Intended Function (SOTIF) one objective is the identification of weaknesses of the design that can potentially lead to hazards. For this purpose, release 2020 R1 introduces Limitations as a first-class modeling concept. Limitations are attached directly to design elements to express all kinds of incapabilities directly within SysML design models. They are fully integrated with all safety analysis methods such as HAZOP/Guidewords, HARA, FMEA, or FTA.

Guideword Analysis

The HAZOP guideword editor has been extended to cover the newly introduced concepts of Limitations and Vulnerabilities. That means, the editor can now be used to identify SOTIF weaknesses as well as Cybersecurity vulnerabilities of the design in a systematic way.

Triggering Conditions

Triggering conditions have been newly introduced in the current version to describe initiators of limitations and failures leading to hazardous behaviour. Triggering conditions are managed in collections and can be linked as enablers to limitations, scenarios, fault trees, and so on.