4 ms·
I recently attended a lecture about developing shutdown software for a nuclear power plant. The development process involved three key stages: Formal Requireme
by ampersandy 13y ago
I recently attended a lecture about developing shutdown software for a nuclear power plant.
The development process involved three key stages: Formal Requirements Documents, a Software Design Document, and finally, Coding. Each step in the process is accompanied by formal verification processes and an audit which produces a Hazard Analysis Report. Code also goes through code review and verification.
I wonder if Intergraph employed a testing plan quite as thorough.
Development cycle diagram: http://i.imgur.com/RaBSNHN.png http://i.imgur.com/RaBSNHN.png (from the below PDF, page 4)
The entire paper: http://procon.bg/system/files/28.18_Lawford_Wassyng.pdf http://procon.bg/system/files/28.18_Lawford_Wassyng.pdf
- ams6110 13y agoI think that mil-spec or nuclear QC standards are probably overkill for civilian systems such as 911. Granted there should be some high standards in place, but the systems are a) not secret/classified and b) not as high liability. Yes, failure to handle a 911 call is serious problem, but not like a failed nuclear reactor shutdown in terms of cost, number of people affected, and as a last resort, ability to fall back to a paper-and-pen backup system.
- ampersandy 13y agoI agree that this process might be overkill for a civilian system, but it seems to me that an ongoing failure to respond efficiently to 911 calls (over the course of weeks, months, years) is quite worthy of a development process that reflects the life or death nature of the software's purpose. Regardless, hopefully Intergraph fixes their software quickly so that the operators aren't put under more stress than they need to be.