1 Purpose.
2 Audience.
3 Best practices.
Advisory
U.S. Department of Transportation Federal Aviation
Circular
Administration Subject : Best Practices for Airborne Date: 0 7/21 / 2017 AC No: 00 - 69 Software Development Assurance Using Initiated by: AIR - 134 Change: EUROCAE ED - 12( ) and RTCA DO - 178( ) 1 PURPOSE . This advisory circular (AC) provides information in the form of “best practices ” and, as such, is not intended as guidance but rather as comple mentary information to ED - 12C/DO - 178C (and related documents) and AC 20 - 115D.
2 AUDIENCE . We wrote this AC as a means of assisting applicants, design approval holders and developers of airborn e systems and equipment containing software intended to be installed on type certificated aircraft, engines, and propellers , or to be used in TSO articles .
3 BEST PRACTICES .
3.1 S oftware Change Impact Analyses (CIA ) .
3.1.1 These practices provide complement ary information to ED - 12C /DO - 178C and ED - 12B /DO - 178B , section 12.1.1, 12.1.2, and 12.1.3 ; and AC 20 - 115D section 9.b.(4) .
You may consider using these best practices when you need to conduct a software CIA .
3.1.2 The CIA identif ies the released software baseline up on which the proposed sof tware is to be built, providing: 3.1.2.1 A summary of the changes and impact of the changes; 3.1.2.2 A listing and descriptions of the problem reports to be corrected as part of the intended change and/or change requests related to those changes; and 3.1.2.3 A listing of new functions to be activated and/or implemented.
3.1.3 The CIA address es changes in the following items , where applicable : 3.1.3.1 S oftware level; 3.1.3.2 D evelopment or verification environment; 3.1.3.3 Software processes ; 7 /21 / 17 AC 00 - 69 3.1.3.4 T ool s (e.g. when a new tool version is introduced or a tool’s use is modified) ; 3.1.3.5 P rocessor or other hardware components and interfaces; 3.1.3.6 C onfiguration data, especially when activating or deactivating functions; 3.1.3.7 S oftware interface characteristics and input/output requirements; and 3.1.3.8 S oftware requirements, design, architecture, and code components , where such changes are not limited to the modified life - cycle data , but should also consider the ones affected by the change.
3.1.4 For each applicable item in subparagraph 3.1.3 ( above ) , the CIA describes the resulting impact and identifies the activities to be performed to satisfy ED - 12C/DO - 178C and ED - 12B/DO - 178B and continue to satisfy requirements for safe operation.
3.2 Clarification on Data Coupling and Control Coupling . Thes e practices provide complementary information to ED - 94C/DO - 248C , FAQ #67 for satisfying objective A - 7 (8) of ED - 12C /DO - 178C and ED - 12B /DO - 178B : 3.2.1 D ata coupling analysis is of different type and purpose than control coupling analys i s .
Both analyses are necessary to satisfy this objective .
3.2.2 Although they support a verification objective, d ata coupling and control coupling analyses rely on good practices in the software design phase ; for example, through the specification of interface s (I/O) and of dependen cies between components .
3.3 Error Handling at Design Level .
3.3.1 Th ese practices provide complement ary information to ED - 12C/DO - 178C and ED - 12B/DO - 178B , sections 6.3.2, 6.3.3, and 6.3.4 . Section 6.3.4.f. identifies potential sources of errors that require specific activity focused at the source code review level .
However , in order to protect against foreseeable unintended software behavior , it is beneficial and recommended to handle these sources of error at the design level .
3.3.2 T o reduce the possibility of unintended software behavior , co nsider the following activities : 3.3.2.1 Identif ication of foreseeable sources of software errors , which include: 3.3.2.1.1 Runtime exceptions or errors like fixed/floating point arithmetic overflow, stack/heap overflow, division by zero, or c ounter an d timer overrun/wrap - around .
3.3.2.1.2 Data/memory corruption or timing issues like those due to lack of partitioning or to improper interrupt management or cache management.
5 Where to Find this AC.
7 /21 / 17 AC 00 - 69 EUROCAE ED - 217, Object - Oriented Technology an d Related Techniques Supplement to ED - 12C and ED - 109A , dated January 2012 EUROCAE ED - 218, Model - Based Development and Verification Supplement to ED - 12C and ED - 109A , dated January 2012 .
5 WHERE TO FIND THIS A C.
5.1 You may find this AC at http://www.faa.gov/regulations_policies/advisory_circulars/ .
5.2 If you have suggestions for improvement or changes, you may use the template in appendix A at the end of this AC.
Sus an J. M. Cabler Manager, Design, Manufacturing, & Airworthiness Division Aircraft Certification Service 7 /21 / 17 AC 00 - 69 Appendix A Appendix A. Advisory Circular Feedback Information If you find an error in this AC, have recommendations for improving it, or have suggestions for new items/subjects to be added, you may let us know by (1) complete the form online at https://ksn2 .faa.gov/avs/dfs/Pages/Home.aspx or (2) emailing this form to 9 - AWA - AVS - AIR - DMO@faa.gov Subject: AC 00 - SW Date: ___________ Please check all appropriate line items: An error (procedural or typographical) has been noted in paragraph _______ on page _______ .
Recommend p aragraph _______ on page _______ be changed as follows: In a future change to this AC, please cover the following subject: (Briefly describe what you want added.)
Other comments: I would like to discuss the above. Please contact me.
Submitted by : _________________________________ Date : __________________ A - 1